Agent skill

Composing Vulnerability Report

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title…

MITAuto-check: notesSecurity

Install Composing Vulnerability Report

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill composing-vulnerability-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace composing-vulnerability-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/composing-vulnerability-report .claude/skills/composing-vulnerability-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
composing-vulnerability-report
GitHub stars
2.8k
Token cost
~1.9k tokens
SKILL.md length
611 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title…

  • Works in 4 steps: Gather findings sources → Run the composer → Review the report → …
  • : closing an engagement
  • SKILL.md covers Overview, When the skill produces findings, Prerequisites and Instructions, plus 4 more sections
  • Runs Python scripts from its folder; calls python3 and jq

What it does

Composing Vulnerability Report is an agent skill from jeremylongshore/tons-of-skills-marketplace. Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title, severity, target, detail, remediation, evidence) and a top-level summary table. The canonical written artifact a customer receives at engagement close; precise, reproducible, machine- checkable against source findings. Use when: closing an engagement, generating an interim report, regenerating after CVE or OWASP…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/compose_report.py`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Web application vulnerabilities, Summarization and Penetration testing. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : closing an engagement
  • Generating an interim report
  • Regenerating after CVE
  • OWASP enrichment

Example prompts

  • “compose vuln report”
  • “write pentest report”
  • “generate vulnerability deliverable”
  • “/composing-vulnerability-report”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Bash(python3:*), Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Gather findings sources
  2. Run the composer
  3. Review the report
  4. Verify against sources

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash(python3:*)
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Composing Vulnerability Report loads about 1.9k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 214 tokens; SKILL.md has 611 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~214
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:27
    - Write(.env)
  • NoteMentions a .env fileSKILL.md:28
    - Edit(.env)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 611 words, ~1,933 tokens.

Download SKILL.mdSave it as .claude/skills/composing-vulnerability-report/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
composing-vulnerability-report
description
Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title, severity, target, detail, remediation, evidence) and a top-level summary table. The canonical written artifact a customer receives at engagement close; precise, reproducible, machine- checkable against source findings. Use when: closing an engagement, generating an interim report, regenerating after CVE or OWASP enrichment, or producing the input for generating-executive-summary. Threshold: findings missing required fields are dropped. HIGH and CRITICAL findings highlighted in the summary section. Trigger with: "compose vuln report", "write pentest report", "generate vulnerability deliverable", "render findings to report".
allowed-tools
Read, Write, Bash(python3:*), Glob
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Bash(curl:*), Bash(wget:*), Write(.env), Edit(.env)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, reporting, vulnerability-report, cvss, pentest

Composing Vulnerability Report

Overview

After cluster 1-4 scan skills run, each one produces a Findings file. A typical engagement ends up with eight to twenty such files across the different skill categories. The customer wants ONE vulnerability report — comprehensive, deduplicated, organized by severity, with each finding cross-referenced to its source skill and target.

This skill consumes one or more findings files (JSONL preferred, JSON list also accepted), deduplicates entries by the canonical fingerprint defined in lib/finding.py, enriches each finding with a CVSS v3.1 vector when one isn't present (using a deterministic heuristic based on severity + category — explicitly noted as "derived, not assigned by NVD" in the output), and emits a single markdown report with per-finding sections plus a top-level summary table.

The report has a defined structure that downstream tools (next two skills in cluster 6) consume:

  1. Header — engagement ID, generation timestamp, source files
  2. Summary table — finding count by severity
  3. Per-severity sections — CRITICAL first, then HIGH, MEDIUM, LOW, INFO
  4. Per-finding subsections — title, severity, target, detail, remediation, evidence, references

When the skill produces findings

FindingSeverityThresholdAffected control
Source file unparseableHIGHJSON/JSONL parse fails(operational)
Finding missing required fieldHIGHA finding record is missing title, severity, target, detail, or remediation(operational)
Duplicate fingerprint across filesINFOSame finding appears in N>1 sources; reported as deduplication count(informational)
Source file has zero findingsINFOEmpty or all-info-only file; reported but not an error(informational)
Report generated cleanlyINFOPositive confirmation(informational)

Prerequisites

  • Python 3.9+
  • One or more findings files in JSON or JSONL format produced by any cluster 1-4 scan skill (which all share lib/finding.py schema)

Instructions

Step 1 — Gather findings sources

By default the skill reads every file matching engagement/findings/*.json and engagement/findings/*.jsonl. Override with --source FILE (repeatable).

Step 2 — Run the composer
bash
python3 ./scripts/compose_report.py engagements/acme-2026-q2/

Options:

Usage: compose_report.py PATH [OPTIONS]

Options:
  --source FILE         Specific findings file (repeatable; overrides default glob)
  --report-output FILE  Write the composed report here (default:
                        PATH/reports/vulnerability-report.md)
  --engagement-id ID    Override the engagement ID (default: parse from PATH/roe.yaml)
  --output FILE         Operational findings output (this skill's own findings)
  --format FMT          json | jsonl | markdown (default: markdown)
  --min-severity SEV    Filter report to findings at or above this severity
  --include-info        Include INFO-severity findings in the report (default: omit)
Step 3 — Review the report

The output report has a predictable structure. The header identifies the engagement, the source files, and the generation timestamp. The summary table shows finding counts by severity. Per-severity sections follow.

Each finding subsection includes a stable anchor (the fingerprint) so cross-references from later artifacts (executive summary, OWASP mapping) resolve into the report cleanly.

Show full SKILL.md (254 more words)Show less
Step 4 — Verify against sources
bash
python3 ./scripts/compose_report.py engagements/acme-2026-q2/ --format json --output /tmp/compose-findings.json
jq '.[] | select(.severity == "high")' /tmp/compose-findings.json

If the report references a finding the operator didn't expect, trace back via the finding's skill_id + target to the source file.

