Agent skill

Generating Executive Summary

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report.

MITAuto-check: notesSecurity

Install Generating Executive Summary

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace generating-executive-summary --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/generating-executive-summary .claude/skills/generating-executive-summary && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
generating-executive-summary
GitHub stars
2.8k
Token cost
~2.2k tokens
SKILL.md length
730 words
Files
4 (incl. scripts, references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report.

  • Works in 4 steps: Verify the inputs are present → Generate the summary → Review the risk score → …
  • : closing an engagement
  • SKILL.md covers Overview, When the skill produces findings, Risk score (0-100) composition and Top-3 remediation priorities, plus 6 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Generating Executive Summary is an agent skill from jeremylongshore/tons-of-skills-marketplace. Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. Computes a single engagement risk score (0-100, severity-weighted with OWASP-breadth and governance terms), rolls up findings into headline counts, names the top-3 remediation priorities with effort + impact estimates, and produces a 1-2 page markdown document for a C-level or board audience. Elides technical detail; the vulnerability report is the deep document. Use when: closing an engagement, preparing the…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/PLAYBOOK.md`, `references/THEORY.md` and `scripts/exec_summary.py`). Compatibility notes: Designed for Claude Code

It sits in Security, covering Summarization, Web application vulnerabilities and Test coverage. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • : closing an engagement
  • Preparing the exec-readout meeting
  • Packaging for board review
  • Producing a one-page narrative for auditor / insurer / board

Example prompts

  • “generate exec summary”
  • “executive summary”
  • “C-level readout”
  • “/generating-executive-summary”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Bash(python3:*), Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Verify the inputs are present
  2. Generate the summary
  3. Review the risk score
  4. Hand off

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash(python3:*)
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Generating Executive Summary loads about 2.2k tokens when it runs, and up to ~5.9k if it reads all its reference files. Until then it costs about 220 tokens; SKILL.md has 730 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~220
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:28
    - Write(.env)
  • NoteMentions a .env fileSKILL.md:29
    - Edit(.env)

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 730 words, ~2,229 tokens.

Download SKILL.mdSave it as .claude/skills/generating-executive-summary/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
generating-executive-summary
description
Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. Computes a single engagement risk score (0-100, severity-weighted with OWASP-breadth and governance terms), rolls up findings into headline counts, names the top-3 remediation priorities with effort + impact estimates, and produces a 1-2 page markdown document for a C-level or board audience. Elides technical detail; the vulnerability report is the deep document. Use when: closing an engagement, preparing the exec-readout meeting, packaging for board review, or producing a one-page narrative for auditor / insurer / board. Threshold: input findings missing produces CRITICAL operational finding; otherwise the deliverable is the document itself. Trigger with: "generate exec summary", "executive summary", "C-level readout", "board pentest summary".
allowed-tools
Read, Write, Bash(python3:*), Glob
compatibility
Designed for Claude Code
disallowed-tools
Bash(rm:*), Bash(curl:*), Bash(wget:*), Write(.env), Edit(.env)
version
3.30.0
author
Jeremy Longshore <jeremy@intentsolutions.io>
license
MIT
tags
security, reporting, executive-summary, risk-score, pentest

Generating Executive Summary

Overview

The vulnerability report is comprehensive — every finding, full detail, every reference. The C-level reader doesn't open it. They ask their security lead "what should I tell the board?" The security lead needs a one-page answer.

That one-page answer is the executive summary. It states the engagement's bottom line:

  • A single risk score (0-100)
  • Headline counts by severity
  • Top-3 remediation priorities, each with rough effort + impact
  • OWASP Top 10 coverage (where the work landed)
  • Engagement scope and authorization summary (what was tested, under what authority, in what window)
  • Next steps the customer's organization should take

The summary doesn't omit anything important; it just compresses. The vulnerability report remains the deep artifact for anyone who needs the technical detail.

This skill consumes the enriched findings JSONL (after OWASP mapping) + the OWASP coverage report + the ROE, computes the risk score, picks the top remediation priorities deterministically, and renders the document.

When the skill produces findings

FindingSeverityThresholdAffected control
Input findings file missingCRITICALSource JSONL doesn't exist(operational)
OWASP coverage report missingHIGHCoverage referenced but not present(operational)
ROE missingMEDIUMCan still generate summary but lacks scope/authz context(operational)
Exec summary written cleanlyINFOConfirmation(informational)
Risk score >75 (high engagement risk)HIGHComputed risk score elevated(advisory)
Risk score >90 (critical engagement risk)CRITICALEngagement exposed material risk; needs urgent action(advisory)

Risk score (0-100) composition

The single risk score is the headline number on the exec summary. The composition is deterministic and documented:

risk = clamp(0, 100,
    20 * count(CRITICAL)
  + 10 * count(HIGH)
  +  3 * count(MEDIUM)
  +  1 * count(LOW)
  +  0 * count(INFO)
  +  5 * (count(distinct OWASP categories touched) - 5 if >5 else 0)
  - 10 * 1 if engagement was authorized cleanly and in-scope (governance bonus)
)

The first five terms weight by severity. The OWASP-coverage term adds 5 points per category beyond 5 (a broader-finding engagement implies broader risk surface). The governance bonus is a -10 adjustment when ROE was clean — explicit recognition that finding problems in a well-governed engagement is HEALTHIER than finding the same problems in a chaotic engagement.

