generating-security-audit-reports
Installation
SKILL.md
Generating Security Audit Reports
Overview
Aggregate vulnerability scan results, configuration analyses, and compliance assessments into a structured, auditor-ready security report. Map every finding to a CVSS severity, applicable compliance control (PCI-DSS, HIPAA, SOC 2, GDPR), and a prioritized remediation timeline.
Prerequisites
- Vulnerability scanner outputs (Nmap, Nessus, OpenVAS, OWASP ZAP) available in
${CLAUDE_SKILL_DIR}/security/ - Application and infrastructure configuration files accessible
- SAST/DAST tool results (e.g., Semgrep, Snyk, Trivy, Bandit)
- Applicable compliance framework documentation identified (PCI-DSS v4.0, HIPAA Security Rule, SOC 2 TSC, GDPR)
- Write permissions for report output directory
${CLAUDE_SKILL_DIR}/reports/