Examples

Example 1 — End-of-engagement report
bash
python3 ./scripts/compose_report.py engagements/acme-2026-q2/ \
    --report-output engagements/acme-2026-q2/reports/vulnerability-report.md
Example 2 — Interim report mid-engagement
bash
python3 ./scripts/compose_report.py engagements/acme-2026-q2/ \
    --min-severity high \
    --report-output engagements/acme-2026-q2/reports/interim-2026-06-15.md

--min-severity high produces an interim report covering only HIGH and CRITICAL findings — useful for in-engagement customer syncs.

Example 3 — Regenerate after OWASP mapping
bash
python3 ./scripts/compose_report.py engagements/acme-2026-q2/ \
    --source engagements/acme-2026-q2/findings/all-findings-with-owasp.jsonl \
    --report-output engagements/acme-2026-q2/reports/vulnerability-report-v2.md

Re-run after mapping-findings-to-owasp-top10 has enriched each finding with its OWASP category; the regenerated report includes the OWASP tag in each per-finding subsection.

Output

JSON / JSONL / Markdown per lib/report.py for the skill's own operational findings. The PRIMARY output is the composed vulnerability report, written as standalone Markdown to the --report-output path.

Each operational Finding includes:

  • id — compose::<issue>::<source-file>
  • severity — CRITICAL / HIGH / MEDIUM / INFO
  • category — report-composition
  • summary — what went wrong (or right) during composition
  • evidence — source files, finding counts, dedup stats

Error Handling

  • PATH missing or empty → emits CRITICAL operational finding, exits 1.
  • Source file unparseable → emits HIGH operational finding, skips the file, continues with remaining sources.
  • No findings files found → emits HIGH operational finding, exits 1.
  • Output report path not writable → emits HIGH operational finding, exits 1.
  • Finding missing required fields → emits HIGH operational finding, omits that record from the report, continues.

Resources

  • references/THEORY.md — Vulnerability-report structure history (NIST SP 800-115, OWASP Testing Guide), CVSS v3.1 vector composition, severity scoring tradeoffs (CVSS vs intrinsic vs EPSS), finding-deduplication theory, why fingerprint-based dedup beats title-based
  • references/PLAYBOOK.md — Report-template variants per audience (technical, executive, regulatory), per-finding remediation phrasing patterns, evidence-redaction patterns for distributed reports, cross-reference protocol with the OWASP-mapping and exec-summary skills

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/composing-vulnerability-report of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/compose_report.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Composing Vulnerability Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Composing Vulnerability Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Composing Vulnerability Report this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.9kAutomated safety check: NotesMIT
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Security Auditdavila7/claude-code-templates33k4 repos~1.3kAutomated safety check: PassMIT
Cybersecurityohmyjahh/xquads-squads277—~895Automated safety check: PassMIT
Security AuditRightNow-AI/openfang18k—~858Automated safety check: PassApache-2.0
Web VulnCommonHuman-Lab/nyxstrike157—~896Automated safety check: PassCustom licence

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Security Audit

    davila7/claude-code-templates

    Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

    33k GitHub starsUsed in 4 repos~1.3k tokens
    SecurityAuto-check passed
  • Cybersecurity

    ohmyjahh/xquads-squads

    Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

    277 GitHub stars~895 tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Security Audit

    RightNow-AI/openfang

    Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

    18k GitHub stars~858 tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Web Vuln

    CommonHuman-Lab/nyxstrike

    Web vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles

    157 GitHub stars~896 tokensUpdated today
    SecurityAuto-check passed
  • Security Pen Testing

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments.

    28k GitHub stars~3.5k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Composing Vulnerability Report

What does Composing Vulnerability Report do?

Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title…. Composing Vulnerability Report is an agent skill from jeremylongshore/tons-of-skills-marketplace. Read findings JSONL files from cluster 1-4 skills, deduplicate by fingerprint, group by severity, and compose a deliverable- grade markdown vulnerability report with per-finding sections (title, severity, target, detail, remediation, evidence) and a top-level summary table.

When should I use Composing Vulnerability Report?

Composing Vulnerability Report fits situations like: : closing an engagement; generating an interim report; regenerating after CVE; OWASP enrichment.

How do I install Composing Vulnerability Report in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill composing-vulnerability-report -a claude-code`. Or copy the skill folder (skills/.curated/composing-vulnerability-report in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/composing-vulnerability-report in your project. Claude Code loads it when a task matches its description.

How do I install Composing Vulnerability Report in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill composing-vulnerability-report -a codex`. Or copy the skill folder (skills/.curated/composing-vulnerability-report in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/composing-vulnerability-report in your project. Codex loads it when a task matches its description.

Can I use Composing Vulnerability Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill composing-vulnerability-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/composing-vulnerability-report, .gemini/skills/composing-vulnerability-report, .github/skills/composing-vulnerability-report and .opencode/skills/composing-vulnerability-report in your project.

What does Composing Vulnerability Report need to run?

Going by SKILL.md and its folder, Composing Vulnerability Report needs Python for the scripts in its folder and the command-line tools its instructions call (python3 and jq). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash(python3:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.

Does Composing Vulnerability Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Composing Vulnerability Report safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Composing Vulnerability Report use?

Composing Vulnerability Report is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Composing Vulnerability Report use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Composing Vulnerability Report?

Skills that share tags, products or a category with Composing Vulnerability Report: Code Audit (3stoneBrother/code-audit, 892 stars), Security Audit (davila7/claude-code-templates, 33k stars), Cybersecurity (ohmyjahh/xquads-squads, 277 stars) and Security Audit (RightNow-AI/openfang, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Composing Vulnerability Report?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.