Report security assessment
The Source for macOS Agent Workflows
npx -y skills add gaelic-ghost/socket --skill report-security-assessmentAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 6 stars6 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Write a reproducible security assessment or penetration-test report from validated evidence. Use when technical findings, negative results, scope, methodology, limitations, exposure, impact, confidence, remediation, retest criteria, evidence handling, and a plain-language executive explanation must be assembled without overstating scanner output or untested coverage.
SKILL.md
2.1 KB, 350 tokens by cl100k_base, as published. Nobody here has run it
Report Security Assessment
Overview
Produce a report that lets technical owners reproduce findings and non-specialists understand what matters. Preserve uncertainty, scope limits, and negative results that materially constrain conclusions.
Read references/security-report-shape.md for the required structure.
Workflow
- Fix report identity.
- Record title, client/project, assessment type, dates, version, authors, classification, and distribution.
- State scope and authority.
- List included/excluded targets, environments, accounts/roles, techniques, time windows, constraints, and changes from the approved scope.
- Summarize outcomes plainly.
- Explain what was found, affected assets, practical consequence, urgent actions, and material uncertainty without jargon or panic.
- Describe methodology and coverage.
- Name standards/guidance, tools/versions, manual checks, evidence sources, assumptions, unavailable telemetry, and untested areas.
- Write each finding.
- Include identity, status/confidence, affected assets, prerequisites, evidence/reproduction, impact, exposure, severity/vector if used, remediation, mitigation, and retest steps.
- Keep raw secrets and unnecessary personal data out of the report.
- Record negative results and limitations.
- Build a remediation plan.
- Group immediate containment, near-term fixes, structural hardening, owners, deadlines, and dependencies.
- Verify the report.
- Cross-check evidence links, commands, screenshots, identifiers, redaction, scope, and status.
Output
Return a self-contained report with executive summary, scope, methodology, findings, negative results, limitations, prioritized remediation, and retest plan.
What ships with it: 2 files
892 B alongside SKILL.md
agents/
- openai.yaml249 B