Skip to content
Security
Skill

/executive-summary

Distill technical security results into a concise, business-oriented summary for leadership or a board. Use when the audience is executives/non-technical stakeholders and the ask is risk and decisions, not technical detail.

From plugin
awesome-claude-security
7111 skills17 agents13 commands1 MCP
Install
$ npx -y skills add jassics/awesome-claude-security --skill executive-summary --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/executive-summary

Context preview

The summary Claude sees to decide when to auto-load this skill.

Distill technical security results into a concise, business-oriented summary for leadership or a board. Use when the audience is executives/non-technical stakeholders and the ask is risk and decisions, not technical detail.

SKILL.md

executive-summary.SKILL.md
name: executive-summary
description: >-
  Distill technical security results into a concise, business-oriented summary
  for leadership or a board. Use when the audience is executives/non-technical
  stakeholders and the ask is risk and decisions, not technical detail.

Goal

A half-to-one-page summary that answers: how exposed are we, what's the headline risk, and what should leadership decide/fund — in business language.

Structure

  • **Bottom line** (1–2 sentences): overall risk posture and direction vs. last time.
  • **Why it matters**: business impact (revenue, compliance, trust, downtime) — not

CVE numbers.

  • **Top risks** (3–5): each one line, plain language, with relative severity.
  • **What we recommend**: the few decisions/investments that move risk most.
  • **Trend**: improving/declining, with one supporting metric if available.

Steps

1. Translate findings into business consequences; drop jargon and tool names. 2. Aggregate to themes (e.g. "identity weaknesses", "unpatched exposure") rather than listing every finding. 3. Quantify where you can (residual risk, % critical remediated, MTTR). 4. Lead with the decision the reader must make.

Output

The summary (Markdown). Offer to pair it with `security-diagramming:infographic` for a board-ready one-pager, and to roll it into a `pentest-report` or CISO deck.

Notes

Executives optimize for decisions under uncertainty — give them the "so what" and the recommended action, not a finding dump.

Read more
Ships withawesome-claude-security

A Claude Code plugin marketplace for the full cybersecurity & GenAI-security lifecycle — from recon and threat modeling to detection engineering, GRC, and CISO-level strategy. A pentester knows which OWASP test bends a broken-access-control endpoint.

Get the whole plugin

Other skills on awesome-claude-security.