generating-executive-summary
Installation
SKILL.md
Generating Executive Summary
Overview
The vulnerability report is comprehensive — every finding, full detail, every reference. The C-level reader doesn't open it. They ask their security lead "what should I tell the board?" The security lead needs a one-page answer.
That one-page answer is the executive summary. It states the engagement's bottom line:
- A single risk score (0-100)
- Headline counts by severity
- Top-3 remediation priorities, each with rough effort + impact
- OWASP Top 10 coverage (where the work landed)
- Engagement scope and authorization summary (what was tested, under what authority, in what window)
- Next steps the customer's organization should take