pentest-findings-reportUse this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authori...
Install via ClawdBot CLI:
clawdbot install archlab-space/pentest-findings-reportGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/archlab-space/Open-Skill-Hub/issuesAudited Jun 1, 2026 · audit v1.0
Generated Oct 6, 2026
A boutique penetration testing firm completes a two-week web application assessment for a client and needs to transform tester notes, screenshots, and CVSS calculations into a structured client-ready draft. The lead tester uses this skill to guide the structured intake of findings one at a time and assemble a PTES-aligned draft with executive summary and remediation roadmap. It accelerates the documentation phase while preserving human review and authorization safeguards.
An in-house red team at a bank finishes an authorized internal network assessment and must produce a formal report for the CISO and internal audit committee. The skill ensures executive summary language is CISO-readable, findings are tagged with business impact, and CVSS scores are only recorded with tester input. The signed DRAFT review block helps satisfy internal governance and confidentiality requirements.
A healthcare organization requires annual penetration testing documentation to satisfy HIPAA and internal security policies. The security consultant uses this skill to gather engagement metadata, scope, and findings, then drafts a report with a remediation roadmap grouped by effort tiers. The standardized format reduces rework and ensures evidence is summarized without exposing exploit payloads.
An MSSP conducts dozens of small to mid-sized authorized pentests each quarter and struggles with inconsistent report quality across junior testers. This skill provides a repeatable seven-phase workflow and a fixed output structure that junior testers can follow. The lead tester review block and CVSS accuracy rules reduce errors before client delivery.
A SaaS company hires an external firm to test its multi-tenant AWS environment under an authorized engagement. The tester uses the skill to document findings such as IAM misconfigurations and insecure APIs, map remediations to responsible teams, and produce appendix stubs for raw evidence. The draft is reviewed by the lead tester before the CTO and engineering leads receive the final report.
Security firms charge clients a recurring monthly or annual retainer for ongoing penetration testing, vulnerability assessments, and report documentation. The pentest findings report skill reduces the time consultants spend drafting reports, allowing them to take on more engagements or deliver faster. Revenue is driven by billable hours or flat-fee retainer contracts.
Providers bundle penetration testing with compliance documentation for frameworks such as PCI DSS, HIPAA, or SOC 2. This skill helps standardize the findings report artifact that auditors and regulators expect, making it a repeatable deliverable. Revenue comes from subscription compliance packages and per-assessment fees.
Large enterprises maintain internal red teams and security assessment functions as a cost center rather than a profit center. Adopting this skill improves documentation consistency across internal testers and reduces the time security leadership spends reviewing reports. Value is measured in risk reduction, audit readiness, and operational efficiency rather than direct revenue.
💬 Integration Tip
Pre-fill engagement metadata and scope from your project management or ticketing system to skip routine questions, and pair this skill with a CVSS calculator or vulnerability database lookup to speed up scoring while preserving the skill's tester-input requirement.
Scored Oct 6, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...