agentCLAWHUBUnverified

Pentest Findings Report

Use this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authori...

OpenClaw

Rank

62

Safety

84

Downloads

1.2k

Updated

Oct 11, 2026

Version

0.1.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.2K downloadsadoption · observed Oct 11, 2026
Latest release
0.1.0release · observed May 31, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:pentest-findings-report
  1. Install using `clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:pentest-findings-report` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/archlab-space/pentest-findings-report before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/snapshot"

Documentation

CLAWHUB

12,298 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: pentest-findings-report
description: >
  Use this skill when an authorized penetration tester, red team operator, or security
  consultant needs to document and draft findings from a completed authorized engagement
  into a structured penetration test report. Covers executive summary, technical findings
  with CVSS scoring, proof-of-concept summaries, impact analysis, remediation roadmap,
  and appendices. Produces a DRAFT report for lead tester review before client delivery.
---

# Pentest Findings Report

Convert raw authorized engagement findings into a structured, client-ready penetration test report aligned to PTES and OWASP Testing Guide documentation standards.

## Flow

### Phase 1 — Engagement Metadata

Ask for and record:
- Engagement name and reference number
- Client organization and primary contact
- Scope: in-scope assets (IP ranges, domains, applications, physical locations)
- Explicitly out-of-scope assets
- Rules of engagement summary
- Testing window (start and end dates)
- Testing team (lead tester, testers, reviewer)
- Report classification level (Confidential / Restricted)

### Phase 2 — Executive Summary Inputs

Ask for:
- Overall risk rating (Critical / High / Medium / Low)
- Finding counts by severity tier
- One-paragraph business context for why this assessment was conducted
- Top 3 Critical/High findings to highlight for leadership
- One-to-two sentence overall security posture statement for the CISO audience

Draft the Executive Summary now. Ask the tester to confirm before continuing to Phase 3.

### Phase 3 — Findings Intake

For each finding, collect in order:
1. Finding title (clear and descriptive)
2. Severity (Critical / High / Medium / Low / Informational)
3. CVSS 3.1 Base Score and vector string — if not provided, prompt for the required base metrics; label estimated scores as "Estimated"
4. Affected asset(s)
5. Vulnerability description: what the vulnerability is and its root cause
6. Proof-of-concept evidence summary: screenshot filenames, command output references, HTTP request/response references — no working exploit payloads or shellcode
7. Business impact in plain language: what an attacker can achieve with this vulnerability
8. Remediation recommendation: specific and actionable
9. References: CVE, CWE, OWASP category, vendor advisory

Ask "Are there more findings to enter?" after each one. When all findings are entered, display the full list and ask the tester to confirm before drafting.

### Phase 4 — Risk Summary Table

Build a findings table sorted by severity (Critical → High → Medium → Low → Informational):

| # | Title | Severity | CVSS Score | Affected Asset | Status |

Ask tester whether any findings are already mitigated or remediated; update Status column accordingly (Open / Mitigated / Remediated).

### Phase 5 — Remediation Roadmap

Group remediations by effort tier:
- **Immediate (≤30 days):** Critical and High findings
- **Short-term (31–90 days):** Medium findings
- **Long-term (

README.md

# pentest-findings-report

Turn authorized penetration test findings into a structured, client-ready report.

## Overview

This skill guides authorized penetration testers and security consultants through converting raw engagement findings into a professional report aligned to PTES and OWASP Testing Guide documentation standards. It covers executive summary drafting, per-finding technical documentation with CVSS 3.1 scoring, a risk summary table sorted by severity, and a tiered remediation roadmap. Produces a DRAFT for lead tester review before client delivery.

**For authorized engagements only.** The skill confirms that all findings come from a scoped, authorized engagement before drafting.

