
Penetration Test Report Engine
Transform penetration test findings into client-ready reports with risk matrices and remediation ...
What You Can Do
This skill transforms raw vulnerability findings, tool outputs, and testing notes into polished, client-deliverable penetration test reports. You feed it your technical data—whether from Burp Suite, Metasploit, manual testing, or other sources—and it structures findings by severity, calculates CVSS 3.1 scores, generates executive summaries that justify security investments, and produces remediation roadmaps with timelines and resource estimates. It handles audience segmentation so your C-suite gets business impact while technical teams get actionable implementation details.
Features
automatically classify vulnerabilities by severity and business impact with industry-standard metrics
convert technical findings into business impact statements that justify security investments to leadership
create separate executive briefs, technical findings, and appendices tailored to different stakeholder expertise levels
build phased implementation timelines with dependency mapping, resource estimates, and priority sequencing
consolidate duplicate findings across tools and organize by vulnerability type, affected asset, and business function
align remediation guidance with relevant frameworks (OWASP, CIS, PCI-DSS, HIPAA requirements)
visualize vulnerability landscape and track exposure across engagement phases
Example Output
Executive Summary Output:
- 47 vulnerabilities identified across web application and infrastructure
- 8 critical findings requiring immediate remediation (30-day timeline)
- Estimated risk reduction value: $2.3M in prevented breach costs
- Recommended remediation investment: $145K over 90 days
Technical Finding Example:
Finding: SQL Injection in User Login Form
CVSS 3.1 Score: 9.8 (Critical)
Affected Component: /api/v1/authenticate endpoint
Business Impact: Attackers could extract customer PII, authentication tokens, and financial records
Remediation: Implement parameterized queries and input validation (Effort: 16 hours, Timeline: 2 weeks)
Remediation Roadmap Output: Phase 1 (Weeks 1-2): Critical infrastructure patches and WAF rules — blocks 8 critical findings, 4 high-severity issues Phase 2 (Weeks 3-6): Application code remediation with security testing — addresses 15 medium-severity findings Phase 3 (Weeks 7-12): Architecture improvements and security hardening — implements defense-in-depth controls
What's Included
- SKILL.md instruction file with report generation methodology and framework selection guidance:
- Executive Summary Template: pre-formatted structure for C-suite briefings with risk quantification
- Technical Findings Template: standardized finding documentation with CVSS scoring, impact analysis, and remediation steps
- Remediation Roadmap Framework: phased timeline builder with dependency mapping and resource allocation
- Report Structure Checklist: validation checklist ensuring compliance with industry standards (OWASP, PTES, NIST guidelines)
Who It's For
- Penetration testers and security researchers — convert testing output into client-deliverable reports efficiently
- Security consultants — generate consistent, professional reports across multiple engagements and client types
- Chief Information Security Officers — present findings to executive leadership with business impact quantification
- Compliance and risk managers — map vulnerabilities to regulatory requirements and remediation deadlines
- IT directors and infrastructure teams — understand technical findings and prioritize remediation based on business criticality
Best For
- Post-engagement report writing after penetration testing completion
- Converting tool outputs (Burp Suite, Metasploit, Nessus) into narrative findings
- Creating executive briefings and C-suite presentations from technical vulnerability data
- Developing remediation timelines and resource estimates for budget approval
- Organizing findings for regulated industries requiring compliance-mapped reporting (finance, healthcare, government)







