Under 15 words. Title Case. Impact-forward. No URLs.
Bad
Good
XSS in search
Stored XSS in Comment Renderer Executes JavaScript in Admin Context
IDOR found
IDOR in User API Exposes PII of All Platform Users
SQL injection
Blind SQL Injection in Search Filter Enables Full Database Extraction
Structure
Summary (2-3 sentences): What's broken, what attacker can do, who's affected.
Steps to Reproduce: Numbered. ONE action per step. Exact URL, method, headers, body.
Impact: What attacker walks away with. How many users. Business impact.
PoC: Self-contained file. Screenshots at each step. Video if multi-step.
CVSS 4.0: Full vector string with justification per metric.
Remediation: 1-2 sentences. Developer-actionable. Specific fix.
Style Rules
Human tone, technical but triager-accessible
Lead with impact, not process
No padding ("I discovered...", "During my testing...")
Every sentence adds information
Never submit without PoC + evidence
Common Mistakes
Theoretical bugs ("could allow...")
Screenshots of Burp instead of clear steps
CVSS overclaiming
Same bug class on multiple endpoints as one report (should be separate)
Missing evidence attachment
1---2name: pentest-agents-report-writing3description: Report Writing4---5# Report Writing67## Title Formula8`[Vulnerability] in [Component] Enables [Impact]`910Under 15 words. Title Case. Impact-forward. No URLs.1112| Bad | Good |13|---|---|14| XSS in search | Stored XSS in Comment Renderer Executes JavaScript in Admin Context |15| IDOR found | IDOR in User API Exposes PII of All Platform Users |16| SQL injection | Blind SQL Injection in Search Filter Enables Full Database Extraction |1718## Structure19201. **Summary** (2-3 sentences): What's broken, what attacker can do, who's affected.212. **Steps to Reproduce**: Numbered. ONE action per step. Exact URL, method, headers, body.223. **Impact**: What attacker walks away with. How many users. Business impact.234. **PoC**: Self-contained file. Screenshots at each step. Video if multi-step.245. **CVSS 4.0**: Full vector string with justification per metric.256. **Remediation**: 1-2 sentences. Developer-actionable. Specific fix.2627## Style Rules28- Human tone, technical but triager-accessible29- Lead with impact, not process30- No padding ("I discovered...", "During my testing...")31- Every sentence adds information32- Never submit without PoC + evidence3334## Common Mistakes35- Theoretical bugs ("could allow...")36- Screenshots of Burp instead of clear steps37- CVSS overclaiming38- Same bug class on multiple endpoints as one report (should be separate)39- Missing evidence attachment
Run npx skillmds@latest add h-mmer/pentest-agents-report-writing in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Report Writing It is listed under Docs & Writing on SkillMD.
This skill has not completed SkillMD's automated safety review yet. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
h-mmer (@h-mmer) published this skill. Their other Agent Skills are listed on their SkillMD profile.