Pentest Report Writer - CVSS & Findings
Turn raw penetration-test findings into a client-ready report, CVSS-scored, evidence-driven, for any engagement type.
$12
Works with the AI tools you already use
Pentest Report Writer - CVSS & Findings
Example session with this skill installed
I have a SQL injection finding on the /api/v1/user endpoint. The payload ' OR 1=1-- bypassed auth. I need a CVSS v4.0 score and a full finding writeup with remediation for a web app report.
- Read your context and instructions
- Compiled the pentest report writer
- Generated the document
I have processed the SQL injection finding for the web application report. I have assigned a CVSS v4.0 score and drafted the technical writeup with remediation steps.
Finding: Broken Authentication via SQL Injection
| Attribute | Details |
|---|---|
| Severity | Critical (9.3) |
| CVSS v4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L |
| CWE Mapping | CWE-89: Improper Neutralization of Special Elements used in an SQL Command |
| Endpoint | /api/v1/user |
| Parameter | id or username |
Description
The application's authentication endpoint is vulnerable to SQL injection. An attacker can supply crafted SQL syntax to bypass authentication mechanisms, allowing unauthorized access to administrative or user accounts without a valid password.
Reproduction Steps
- Navigate to the login interface or the
/api/v1/userendpoint. - Intercept the authentication request using a proxy tool.
- Modify the
usernameparameter to include a classic authentication-bypass SQL injection payload (defanged):' OR 1[=]1--. - Submit the request. The server returns a
200 OKresponse and an active session token for the first user in the database.
Impact
Successful exploitation grants an attacker full access to user accounts. This leads to complete loss of confidentiality and integrity of user data, and potential lateral movement within the application environment.
Remediation
- Use Parameterized Queries: Implement prepared statements with variable binding for all database queries.
- Input Validation: Enforce strict allow-lists for all user-supplied input.
- ORM Security: If using an ORM, ensure it is configured to use secure abstraction layers that prevent injection.
Next steps
- Verify if this vulnerability exists on other API endpoints within the
/api/v1/path. - Attach the request/response logs as Evidence Annex A in the final deliverable.
- Review the Executive Summary to ensure this Critical finding is highlighted as a top priority.
pentest-report-writer-cvss-findings.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
An engagement-agnostic report engine that turns raw penetration-test findings into a client-ready deliverable. Give it your notes, scanner exports, or a rough finding list and it normalizes and de-duplicates them, scores each with CVSS v3.1 and v4.0, maps them to CWE and CAPEC, and assembles the full report, executive summary, technical findings with reproduction steps and evidence, a retest and remediation matrix, and appendices. Built for pentesters, red teamers, and security consultants who lose too many hours to documentation.
It handles web, network, mobile, API, cloud, wireless, social-engineering, and red-team engagements, adjusting tone and framing for each, and translates technical impact into business-risk language for non-technical leadership. Reach for it when testing is done and you need a defensible, consistent report out the door on deadline, whether that's a single web app assessment or a multi-vector red-team writeup.
Honest limits: it reports on findings you supply, it does not perform the pentest or discover vulnerabilities. It's evidence-driven by design: it won't fabricate findings or evidence, and it won't inflate or deflate severity to fit a client narrative or sales objective. It scores by reasoning over the CVSS vector, so verify the final number in an official calculator for high-stakes reporting, and while its structure supports a defensible, audit-ready deliverable, it is not legal advice. For documenting authorized engagements only.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 9 days ago
- Passed all security checks, Safe to install