← ClaudeAtlas

security-pentestlisted

Write a dual-audience PTES/OWASP-style penetration-test report — an Executive Summary for leadership (background, posture, risk profile, general findings, recommendation summary, strategic roadmap) plus a Technical Report for engineers (information gathering, vulnerability assessment, exploitation, post-exploitation, and a mandatory severity-ranked findings table scored against a current CVSS rubric). Use when the deliverable is an authorized penetration-test engagement report that must brief executives and equip remediation engineers from the same evidence base. Anti-trigger; for a controls-vs-framework compliance mapping use nist-sp or compliance-audit, for an operational incident-response procedure use playbook or sre-runbook.
modeled-information-format/mif-docs-plugin · ★ 0 · Data & Documents · score 71
Install: claude install-skill modeled-information-format/mif-docs-plugin
# security-pentest Produces a **dual-audience penetration-test report**: a single deliverable that serves both an executive reader and an engineering reader from one evidence base, following the **Penetration Testing Execution Standard (PTES)** reporting model with an OWASP-style findings discipline (scope, methodology, findings with CVSS severity, proof-of-concept, remediation). Its center of gravity is the **severity-ranked findings table** — a report is not conformant without one mapping every surviving finding to a CVSS-scored severity, affected assets, evidence, and remediation. This genre is for **authorized engagements only**; the authorization and scope statement is required matter, not optional framing. ## Pattern (industry: PTES / OWASP-style, dual-audience) ### Front matter - **Authorization & Scope Statement** — engagement authorization, in-scope targets, rules of engagement, and the testing window. Required matter for every report this genre produces. ### Part 1 — Executive Summary (strategic altitude) 1. **Background** — engagement purpose, scope summary, and objectives in business terms. 2. **Posture** — overall security posture assessment in plain language. 3. **Risk Profile** — the aggregate risk picture: severity distribution and business exposure, not per-finding exploit detail. 4. **General Findings** — themes and systemic weaknesses, framed for a non-technical reader. 5. **Recommendation Summary** — prioritized remediation recommendatio