sc-report

Generate a CVSS-aligned SECURITY-REPORT.md from verified findings and architecture.

56|5|Updated Apr 8, 2026
One-click install
npx skills add https://github.com/ersinkoc/security-check --skill sc-report
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: sc-report
Source: https://github.com/ersinkoc/security-check/tree/main/skills/sc-report
Command: npx skills add https://github.com/ersinkoc/security-check --skill sc-report

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates the creation of a comprehensive security assessment report by consolidating verified findings, architecture context, and dependency data into a CVSS-style document.

Core Features & Use Cases

  • Aggregates verified findings, architecture overview, and dependency audit into a single executive report.
  • Maps findings to CVSS-like severities and produces a remediation roadmap for stakeholders.
  • Generates an executive summary, detailed findings, scan statistics, and a prioritized action plan for security reviews.

Quick Start

Ask the AI to generate the final SECURITY-REPORT.md from verified findings, architecture, and dependency data.

Frequently Asked Questions about sc-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a CVSS security report from verified findings and architecture data?▼

To generate a CVSS security report, consolidate verified findings, architecture context, and dependency data into a CVSS-aligned SECURITY-REPORT.md file containing an executive summary, risk scoring, and a remediation roadmap.

What should be included in a security assessment report for stakeholders?▼

A security assessment report for stakeholders should include an executive summary, scan statistics, detailed findings categorized by severity, and a prioritized remediation plan mapping vulnerabilities to CVSS risk scores.

Can I automate remediation roadmap generation from dependency audit results?▼

Yes, you can automate remediation roadmap generation by aggregating dependency audit data and verified findings into a consolidated document that produces a prioritized action plan mapping vulnerabilities to CVSS-like severities.

Does security report generation require inputs from a specific scanning pipeline?▼

Security report generation requires verified findings and architecture inputs, and applies specifically to projects scanned by the security-check sc-* pipeline to produce the final CVSS-aligned assessment document.

What is the best way to map security findings to CVSS severities in an automated report?▼

The best way to map security findings to CVSS severities is by consolidating verified vulnerabilities and architecture context into a structured report that categorizes findings into critical, high, medium, and low risk levels.

Why does my security report need architecture and dependency data alongside findings?▼

Your security report needs architecture and dependency data alongside findings to provide full contextual awareness for risk scoring, enabling the generation of an accurate executive summary and a realistic remediation roadmap.