# Report Security Assessment

> Write a security assessment or penetration-test report from evidence. Use when findings, scope, methodology, limitations, impact, remediation, retest criteria, and an executive explanation need calibrated reporting.

- Skill: `gaelic-ghost/report-security-assessment` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add gaelic-ghost/report-security-assessment`
- Raw SKILL.md: https://api.skillmd.com/api/skills/gaelic-ghost/report-security-assessment/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: gaelic-ghost (https://skillmd.com/u/gaelic-ghost)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/gaelic-ghost/report-security-assessment

---


# Report Security Assessment

## Overview

Produce a report that lets technical owners reproduce findings and non-specialists understand what matters. Preserve uncertainty, scope limits, and negative results that materially constrain conclusions.

Read [references/security-report-shape.md](references/security-report-shape.md) for the required structure.

## Workflow

1. Fix report identity.
   - Record title, client/project, assessment type, dates, version, authors, classification, and distribution.
2. State scope and authority.
   - List included/excluded targets, environments, accounts/roles, techniques, time windows, constraints, and changes from the approved scope.
3. Summarize outcomes plainly.
   - Explain what was found, affected assets, practical consequence, urgent actions, and material uncertainty without jargon or panic.
4. Describe methodology and coverage.
   - Name standards/guidance, tools/versions, manual checks, evidence sources, assumptions, unavailable telemetry, and untested areas.
5. Write each finding.
   - Include identity, status/confidence, affected assets, prerequisites, evidence/reproduction, impact, exposure, severity/vector if used, remediation, mitigation, and retest steps.
   - Keep raw secrets and unnecessary personal data out of the report.
6. Record negative results and limitations.
7. Build a remediation plan.
   - Group immediate containment, near-term fixes, structural hardening, owners, deadlines, and dependencies.
8. Verify the report.
   - Cross-check evidence links, commands, screenshots, identifiers, redaction, scope, and status.

## Output

Return a self-contained report with executive summary, scope, methodology, findings, negative results, limitations, prioritized remediation, and retest plan.