## Use When

- You have completed an authorized penetration test and need to produce the final written deliverable
- You need to structure raw findings (vulnerability descriptions, evidence references, CVSS scores) into a consistent, client-readable format
- You need an executive summary, technical findings sections, and a prioritized remediation roadmap assembled in one document

## Not For

- Documenting findings from unauthorized or out-of-scope testing
- Generating working exploit payloads, shellcode, or attack scripts
- Replacing the lead tester's professional review, sign-off, and client relationship

## Domain

`penetration-testing`

## Workflow Summary

1. **Engagement metadata** — scope, rules of engagement, testing window, team, classification
2. **Executive summary** — overall risk rating, finding counts, top issues, posture statement
3. **Findings intake** — per finding: title, severity, CVSS, asset, description, PoC summary, impact, remediation, references
4. **Risk summary table** — all findings sorted Critical → High → Medium → Low → Informational
5. **Remediation roadmap** — tiered by effort (≤30 days / 31–90 days / >90 days)
6. **Appendix stubs** — scope detail, tool list, evidence log, CVSS rationale
7. **DRAFT report assembly** — complete document with lead-tester review block

## Output

DRAFT penetration test report (executive summary, engagement overview, risk table, technical findings, remediation roadmap, appendices) for lead tester review before client delivery.

## Feedback & Contributions

Found a gap, unusual engagement type, or compliance framework this skill doesn't handle? Open an issue at https://github.com/archlab-space/Open-Skill-Hub/issues

_meta.json

{
  "ownerId": "kn798vfcxrgjdt230v34k8eqf584vpwv",
  "slug": "pentest-findings-report",
  "version": "0.1.0",
  "publishedAt": 1780220604698
}

CHANGELOG.md

# Changelog

## [0.1.0] - 2026-05-30
Initial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap.

skill-card.md

## Description:

Guides authorized penetration testers and security consultants through drafting structured penetration test reports from completed, scoped engagements.

This skill is ready for commercial/non-commercial use.

## Publisher:

[archlab-space](https://clawhub.ai/user/archlab-space)

### License/Terms of Use:

MIT-0

## Use Case:

Security consultants, penetration testers, and red team operators use this skill to turn authorized engagement findings into a client-ready draft report with executive summary, technical findings, risk summary, remediation roadmap, appendices, and review sign-off.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Client names, scoped assets, evidence references, and draft reports may contain confidential engagement information.

Mitigation: Treat all generated reports and inputs as confidential, limit distribution according to the engagement contract, and follow contractual retention and destruction requirements.

Risk: The skill could be misused to document unauthorized or out-of-scope testing activity.

Mitigation: Use only for explicitly authorized security reporting workflows, separate out-of-scope observations, and confirm authorization before inclusion.

Risk: Incorrect severity, CVSS scoring, or impact language could mislead the client or reviewer.

Mitigation: Require tester-provided severity and CVSS inputs, label estimates clearly, and have the lead tester review the final draft before delivery.

Risk: Proof-of-concept sections may expose sensitive exploit details if filled improperly.

Mitigation: Reference screenshots, log excerpts, command descriptions, or request and response evidence only; do not include working exploit code, shellcode, or attack scripts.

## Reference(s):


## Skill Output:

**Output Type(s):** [text, markdown, guidance]

**Output Format:** [Markdown draft penetration test report]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Includes structured sections, evidence summaries without working exploit payloads, remediation tiers, appendix stubs, and a lead tester review block.]

## Skill Version(s):

0.1.0 (source: server release metadata and CHANGELOG, released 2026-05-30)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/archlab-space/skills/pentest-findings-report",
      "sourceUrl": "https://clawhub.ai/archlab-space/skills/pentest-findings-report",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T04:21:16.607Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T04:21:16.607Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.2K downloads",
      "href": "https://clawhub.ai/archlab-space/pentest-findings-report",
      "sourceUrl": "https://clawhub.ai/archlab-space/pentest-findings-report",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T04:21:16.607Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.1.0",
      "href": "https://clawhub.ai/archlab-space/pentest-findings-report",
      "sourceUrl": "https://clawhub.ai/archlab-space/pentest-findings-report",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-31T09:43:24.698Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.1.0",
      "description": "Initial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap.",
      "href": "https://clawhub.ai/archlab-space/pentest-findings-report",
      "sourceUrl": "https://clawhub.ai/archlab-space/pentest-findings-report",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-31T09:43:24.698Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to Pentest Findings Report and adjacent AI workflows.