plugins/pm-security/skills/pentest-report/SKILL.md
Write a clear penetration-test report from findings of an authorized engagement. Use when documenting a pentest, security assessment, or authorized red-team engagement — turning findings into a report clients act on. Produces an executive summary, scope & methodology, findings with severity/evidence/reproduction/remediation, and a risk-ranked remediation plan. For authorized testing only.
npx skillsauth add mohitagw15856/pm-claude-skills pentest-reportInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
A pentest is only as valuable as the report — findings that aren't clearly explained, evidenced, and prioritized don't get fixed. This skill turns the findings of an authorized engagement into a report that both executives and engineers can act on: risk up top, reproducible technical detail below, remediation throughout.
For authorized security testing only (signed scope / rules of engagement). This documents results; it is not a guide to attacking systems you don't have written permission to test.
Ask for these only if they aren't already provided:
1. Executive summary — for leadership: the overall risk posture, the count of findings by severity, the 2–3 most important takeaways, and the headline recommendation. No jargon.
2. Scope & authorization — what was tested, what wasn't, the authorization basis and testing window. (Establishes this was authorized and bounds the results.)
3. Methodology — approach, standards, phases, and tools — enough for the client to understand coverage and limits.
4. Findings — one entry per issue, ordered by severity:
[FINDING TITLE] — Severity: 🔴 Critical / 🟠 High / 🟡 Medium / 🔵 Low (CVSS if used)
- Affected: asset/endpoint/component
- Description: what the weakness is
- Reproduction: the steps to reproduce (responsibly detailed — enough to verify and fix)
- Evidence: request/response, screenshot ref, or output (sensitive data redacted)
- Impact: what an attacker gains; business consequence
- Remediation: the specific fix, and any interim mitigation
5. Risk-ranked remediation plan — a table of all findings with severity, effort, and priority order, so the client knows what to fix first.
| # | Finding | Severity | Fix effort | Priority | |---|---|---|---|---|
6. Positive observations & retest — controls that held up, and the offer/plan to retest fixes.
Penetration-testing reporting standards (PTES, OWASP Testing Guide): exec + technical layers, evidenced reproducible findings, risk-ranked remediation.
business
Analyze why deals are won and lost and turn it into an action plan. Use when asked to run a win/loss analysis, review closed-won and closed-lost deals, understand why the team is losing to a competitor, or summarize sales feedback into patterns. Produces a structured win/loss report with themes, win/loss rates by segment and competitor, representative quotes, and prioritized actions for product, marketing, and sales.
development
Route a fuzzy request to the right skill in this library. Use when the user is unsure which skill fits, asks 'which skill should I use for X', describes a task without naming a skill, or when a request could plausibly match several skills. Produces a best-fit recommendation with the inputs to gather, a runner-up with the tie-breaker, and a workflow recipe when the job spans multiple skills.
testing
Triage a vulnerability or scanner finding — assess real severity, exploitability, and how urgently to fix. Use when asked to triage a CVE, prioritize scanner/pentest findings, assess a vuln's risk, or decide what to patch first. Produces a triage verdict: CVSS-informed severity adjusted for your context, exploitability, real risk, a fix/mitigation, and an SLA — so you fix what matters, not just what's red.
development
Stand up a Voice of Customer (VoC) program that turns feedback into action. Use when asked to build a VoC program, design a customer feedback loop, consolidate feedback sources, or set up a closed-loop feedback process. Produces a VoC program design — objectives, feedback sources and channels, a taxonomy, collection and analysis cadence, closed-loop routing, ownership, and success metrics.