---
name: Report Writing
slug: report-writing
category: Writing
description: Report Writing helps structure pentest and bug bounty findings into clear vulnerability reports with impact, reproduction steps, PoC, CVSS 4.0, and remediation. Use it when you need a submission-ready report that is triager-friendly and evidence-backed.
github: "https://github.com/H-mmer/pentest-agents/tree/main/skills/report-writing"
language: Python
stars: 804
forks: 156
install: "npx degit https://github.com/H-mmer/pentest-agents/tree/main/skills/report-writing ~/.claude/skills/report-writing"
installs_to: ~/.claude/skills/report-writing
source_path: skills/report-writing/SKILL.md
collection_size: 25
category_size: 1012
collection_url: "https://dirskills.com/collections/H-mmer/pentest-agents"
added: 2026-08-22T05:22:32.073Z
last_synced: 2026-08-22T05:22:32.073Z
canonical_url: "https://dirskills.com/skills/report-writing"
---

# Report Writing

Report Writing helps structure pentest and bug bounty findings into clear vulnerability reports with impact, reproduction steps, PoC, CVSS 4.0, and remediation. Use it when you need a submission-ready report that is triager-friendly and evidence-backed.

**Install:**

```bash
npx degit https://github.com/H-mmer/pentest-agents/tree/main/skills/report-writing ~/.claude/skills/report-writing
```

## README

# Report Writing

## Title Formula
`[Vulnerability] in [Component] Enables [Impact]`

Under 15 words. Title Case. Impact-forward. No URLs.

| Bad | Good |
|---|---|
| XSS in search | Stored XSS in Comment Renderer Executes JavaScript in Admin Context |
| IDOR found | IDOR in User API Exposes PII of All Platform Users |
| SQL injection | Blind SQL Injection in Search Filter Enables Full Database Extraction |

## Structure

1. **Summary** (2-3 sentences): What's broken, what attacker can do, who's affected.
2. **Steps to Reproduce**: Numbered. ONE action per step. Exact URL, method, headers, body.
3. **Impact**: What attacker walks away with. How many users. Business impact.
4. **PoC**: Self-contained file. Screenshots at each step. Video if multi-step.
5. **CVSS 4.0**: Full vector string with justification per metric.
6. **Remediation**: 1-2 sentences. Developer-actionable. Specific fix.

## Style Rules
- Human tone, technical but triager-accessible
- Lead with impact, not process
- No padding ("I discovered...", "During my testing...")
- Every sentence adds information
- Never submit without PoC + evidence

## Common Mistakes
- Theoretical bugs ("could allow...")
- Screenshots of Burp instead of clear steps
- CVSS overclaiming
- Same bug class on multiple endpoints as one report (should be separate)
- Missing evidence attachment
