Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add gaelic-ghost/socket --skill report-security-assessment --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Report Security Assessment?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gaelic-ghost-report-security-assessment)More formats (shields.io, HTML) on the badges page.
---
name: report-security-assessment
description: Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.
---
# Report Security Assessment
## Overview
Produce a report that lets technical owners reproduce findings and non-specialists understand what matters. Preserve uncertainty, scope limits, and negative results that materially constrain conclusions.
Read [references/security-report-shape.md](references/security-report-shape.md) for the required structure.
## Workflow
1. Fix report identity.
- Record title, client/project, assessment type, dates, version, authors, classification, and distribution.
2. State scope and authority.
- List included/excluded targets, environments, accounts/roles, techniques, time windows, constraints, and changes from the approved scope.
3. Summarize outcomes plainly.
- Explain what was found, affected assets, practical consequence, urgent actions, and material uncertainty without jargon or panic.
4. Describe methodology and coverage.
- Name standards/guidance, tools/versions, manual checks, evidence sources, assumptions, unavailable telemetry, and untested areas.
5. Write each finding.
- Include identity, status/confidence, affected assets, prerequisites, evidence/reproduction, impact, exposure, severity/vector if used, remediation, mitigation, and retest steps.
- Keep raw secrets and unnecessary personal data out of the report.
6. Record negative results and limitations.
7. Build a remediation plan.
- Group immediate containment, near-term fixes, structural hardening, owners, deadlines, and dependencies.
8. Verify the report.
- Cross-check evidence links, commands, screenshots, identifiers, redaction, scope, and status.
## Output
Return a self-contained report with executive summary, scope, methodology, findings, negative results, limitations, prioritized remediation, and retest plan.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!