{"id":"7ca56230-e696-42a8-b586-6ade3648eafa","entityType":"agent","slug":"clawhub-archlab-space-pentest-findings-report","name":"Pentest Findings Report","canonicalUrl":"https://www.xpersona.co/agent/clawhub-archlab-space-pentest-findings-report","canonicalPath":"/agent/clawhub-archlab-space-pentest-findings-report","generatedAt":"2026-10-11T07:41:48.835Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:21:16.607Z","emptyReason":null},"description":"Use this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authori...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:pentest-findings-report","sourceUrl":"https://clawhub.ai/archlab-space/pentest-findings-report","homepage":"https://clawhub.ai/archlab-space/skills/pentest-findings-report","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/archlab-space/pentest-findings-report","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/archlab-space/skills/pentest-findings-report","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Pentest Findings Report technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:21:16.607Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:21:16.607Z","emptyReason":null},"stars":null,"forks":null,"downloads":1161,"packageName":null,"latestVersion":"0.1.0","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:21:16.595Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T04:21:16.607Z","lastCrawledAt":"2026-10-11T04:21:16.595Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T04:21:16.595Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.0","createdAt":"2026-05-31T09:43:24.698Z","changelog":"Initial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap.","fileCount":5,"zipByteSize":6022}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:pentest-findings-report","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s176qz6rwtpzj9gk93r7b3jm6984ty2d:pentest-findings-report` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/archlab-space/pentest-findings-report before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T07:41:48.835Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-archlab-space-pentest-findings-report/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:21:16.607Z","emptyReason":null},"readme":"Skill: Pentest Findings Report\n\nOwner: archlab-space\n\nSummary: Use this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authori...\n\nTags: latest:0.1.0\n\nVersion history:\n\nv0.1.0 | 2026-05-31T09:43:24.698Z | user\n\nInitial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap.\n\nArchive index:\n\nArchive v0.1.0: 5 files, 6022 bytes\n\nFiles: CHANGELOG.md (281b), README.md (2432b), skill-card.md (2504b), SKILL.md (6169b), _meta.json (142b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: pentest-findings-report\ndescription: >\n  Use this skill when an authorized penetration tester, red team operator, or security\n  consultant needs to document and draft findings from a completed authorized engagement\n  into a structured penetration test report. Covers executive summary, technical findings\n  with CVSS scoring, proof-of-concept summaries, impact analysis, remediation roadmap,\n  and appendices. Produces a DRAFT report for lead tester review before client delivery.\n---\n\n# Pentest Findings Report\n\nConvert raw authorized engagement findings into a structured, client-ready penetration test report aligned to PTES and OWASP Testing Guide documentation standards.\n\n## Flow\n\n### Phase 1 — Engagement Metadata\n\nAsk for and record:\n- Engagement name and reference number\n- Client organization and primary contact\n- Scope: in-scope assets (IP ranges, domains, applications, physical locations)\n- Explicitly out-of-scope assets\n- Rules of engagement summary\n- Testing window (start and end dates)\n- Testing team (lead tester, testers, reviewer)\n- Report classification level (Confidential / Restricted)\n\n### Phase 2 — Executive Summary Inputs\n\nAsk for:\n- Overall risk rating (Critical / High / Medium / Low)\n- Finding counts by severity tier\n- One-paragraph business context for why this assessment was conducted\n- Top 3 Critical/High findings to highlight for leadership\n- One-to-two sentence overall security posture statement for the CISO audience\n\nDraft the Executive Summary now. Ask the tester to confirm before continuing to Phase 3.