Skip to content
Development
Skill

/report-security-assessment

Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.

From plugin
socket
7200 skills5 MCP
Install
$ npx -y skills add gaelic-ghost/socket --skill report-security-assessment --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/report-security-assessment

Context preview

The summary Claude sees to decide when to auto-load this skill.

Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.

SKILL.md

report-security-assessment.SKILL.md
name: report-security-assessment
description: Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.

Report Security Assessment

Overview

Produce a report that lets technical owners reproduce findings and non-specialists understand what matters. Preserve uncertainty, scope limits, and negative results that materially constrain conclusions.

Read [references/security-report-shape.md](references/security-report-shape.md) for the required structure.

Workflow

1. Fix report identity.

  • Record title, client/project, assessment type, dates, version, authors, classification, and distribution.

2. State scope and authority.

  • List included/excluded targets, environments, accounts/roles, techniques, time windows, constraints, and changes from the approved scope.

3. Summarize outcomes plainly.

  • Explain what was found, affected assets, practical consequence, urgent actions, and material uncertainty without jargon or panic.

4. Describe methodology and coverage.

  • Name standards/guidance, tools/versions, manual checks, evidence sources, assumptions, unavailable telemetry, and untested areas.

5. Write each finding.

  • Include identity, status/confidence, affected assets, prerequisites, evidence/reproduction, impact, exposure, severity/vector if used, remediation, mitigation, and retest steps.
  • Keep raw secrets and unnecessary personal data out of the report.

6. Record negative results and limitations. 7. Build a remediation plan.

  • Group immediate containment, near-term fixes, structural hardening, owners, deadlines, and dependencies.

8. Verify the report.

  • Cross-check evidence links, commands, screenshots, identifiers, redaction, scope, and status.

Output

Return a self-contained report with executive summary, scope, methodology, findings, negative results, limitations, prioritized remediation, and retest plan.

Read more
Ships withsocket

Stuff for Agents on macOS Promo audio: Socket Codex Marketplace Promo

Get the whole plugin

Other skills on socket.