security-pentestlisted
Install: claude install-skill modeled-information-format/mif-docs-plugin
# security-pentest
Produces a **dual-audience penetration-test report**: a single deliverable that
serves both an executive reader and an engineering reader from one evidence
base, following the **Penetration Testing Execution Standard (PTES)** reporting
model with an OWASP-style findings discipline (scope, methodology, findings
with CVSS severity, proof-of-concept, remediation). Its center of gravity is
the **severity-ranked findings table** — a report is not conformant without
one mapping every surviving finding to a CVSS-scored severity, affected
assets, evidence, and remediation. This genre is for **authorized engagements
only**; the authorization and scope statement is required matter, not optional
framing.
## Pattern (industry: PTES / OWASP-style, dual-audience)
### Front matter
- **Authorization & Scope Statement** — engagement authorization, in-scope
targets, rules of engagement, and the testing window. Required matter for
every report this genre produces.
### Part 1 — Executive Summary (strategic altitude)
1. **Background** — engagement purpose, scope summary, and objectives in
business terms.
2. **Posture** — overall security posture assessment in plain language.
3. **Risk Profile** — the aggregate risk picture: severity distribution and
business exposure, not per-finding exploit detail.
4. **General Findings** — themes and systemic weaknesses, framed for a
non-technical reader.
5. **Recommendation Summary** — prioritized remediation recommendatio