跳到主要内容
知仓学习社ZHICANG

pentest-report

Write a clear penetration-test report from findings of an authorized engagement. Use when documenting a pentest, security assessment, or authorized …

不碰外部(只输出文字)无严重或高危命中mohitagw15856/pm-claude-skills

它会碰到什么

扫了多少1 个文本文件,4 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Penetration Test Report Skill

A pentest is only as valuable as the report — findings that aren't clearly explained, evidenced, and

prioritized don't get fixed. This skill turns the findings of an authorized engagement into a report that

both executives and engineers can act on: risk up top, reproducible technical detail below, remediation

throughout.

> For authorized security testing only (signed scope / rules of engagement). This documents results; it is

> not a guide to attacking systems you don't have written permission to test.

Required Inputs

Ask for these only if they aren't already provided:

  • Engagement scope — what was in scope (targets, environments), the authorization/rules of engagement, and the testing window.
  • Methodology — approach (black/grey/white-box), standards followed (e.g. OWASP, PTES), tools.
  • Findings — each issue found: what it is, affected asset, how it was exploited, evidence, and impact.
  • Audience — client's technical team, leadership, or both.

Output Format

Penetration Test Report: [client / engagement]

1. Executive summary — for leadership: the overall risk posture, the count of findings by severity, the 2–3 most important takeaways, and the headline recommendation. No jargon.

2. Scope & authorization — what was tested, what wasn't, the authorization basis and testing window. (Establishes this was authorized and bounds the results.)

3. Methodology — approach, standards, phases, and tools — enough for the client to understand coverage and limits.

4. Findings — one entry per issue, ordered by severity:

> [FINDING TITLE] — Severity: 🔴 Critical / 🟠 High / 🟡 Medium / 🔵 Low (CVSS if used)

> - Affected: asset/endpoint/component

> - Description: what the weakness is

> - Reproduction: the steps to reproduce (responsibly detailed — enough to verify and fix)

> - Evidence: request/response, screenshot ref, or output (sensitive data redacted)

> - Impact: what an attacker gains; business consequence

> - Remediation: the specific fix, and any interim mitigation

5. Risk-ranked remediation plan — a table of all findings with severity, effort, and priority order, so the client knows what to fix first.

| # | Finding | Severity | Fix effort | Priority |

|---|---|---|---|---|

6. Positive observations & retest — controls that held up, and the offer/plan to retest fixes.

Quality Checks

  • [ ] The executive summary conveys overall risk and top actions without jargon
  • [ ] Scope, authorization, and methodology are stated (results are bounded and clearly authorized)
  • [ ] Each finding has severity, affected asset, reproduction, evidence, impact, and remediation
  • [ ] Findings are ordered by severity and rolled into a risk-ranked remediation plan
  • [ ] Sensitive data in evidence is redacted; positive findings and a retest path are included

Anti-Patterns

  • [ ] Do not omit the authorization/scope — an unbounded, unauthorized-looking report is unusable and unsafe
  • [ ] Do not give a severity without impact and remediation — clients fix what they understand and can prioritize
  • [ ] Do not write findings only engineers can read (or only execs) — serve both audiences in their sections
  • [ ] Do not leave evidence unredacted — protect the very data you're helping secure
  • [ ] Do not produce this for testing that wasn't authorized in writing

Based On

Penetration-testing reporting standards (PTES, OWASP Testing Guide): exec + technical layers, evidenced reproducible findings, risk-ranked remediation.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

同名技能的其他版本

有 3 个不同仓库或目录里都有叫 pentest-report 的技能。它们内容并不相同,别混用: