Install
openclaw skills install pentest-findings-reportUse this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authorized engagement into a structured penetration test report. Covers executive summary, technical findings with CVSS scoring, proof-of-concept summaries, impact analysis, remediation roadmap, and appendices. Produces a DRAFT report for lead tester review before client delivery.
openclaw skills install pentest-findings-reportConvert raw authorized engagement findings into a structured, client-ready penetration test report aligned to PTES and OWASP Testing Guide documentation standards.
Ask for and record:
Ask for:
Draft the Executive Summary now. Ask the tester to confirm before continuing to Phase 3.
For each finding, collect in order:
Ask "Are there more findings to enter?" after each one. When all findings are entered, display the full list and ask the tester to confirm before drafting.
Build a findings table sorted by severity (Critical → High → Medium → Low → Informational):
| # | Title | Severity | CVSS Score | Affected Asset | Status |
Ask tester whether any findings are already mitigated or remediated; update Status column accordingly (Open / Mitigated / Remediated).
Group remediations by effort tier:
For each tier, list: finding title, recommended action, and responsible team placeholder.
Produce appendix stubs for the lead tester to populate:
Assemble the DRAFT report in this order:
Add this block at the end of the document:
DRAFT — FOR AUTHORIZED INTERNAL REVIEW ONLY
Lead Tester Review: _________________________ Date: ________
Reviewer Sign-off: _________________________ Date: ________
This report documents findings from an authorized security engagement.
Do not distribute without lead tester signature. Drafted with AI assistance;
human review required before client delivery.
DRAFT penetration test report containing:
All severity ratings, CVSS scores, and impact statements reflect tester-provided inputs. The AI does not independently assess vulnerability severity or compensability.
If you encounter an engagement type, compliance framework mapping, or output format requirement this skill doesn't handle, share it at https://github.com/archlab-space/Open-Skill-Hub/issues so the community can improve the skill.