Pentest Report Writer - CVSS & Findings

    1

    Turn raw penetration-test findings into a client-ready report, CVSS-scored, evidence-driven, for any engagement type.

    $12

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Pentest Report Writer - CVSS & Findings

    Example session with this skill installed

    I have a SQL injection finding on the /api/v1/user endpoint. The payload ' OR 1=1-- bypassed auth. I need a CVSS v4.0 score and a full finding writeup with remediation for a web app report.

    • Read your context and instructions
    • Compiled the pentest report writer
    • Generated the document

    I have processed the SQL injection finding for the web application report. I have assigned a CVSS v4.0 score and drafted the technical writeup with remediation steps.

    Finding: Broken Authentication via SQL Injection

    AttributeDetails
    SeverityCritical (9.3)
    CVSS v4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
    CWE MappingCWE-89: Improper Neutralization of Special Elements used in an SQL Command
    Endpoint/api/v1/user
    Parameterid or username

    Description

    The application's authentication endpoint is vulnerable to SQL injection. An attacker can supply crafted SQL syntax to bypass authentication mechanisms, allowing unauthorized access to administrative or user accounts without a valid password.

    Reproduction Steps

    1. Navigate to the login interface or the /api/v1/user endpoint.
    2. Intercept the authentication request using a proxy tool.
    3. Modify the username parameter to include a classic authentication-bypass SQL injection payload (defanged): ' OR 1[=]1--.
    4. Submit the request. The server returns a 200 OK response and an active session token for the first user in the database.

    Impact

    Successful exploitation grants an attacker full access to user accounts. This leads to complete loss of confidentiality and integrity of user data, and potential lateral movement within the application environment.

    Remediation

    • Use Parameterized Queries: Implement prepared statements with variable binding for all database queries.
    • Input Validation: Enforce strict allow-lists for all user-supplied input.
    • ORM Security: If using an ORM, ensure it is configured to use secure abstraction layers that prevent injection.

    Next steps

    • Verify if this vulnerability exists on other API endpoints within the /api/v1/ path.
    • Attach the request/response logs as Evidence Annex A in the final deliverable.
    • Review the Executive Summary to ensure this Critical finding is highlighted as a top priority.

    pentest-report-writer-cvss-findings.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Generate structured findings with CVSS v4.0 scoring and CWE mappings.Translate technical vulnerabilities into business-risk executive summaries.Build remediation roadmaps and retest matrices for client deliverables.Standardize reporting across web, cloud, and network security assessments.

    About this skill

    An engagement-agnostic report engine that turns raw penetration-test findings into a client-ready deliverable. Give it your notes, scanner exports, or a rough finding list and it normalizes and de-duplicates them, scores each with CVSS v3.1 and v4.0, maps them to CWE and CAPEC, and assembles the full report, executive summary, technical findings with reproduction steps and evidence, a retest and remediation matrix, and appendices. Built for pentesters, red teamers, and security consultants who lose too many hours to documentation.

    It handles web, network, mobile, API, cloud, wireless, social-engineering, and red-team engagements, adjusting tone and framing for each, and translates technical impact into business-risk language for non-technical leadership. Reach for it when testing is done and you need a defensible, consistent report out the door on deadline, whether that's a single web app assessment or a multi-vector red-team writeup.

    Honest limits: it reports on findings you supply, it does not perform the pentest or discover vulnerabilities. It's evidence-driven by design: it won't fabricate findings or evidence, and it won't inflate or deflate severity to fit a client narrative or sales objective. It scores by reasoning over the CVSS vector, so verify the final number in an official calculator for high-stakes reporting, and while its structure supports a defensible, audit-ready deliverable, it is not legal advice. For documenting authorized engagements only.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 9 days ago

    • Passed all security checks, Safe to install

    Listed9 days ago

    What's inside

    Frequently Asked Questions