Pentest Findings Report
Use this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authori...
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
0.1.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 0.1.0release · observed May 31, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:pentest-findings-report- Install using `clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:pentest-findings-report` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/archlab-space/pentest-findings-report before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/snapshot"
Documentation
CLAWHUB
12,298 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: pentest-findings-report description: > Use this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authorized engagement into a structured penetration test report. Covers executive summary, technical findings with CVSS scoring, proof-of-concept summaries, impact analysis, remediation roadmap, and appendices. Produces a DRAFT report for lead tester review before client delivery. --- # Pentest Findings Report Convert raw authorized engagement findings into a structured, client-ready penetration test report aligned to PTES and OWASP Testing Guide documentation standards. ## Flow ### Phase 1 — Engagement Metadata Ask for and record: - Engagement name and reference number - Client organization and primary contact - Scope: in-scope assets (IP ranges, domains, applications, physical locations) - Explicitly out-of-scope assets - Rules of engagement summary - Testing window (start and end dates) - Testing team (lead tester, testers, reviewer) - Report classification level (Confidential / Restricted) ### Phase 2 — Executive Summary Inputs Ask for: - Overall risk rating (Critical / High / Medium / Low) - Finding counts by severity tier - One-paragraph business context for why this assessment was conducted - Top 3 Critical/High findings to highlight for leadership - One-to-two sentence overall security posture statement for the CISO audience Draft the Executive Summary now. Ask the tester to confirm before continuing to Phase 3. ### Phase 3 — Findings Intake For each finding, collect in order: 1. Finding title (clear and descriptive) 2. Severity (Critical / High / Medium / Low / Informational) 3. CVSS 3.1 Base Score and vector string — if not provided, prompt for the required base metrics; label estimated scores as "Estimated" 4. Affected asset(s) 5. Vulnerability description: what the vulnerability is and its root cause 6. Proof-of-concept evidence summary: screenshot filenames, command output references, HTTP request/response references — no working exploit payloads or shellcode 7. Business impact in plain language: what an attacker can achieve with this vulnerability 8. Remediation recommendation: specific and actionable 9. References: CVE, CWE, OWASP category, vendor advisory Ask "Are there more findings to enter?" after each one. When all findings are entered, display the full list and ask the tester to confirm before drafting. ### Phase 4 — Risk Summary Table Build a findings table sorted by severity (Critical → High → Medium → Low → Informational): | # | Title | Severity | CVSS Score | Affected Asset | Status | Ask tester whether any findings are already mitigated or remediated; update Status column accordingly (Open / Mitigated / Remediated). ### Phase 5 — Remediation Roadmap Group remediations by effort tier: - **Immediate (≤30 days):** Critical and High findings - **Short-term (31–90 days):** Medium findings - **Long-term (
README.md
# pentest-findings-report Turn authorized penetration test findings into a structured, client-ready report. ## Overview This skill guides authorized penetration testers and security consultants through converting raw engagement findings into a professional report aligned to PTES and OWASP Testing Guide documentation standards. It covers executive summary drafting, per-finding technical documentation with CVSS 3.1 scoring, a risk summary table sorted by severity, and a tiered remediation roadmap. Produces a DRAFT for lead tester review before client delivery. **For authorized engagements only.** The skill confirms that all findings come from a scoped, authorized engagement before drafting. ## Use When - You have completed an authorized penetration test and need to produce the final written deliverable - You need to structure raw findings (vulnerability descriptions, evidence references, CVSS scores) into a consistent, client-readable format - You need an executive summary, technical findings sections, and a prioritized remediation roadmap assembled in one document ## Not For - Documenting findings from unauthorized or out-of-scope testing - Generating working exploit payloads, shellcode, or attack scripts - Replacing the lead tester's professional review, sign-off, and client relationship ## Domain `penetration-testing` ## Workflow Summary 1. **Engagement metadata** — scope, rules of engagement, testing window, team, classification 2. **Executive summary** — overall risk rating, finding counts, top issues, posture statement 3. **Findings intake** — per finding: title, severity, CVSS, asset, description, PoC summary, impact, remediation, references 4. **Risk summary table** — all findings sorted Critical → High → Medium → Low → Informational 5. **Remediation roadmap** — tiered by effort (≤30 days / 31–90 days / >90 days) 6. **Appendix stubs** — scope detail, tool list, evidence log, CVSS rationale 7. **DRAFT report assembly** — complete document with lead-tester review block ## Output DRAFT penetration test report (executive summary, engagement overview, risk table, technical findings, remediation roadmap, appendices) for lead tester review before client delivery. ## Feedback & Contributions Found a gap, unusual engagement type, or compliance framework this skill doesn't handle? Open an issue at https://github.com/archlab-space/Open-Skill-Hub/issues
_meta.json
{
"ownerId": "kn798vfcxrgjdt230v34k8eqf584vpwv",
"slug": "pentest-findings-report",
"version": "0.1.0",
"publishedAt": 1780220604698
}CHANGELOG.md
# Changelog ## [0.1.0] - 2026-05-30 Initial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap.
skill-card.md
## Description: Guides authorized penetration testers and security consultants through drafting structured penetration test reports from completed, scoped engagements. This skill is ready for commercial/non-commercial use. ## Publisher: [archlab-space](https://clawhub.ai/user/archlab-space) ### License/Terms of Use: MIT-0 ## Use Case: Security consultants, penetration testers, and red team operators use this skill to turn authorized engagement findings into a client-ready draft report with executive summary, technical findings, risk summary, remediation roadmap, appendices, and review sign-off. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Client names, scoped assets, evidence references, and draft reports may contain confidential engagement information. Mitigation: Treat all generated reports and inputs as confidential, limit distribution according to the engagement contract, and follow contractual retention and destruction requirements. Risk: The skill could be misused to document unauthorized or out-of-scope testing activity. Mitigation: Use only for explicitly authorized security reporting workflows, separate out-of-scope observations, and confirm authorization before inclusion. Risk: Incorrect severity, CVSS scoring, or impact language could mislead the client or reviewer. Mitigation: Require tester-provided severity and CVSS inputs, label estimates clearly, and have the lead tester review the final draft before delivery. Risk: Proof-of-concept sections may expose sensitive exploit details if filled improperly. Mitigation: Reference screenshots, log excerpts, command descriptions, or request and response evidence only; do not include working exploit code, shellcode, or attack scripts. ## Reference(s): ## Skill Output: **Output Type(s):** [text, markdown, guidance] **Output Format:** [Markdown draft penetration test report] **Output Parameters:** [1D] **Other Properties Related to Output:** [Includes structured sections, evidence summaries without working exploit payloads, remediation tiers, appendix stubs, and a lead tester review block.] ## Skill Version(s): 0.1.0 (source: server release metadata and CHANGELOG, released 2026-05-30) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/archlab-space/skills/pentest-findings-report",
"sourceUrl": "https://clawhub.ai/archlab-space/skills/pentest-findings-report",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T04:21:16.607Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T04:21:16.607Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/archlab-space/pentest-findings-report",
"sourceUrl": "https://clawhub.ai/archlab-space/pentest-findings-report",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T04:21:16.607Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.0",
"href": "https://clawhub.ai/archlab-space/pentest-findings-report",
"sourceUrl": "https://clawhub.ai/archlab-space/pentest-findings-report",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-31T09:43:24.698Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.0",
"description": "Initial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap.",
"href": "https://clawhub.ai/archlab-space/pentest-findings-report",
"sourceUrl": "https://clawhub.ai/archlab-space/pentest-findings-report",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-31T09:43:24.698Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