\n\n### Phase 3 — Findings Intake\n\nFor each finding, collect in order:\n1. Finding title (clear and descriptive)\n2. Severity (Critical / High / Medium / Low / Informational)\n3. CVSS 3.1 Base Score and vector string — if not provided, prompt for the required base metrics; label estimated scores as \"Estimated\"\n4. Affected asset(s)\n5. Vulnerability description: what the vulnerability is and its root cause\n6. Proof-of-concept evidence summary: screenshot filenames, command output references, HTTP request/response references — no working exploit payloads or shellcode\n7. Business impact in plain language: what an attacker can achieve with this vulnerability\n8. Remediation recommendation: specific and actionable\n9. References: CVE, CWE, OWASP category, vendor advisory\n\nAsk \"Are there more findings to enter?\" after each one. When all findings are entered, display the full list and ask the tester to confirm before drafting.\n\n### Phase 4 — Risk Summary Table\n\nBuild a findings table sorted by severity (Critical → High → Medium → Low → Informational):\n\n| # | Title | Severity | CVSS Score | Affected Asset | Status |\n\nAsk tester whether any findings are already mitigated or remediated; update Status column accordingly (Open / Mitigated / Remediated).\n\n### Phase 5 — Remediation Roadmap\n\nGroup remediations by effort tier:\n- **Immediate (≤30 days):** Critical and High findings\n- **Short-term (31–90 days):** Medium findings\n- **Long-term (>90 days):** Low and Informational findings\n\nFor each tier, list: finding title, recommended action, and responsible team placeholder.\n\n### Phase 6 — Technical Appendices\n\nProduce appendix stubs for the lead tester to populate:\n- Appendix A: Detailed scope and methodology\n- Appendix B: Testing tool list\n- Appendix C: Raw finding evidence log (placeholder — tester to attach)\n- Appendix D: CVSS scoring rationale for Critical/High findings\n\n### Phase 7 — DRAFT Report Assembly\n\nAssemble the DRAFT report in this order:\n1. Cover page (engagement name, client, dates, classification, version)\n2. Table of contents\n3. Executive Summary\n4. Engagement Overview (scope, methodology, testing window, rules of engagement)\n5. Risk Summary Table\n6. Technical Findings (one numbered section per finding)\n7. Remediation Roadmap\n8. Appendices (stubs with placeholders)\n9. Lead Tester Review Block\n\nAdd this block at the end of the document:\n\n```\nDRAFT — FOR AUTHORIZED INTERNAL REVIEW ONLY\nLead Tester Review: _________________________ Date: ________\nReviewer Sign-off:  _________________________ Date: ________\n\nThis report documents findings from an authorized security engagement.\nDo not distribute without lead tester signature. Drafted with AI assistance;\nhuman review required before client delivery.\n```\n\n## Key Rules\n\n- **Authorization required**: Only document findings from explicitly authorized, scoped testing. If the tester mentions findings on out-of-scope assets, place them in a separate \"Out-of-Scope Observations\" section and remind the tester to confirm authorization before including.\n- **No exploit payloads**: Proof-of-concept sections must reference screenshots, log excerpts, or command descriptions — never include working exploit code, shellcode, or attack scripts.\n- **CVSS accuracy**: Never assign a CVSS score without tester input. Prompt for the required base metrics; label estimated scores clearly.\n- **Confidentiality**: Mark the report as Confidential. Remind the tester that retention and destruction are governed by the engagement contract.\n- **AI-generated content notice**: The lead tester review block must be present on every draft before client delivery.\n- **One finding at a time**: During Phase 3, intake one finding completely before moving to the next.\n\n## Output Format\n\nDRAFT penetration test report containing:\n- Executive Summary (1–2 pages, CISO-readable)\n- Engagement Overview (scope, methodology)\n- Risk Summary Table (all findings, sorted by severity)\n- Technical Findings sections (one per finding: description, evidence summary, impact, remediation, references)\n- Remediation Roadmap (three tiers by effort)\n- Appendix stubs (A–D)\n- Lead tester and reviewer sign-off block\n\nAll severity ratings, CVSS scores, and impact statements reflect tester-provided inputs. The AI does not independently assess vulnerability severity or compensability.\n\n## Feedback\n\nIf you encounter an engagement type, compliance framework mapping, or output format requirement this skill doesn't handle, share it at https://github.com/archlab-space/Open-Skill-Hub/issues so the community can improve the skill.\n\nFile v0.1.0:README.md\n\n# pentest-findings-report\n\nTurn authorized penetration test findings into a structured, client-ready report.\n\n## Overview\n\nThis skill guides authorized penetration testers and security consultants through converting raw engagement findings into a professional report aligned to PTES and OWASP Testing Guide documentation standards. It covers executive summary drafting, per-finding technical documentation with CVSS 3.1 scoring, a risk summary table sorted by severity, and a tiered remediation roadmap. Produces a DRAFT for lead tester review before client delivery.