vuln-report

Generate a complete vulnerability report with standardized sections from a finding input.

19|3|Updated Feb 28, 2026
One-click install
npx skills add https://github.com/qa-aman/claude-skills --skill vuln-report-qa-aman
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: vuln-report
Source: https://github.com/qa-aman/claude-skills/tree/main/skills/by-role/security/vuln-report
Command: npx skills add https://github.com/qa-aman/claude-skills --skill vuln-report-qa-aman

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security teams and developers produce comprehensive vulnerability reports that clearly communicate risk, evidence, and remediation to both technical and non-technical stakeholders.

Core Features & Use Cases

  • Standardized report structure: header, executive summary, technical description, reproduction steps, evidence, impact, and remediation sections.
  • Evidence handling: guidelines for attaching redacted screenshots, logs, and CVSS/CWE references.
  • Templates and consistency: ensures consistent language and formatting across reports for audits and bug bounty programs.
  • Use case examples: generate a report from a newly discovered vulnerability during a penetration test or bug bounty finding.

Quick Start

Provide a concise vulnerability header and fill the sections with evidence, impact, and remediation.

Frequently Asked Questions about vuln-report

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a standardized vulnerability report from security testing findings?▼

Generate a complete vulnerability report by inputting a security finding to produce a standardized output containing a header, executive summary, technical description, reproduction steps, evidence, impact assessment, and remediation guidance.

What is the best way to format reproduction steps and evidence for a bug bounty report?▼

Format reproduction steps and evidence using standardized templates that guide the attachment of redacted screenshots, logs, and CVSS or CWE references to ensure consistent language across bug bounty reports.

Can I use this for internal security audits and penetration testing projects?▼

Yes, you can use this across security testing projects, bug bounty programs, and internal audits to produce consistent vulnerability reports that clearly communicate risk and remediation to technical and non-technical stakeholders.

How do I structure a vulnerability report to communicate impact and remediation to developers?▼

Structure the vulnerability report using a standardized template that separates the technical description and reproduction steps from the executive summary, impact assessment, and remediation guidance to clearly communicate risk to developers.

What sections should a complete vulnerability report include for stakeholder review?▼

A complete vulnerability report should include a header, executive summary, technical description, reproduction steps, evidence, impact assessment, and remediation guidance to effectively communicate findings to stakeholders.

Do I need to provide CVSS and CWE references when creating a vulnerability report?▼

Providing CVSS and CWE references is recommended as part of the evidence handling guidelines to ensure the vulnerability report meets standardized security testing and auditing requirements.