skills/report-phase-essentials/SKILL.md
Methodology and quality framework for the penetration testing report phase. Use when: writing or QA-ing pentest reports, improving executive and technical readability, enforcing evidence completeness, adding remediation and retest guidance, including cleanup/restoration and residual risk, or securing report packaging and delivery. NOT for: running phase-specific testing tasks or replacing the specialized reporting implementation/publishing workflow.
npx skillsauth add duriandurino/openclawrino report-phase-essentialsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill to make pentest reports defensible, multi-audience, actionable, and securely handled. This is a methodology and QA layer for reporting, not a replacement for the concrete reporting/publishing pipeline.
✅ USE this skill when:
❌ DON'T use this skill when:
The report is the deliverable
Write for multiple audiences
Cleanup must be explicit
Curate evidence, do not dump tools
Secure handling is part of reporting
Include at least:
Every final report should include a dedicated section answering:
Were tester-created artifacts introduced?
What was removed during cleanup?
What remains intentionally in place, if anything?
Was the environment restored to agreed state?
What residual risk remains after cleanup?
Any follow-up actions required by the client?
If nothing was introduced, say so explicitly.
Each finding should include:
ID
Title
Affected Asset(s)
Severity
Technical Basis (include CVSS when the finding can be scored)
Business Impact / Priority Context
Evidence
Reproduction / Validation Steps
Remediation
Verification / Retest Guidance
References
Use this scoring policy unless the engagement explicitly requires something else:
For every scored finding, include:
CVSS version
CVSS vector
CVSS numeric score
1-3 line metric rationale
Severity band (Low/Medium/High/Critical)
If the evidence is incomplete:
Do not publish a naked score without its vector and rationale.
When relevant, also include:
The executive material should answer quickly:
Rule:
Good remediation should include:
Write every finding so it can be retested deterministically.
Include:
Use these rules:
Before final delivery, check:
Useful quality metrics:
For real finalized engagements, the report handoff should include:
Avoid:
When a pentest sub-agent uses this skill, it should:
Load on demand:
references/examples.md — trigger phrases and expected usereferences/finding-template.md — standardized finding blockreferences/report-qa-checklist.md — final release gate checklistreferences/cleanup-section.md — required cleanup/restoration section templatetesting
Vulnerability analysis and CVE matching for penetration testing. Use when: user asks to check for vulnerabilities, match CVEs against service versions, analyze scan results for weaknesses, research exploitability, assess risk of discovered services, or identify known vulnerabilities. This is the analysis phase — no exploitation yet. NOT for: active scanning (use enum skill), exploitation (use exploit skill), or post-exploitation (use post skill).
development
Methodology and decision framework for the penetration testing vulnerability phase. Use when: validating scanner output, distinguishing confirmed vulnerabilities from hypotheses, explaining CVE/CWE/CVSS, prioritizing findings with KEV/EPSS/business context, guiding vuln-analysis workflow, or reinforcing evidence-backed reporting during the vulnerability phase. NOT for: initial recon or active enumeration, hands-on exploitation, post-exploitation, or replacing the specialized vuln skill's concrete checks.
development
Great slides need two things: content worth presenting and design worth looking at. #1 on DeepResearch Bench (Feb 2026) — CellCog researches and fills content mindfully from minimal prompts, no filler. State-of-the-art PDF generation for presentations, pitch decks, keynotes, and slideshows you can present as-is. Requires cellcog skill for SDK. If cellcog is unavailable, use gog slides as fallback (Google Workspace).
development
Generate pentest presentation slides from engagement findings. Use when: user asks for slides, presentation deck, slide count specified, 'make a presentation', 'create slides', or wants a talk/showcase format from pentest reports. NOT for: writing the full technical report (use reporting skill), raw data collection, or non-security presentations.