\n\n**For authorized engagements only.** The skill confirms that all findings come from a scoped, authorized engagement before drafting.\n\n## Use When\n\n- You have completed an authorized penetration test and need to produce the final written deliverable\n- You need to structure raw findings (vulnerability descriptions, evidence references, CVSS scores) into a consistent, client-readable format\n- You need an executive summary, technical findings sections, and a prioritized remediation roadmap assembled in one document\n\n## Not For\n\n- Documenting findings from unauthorized or out-of-scope testing\n- Generating working exploit payloads, shellcode, or attack scripts\n- Replacing the lead tester's professional review, sign-off, and client relationship\n\n## Domain\n\n`penetration-testing`\n\n## Workflow Summary\n\n1. **Engagement metadata** — scope, rules of engagement, testing window, team, classification\n2. **Executive summary** — overall risk rating, finding counts, top issues, posture statement\n3. **Findings intake** — per finding: title, severity, CVSS, asset, description, PoC summary, impact, remediation, references\n4. **Risk summary table** — all findings sorted Critical → High → Medium → Low → Informational\n5. **Remediation roadmap** — tiered by effort (≤30 days / 31–90 days / >90 days)\n6. **Appendix stubs** — scope detail, tool list, evidence log, CVSS rationale\n7. **DRAFT report assembly** — complete document with lead-tester review block\n\n## Output\n\nDRAFT penetration test report (executive summary, engagement overview, risk table, technical findings, remediation roadmap, appendices) for lead tester review before client delivery.\n\n## Feedback & Contributions\n\nFound a gap, unusual engagement type, or compliance framework this skill doesn't handle? Open an issue at https://github.com/archlab-space/Open-Skill-Hub/issues\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn798vfcxrgjdt230v34k8eqf584vpwv\",\n  \"slug\": \"pentest-findings-report\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1780220604698\n}\n\nFile v0.1.0:CHANGELOG.md\n\n# Changelog\n\n## [0.1.0] - 2026-05-30\nInitial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap.\n\nFile v0.1.0:skill-card.md\n\n## Description:\n\nGuides authorized penetration testers and security consultants through drafting structured penetration test reports from completed, scoped engagements.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[archlab-space](https://clawhub.ai/user/archlab-space)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nSecurity consultants, penetration testers, and red team operators use this skill to turn authorized engagement findings into a client-ready draft report with executive summary, technical findings, risk summary, remediation roadmap, appendices, and review sign-off.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Client names, scoped assets, evidence references, and draft reports may contain confidential engagement information.\n\nMitigation: Treat all generated reports and inputs as confidential, limit distribution according to the engagement contract, and follow contractual retention and destruction requirements.\n\nRisk: The skill could be misused to document unauthorized or out-of-scope testing activity.\n\nMitigation: Use only for explicitly authorized security reporting workflows, separate out-of-scope observations, and confirm authorization before inclusion.\n\nRisk: Incorrect severity, CVSS scoring, or impact language could mislead the client or reviewer.\n\nMitigation: Require tester-provided severity and CVSS inputs, label estimates clearly, and have the lead tester review the final draft before delivery.\n\nRisk: Proof-of-concept sections may expose sensitive exploit details if filled improperly.\n\nMitigation: Reference screenshots, log excerpts, command descriptions, or request and response evidence only; do not include working exploit code, shellcode, or attack scripts.\n\n## Reference(s):\n\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, guidance]\n\n**Output Format:** [Markdown draft penetration test report]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes structured sections, evidence summaries without working exploit payloads, remediation tiers, appendix stubs, and a lead tester review block.]