reporting-pentest-report

Installation
SKILL.md

Penetration-test report

When it governs

End of a pentest engagement, when findings become a client deliverable. Different from a bug-bounty report (reporting-bug-bounty-writeup): this is the whole engagement — executive narrative plus detailed findings — read by both executives and engineers.

Structure

  1. Executive summary — non-technical: what was tested, overall risk posture, the 3–5 things that matter, and business impact. One page. No jargon.
  2. Scope & methodology — assets/IPs/apps in scope, dates, testing type (black/grey/white), standards followed (PTES/OWASP WSTG/NIST), and limitations.
  3. Findings — one per issue, ordered by risk. Each: title, severity (CVSS vector + rating), affected assets, description, reproduction steps (exact requests/commands), evidence (screenshots/output), impact (business terms), remediation (specific fix), references.
  4. Risk ratings — a consistent method (CVSS + likelihood/impact matrix); explain it.
  5. Remediation roadmap — prioritized, with quick wins vs strategic fixes; owners/timelines if known.
  6. Appendices — full tool output, methodology detail, out-of-scope notes, retest results.
Installs
2
GitHub Stars
19
First Seen
7 days ago
reporting-pentest-report — noorqureshi/sploitagent