\n\n## Skill Version(s):\n\n0.1.0 (source: server release metadata and CHANGELOG, released 2026-05-30)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: Pentest Findings Report Owner: archlab-space Summary: Use this skill when an authorized penetration tester, red team operator, or security consultant needs to document and draft findings from a completed authori... Tags: latest:0.1.0 Version history: v0.1.0 | 2026-05-31T09:43:24.698Z | user Initial release. Guides authorized penetration testers through converting raw engagement findings into a structured clien","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"DRAFT — FOR AUTHORIZED INTERNAL REVIEW ONLY\nLead Tester Review: _________________________ Date: ________\nReviewer Sign-off:  _________________________ Date: ________\n\nThis report documents findings from an authorized security engagement.\nDo not distribute without lead tester signature. Drafted with AI assistance;\nhuman review required before client delivery."}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: pentest-findings-report\ndescription: >\n  Use this skill when an authorized penetration tester, red team operator, or security\n  consultant needs to document and draft findings from a completed authorized engagement\n  into a structured penetration test report. Covers executive summary, technical findings\n  with CVSS scoring, proof-of-concept summaries, impact analysis, remediation roadmap,\n  and appendices. Produces a DRAFT report for lead tester review before client delivery.\n---\n\n# Pentest Findings Report\n\nConvert raw authorized engagement findings into a structured, client-ready penetration test report aligned to PTES and OWASP Testing Guide documentation standards.\n\n## Flow\n\n### Phase 1 — Engagement Metadata\n\nAsk for and record:\n- Engagement name and reference number\n- Client organization and primary contact\n- Scope: in-scope assets (IP ranges, domains, applications, physical locations)\n- Explicitly out-of-scope assets\n- Rules of engagement summary\n- Testing window (start and end dates)\n- Testing team (lead tester, testers, reviewer)\n- Report classification level (Confidential / Restricted)\n\n### Phase 2 — Executive Summary Inputs\n\nAsk for:\n- Overall risk rating (Critical / High / Medium / Low)\n- Finding counts by severity tier\n- One-paragraph business context for why this assessment was conducted\n- Top 3 Critical/High findings to highlight for leadership\n- One-to-two sentence overall security posture statement for the CISO audience\n\nDraft the Executive Summary now. Ask the tester to confirm before continuing to Phase 3.\n\n### Phase 3 — Findings Intake\n\nFor each finding, collect in order:\n1. Finding title (clear and descriptive)\n2. Severity (Critical / High / Medium / Low / Informational)\n3. CVSS 3.1 Base Score and vector string — if not provided, prompt for the required base metrics; label estimated scores as \"Estimated\"\n4. Affected asset(s)\n5. Vulnerability description: what the vulnerability is and its root cause\n6. Proof-of-concept evidence summary: screenshot filenames, command output references, HTTP request/response references — no working exploit payloads or shellcode\n7. Business impact in plain language: what an attacker can achieve with this vulnerability\n8. Remediation recommendation: specific and actionable\n9. References: CVE, CWE, OWASP category, vendor advisory\n\nAsk \"Are there more findings to enter?\" after each one. When all findings are entered, display the full list and ask the tester to confirm before drafting.\n\n### Phase 4 — Risk Summary Table\n\nBuild a findings table sorted by severity (Critical → High → Medium → Low → Informational):\n\n| # | Title | Severity | CVSS Score | Affected Asset | Status |\n\nAsk tester whether any findings are already mitigated or remediated; update Status column accordingly (Open / Mitigated / Remediated).\n\n### Phase 5 — Remediation Roadmap\n\nGroup remediations by effort tier:\n- **Immediate (≤30 days):** Critical and High findings\n- **Short-term (31–90 days):** Medium findings\n- **Long-term ("},{"path":"README.md","content":"# pentest-findings-report\n\nTurn authorized penetration test findings into a structured, client-ready report.\n\n## Overview\n\nThis skill guides authorized penetration testers and security consultants through converting raw engagement findings into a professional report aligned to PTES and OWASP Testing Guide documentation standards. It covers executive summary drafting, per-finding technical documentation with CVSS 3.1 scoring, a risk summary table sorted by severity, and a tiered remediation roadmap. Produces a DRAFT for lead tester review before client delivery.\n\n**For authorized engagements only.** The skill confirms that all findings come from a scoped, authorized engagement before drafting.\n\n## Use When\n\n- You have completed an authorized penetration test and need to produce the final written deliverable\n- You need to structure raw findings (vulnerability descriptions, evidence references, CVSS scores) into a consistent, client-readable format\n- You need an executive summary, technical findings sections, and a prioritized remediation roadmap assembled in one document\n\n## Not For\n\n- Documenting findings from unauthorized or out-of-scope testing\n- Generating working exploit payloads, shellcode, or attack scripts\n- Replacing the lead tester's professional review, sign-off, and client relationship\n\n## Domain\n\n`penetration-testing`\n\n## Workflow Summary\n\n1. **Engagement metadata** — scope, rules of engagement, testing window, team, classification\n2. **Executive summary** — overall risk rating, finding counts, top issues, posture statement\n3. **Findings intake** — per finding: title, severity, CVSS, asset, description, PoC summary, impact, remediation, references\n4. **Risk summary table** — all findings sorted Critical → High → Medium → Low → Informational\n5. **Remediation roadmap** — tiered by effort (≤30 days / 31–90 days / >90 days)\n6. **Appendix stubs** — scope detail, tool list, evidence log, CVSS rationale\n7. **DRAFT report assembly** — complete document with lead-tester review block\n\n## Output\n\nDRAFT penetration test report (executive summary, engagement overview, risk table, technical findings, remediation roadmap, appendices) for lead tester review before client delivery.\n\n## Feedback & Contributions\n\nFound a gap, unusual engagement type, or compliance framework this skill doesn't handle? Open an issue at https://github.com/archlab-space/Open-Skill-Hub/issues"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn798vfcxrgjdt230v34k8eqf584vpwv\",\n  \"slug\": \"pentest-findings-report\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1780220604698\n}"},{"path":"CHANGELOG.md","content":"# Changelog\n\n## [0.1.0] - 2026-05-30\nInitial release. Guides authorized penetration testers through converting raw engagement findings into a structured client-ready report with executive summary, CVSS-scored technical findings, risk summary table, and tiered remediation roadmap."},{"path":"skill-card.md","content":"## Description:\n\nGuides authorized penetration testers and security consultants through drafting structured penetration test reports from completed, scoped engagements.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[archlab-space](https://clawhub.ai/user/archlab-space)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nSecurity consultants, penetration testers, and red team operators use this skill to turn authorized engagement findings into a client-ready draft report with executive summary, technical findings, risk summary, remediation roadmap, appendices, and review sign-off.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Client names, scoped assets, evidence references, and draft reports may contain confidential engagement information.\n\nMitigation: Treat all generated reports and inputs as confidential, limit distribution according to the engagement contract, and follow contractual retention and destruction requirements.\n\nRisk: The skill could be misused to document unauthorized or out-of-scope testing activity.\n\nMitigation: Use only for explicitly authorized security reporting workflows, separate out-of-scope observations, and confirm authorization before inclusion.\n\nRisk: Incorrect severity, CVSS scoring, or impact language could mislead the client or reviewer.\n\nMitigation: Require tester-provided severity and CVSS inputs, label estimates clearly, and have the lead tester review the final draft before delivery.\n\nRisk: Proof-of-concept sections may expose sensitive exploit details if filled improperly.\n\nMitigation: Reference screenshots, log excerpts, command descriptions, or request and response evidence only; do not include working exploit code, shellcode, or attack scripts.\n\n## Reference(s):\n\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, guidance]\n\n**Output Format:** [Markdown draft penetration test report]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes structured sections, evidence summaries without working exploit payloads, remediation tiers, appendix stubs, and a lead tester review block.]\n\n## Skill Version(s):\n\n0.1.0 (source: server release metadata and CHANGELOG, released 2026-05-30)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1470,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T04:21:16.607Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T04:21:16.607Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T07:41:48.835Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}