Score interpretation:

ScoreReading
0-25Low risk: clean engagement OR very narrow scope
26-50Moderate risk: typical engagement with manageable findings
51-75Elevated risk: significant findings, remediation planning required
76-90High risk: material findings; executive attention warranted
91-100Critical risk: urgent remediation required; consider treating as incident

Top-3 remediation priorities

The skill picks top-3 priorities deterministically by:

  1. Severity (CRITICAL > HIGH > MEDIUM > LOW)
  2. Reachability — findings affecting many targets weight higher
  3. Tie-breaker: alphabetical by title for stable output

Each priority gets:

  • A one-line headline
  • Estimated effort (Hours / Days / Weeks)
  • Estimated impact (Limited / Significant / Material)
  • Pointer to the corresponding finding section in the vulnerability report

Effort + impact are heuristic estimates based on the source skill's category — operator can override via --priority-overrides for cases where the heuristic is wrong.

Show full SKILL.md (297 more words)Show less

Prerequisites

  • Python 3.9+
  • Findings JSONL at engagement/findings/all-with-owasp.jsonl (output of mapping-findings-to-owasp-top10) OR an explicit --source FILE
  • OWASP coverage report at engagement/reports/owasp-coverage.md (referenced; optional)
  • ROE at engagement/roe.yaml (referenced for scope summary)

Instructions

Step 1 — Verify the inputs are present
bash
ls engagements/acme-2026-q2/findings/all-with-owasp.jsonl
ls engagements/acme-2026-q2/reports/owasp-coverage.md
ls engagements/acme-2026-q2/roe.yaml

All three should exist for a complete summary. The skill works without the coverage report or ROE but the summary is less complete.

Step 2 — Generate the summary
bash
python3 ./scripts/exec_summary.py engagements/acme-2026-q2/

Options:

Usage: exec_summary.py PATH [OPTIONS]

Options:
  --source FILE              Findings JSONL (default: PATH/findings/all-with-owasp.jsonl)
  --coverage FILE            OWASP coverage report (default: PATH/reports/owasp-coverage.md)
  --roe FILE                 ROE (default: PATH/roe.yaml)
  --summary-output FILE      Output path (default: PATH/reports/executive-summary.md)
  --output FILE              Operational findings output
  --format FMT               json | jsonl | markdown (default: markdown)
  --min-severity SEV         default info
  --priority-overrides FILE  YAML overriding the top-3 priorities
Step 3 — Review the risk score

If the score is in 76-100 range, the operator should sanity-check before delivering: did the underlying findings actually warrant the elevated reading, or did a few INFO-tagged findings get mis-categorized as HIGH?

Step 4 — Hand off

The exec summary is intended as a standalone artifact. Deliver to the customer's exec readout meeting, along with the full vulnerability report.

Examples

Example 1 — End-of-engagement summary
bash
python3 ./scripts/exec_summary.py engagements/acme-2026-q2/
Example 2 — Board-ready summary (force-includes governance section)
bash
python3 ./scripts/exec_summary.py engagements/acme-2026-q2/ \
    --summary-output engagements/acme-2026-q2/reports/board-summary.md
Example 3 — Override priorities
yaml
# priorities-override.yaml
- title: "Hardcoded AWS access key in source"
  effort: Hours
  impact: Material
  rationale: This is the single highest-priority remediation regardless of count.
bash
python3 ./scripts/exec_summary.py engagements/acme-2026-q2/ \
    --priority-overrides priorities-override.yaml

Output

JSON / JSONL / Markdown per lib/report.py for operational findings. PRIMARY output: the executive-summary markdown document.

Operational Finding includes:

  • id — exec::<issue>
  • severity — varies
  • category — executive-summary
  • summary — what was generated
  • evidence — risk score, finding count, top priorities, output path

Error Handling

  • No findings source → CRITICAL operational finding, exits 1.
  • Source JSONL unparseable → HIGH, exits 1.
  • No findings at all → emits LOW operational finding noting the empty engagement; the document is generated but says so.
  • Coverage report missing → MEDIUM, document is generated without the coverage-narrative section.
  • ROE missing → MEDIUM, document is generated without the scope/authorization section.

Resources

  • references/THEORY.md — Executive-summary writing as a technical-communication discipline, single-number risk scoring tradeoffs, why deterministic priority selection beats human-curated for reproducibility, how the score interpretation bands were chosen, comparison with CVSS / DREAD / STRIDE risk models
  • references/PLAYBOOK.md — Per-audience customizations (board, C-suite, security leadership, customer auditor), summary length guidelines, common rewrite patterns, integration with the composing + mapping skills, post-delivery follow-up cadence

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/.curated/generating-executive-summary of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/PLAYBOOK.md
  • references/THEORY.md
  • scripts/exec_summary.py

Open the folder on GitHubat commit cfae287

Compare with similar skills

Generating Executive Summary next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Generating Executive Summary compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Generating Executive Summary this skilljeremylongshore/tons-of-skills-marketplace2.8k—~2.2kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone
Fix Strix Security Findingsusestrix/strix68k—~1.5kAutomated safety check: PassApache-2.0
Wooyun Legacytanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassCustom licence
OWASP Top 10 Testing with Strixusestrix/strix68k—~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    68k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed
  • Wooyun Legacy

    tanweai/wooyun-legacy

    WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

    1.8k GitHub stars~1.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.

    68k GitHub stars~1.6k tokensUpdated today
    SecurityAuto-check passed
  • Client Request Signature Reversal

    awarexone/Agentic-Bug-Hunter

    Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

    5.3k GitHub stars~4.7k tokensUpdated yesterday
    SecurityAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Generating Executive Summary

What does Generating Executive Summary do?

Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report. Generating Executive Summary is an agent skill from jeremylongshore/tons-of-skills-marketplace. Compose an exec-readable summary from a unified findings JSONL plus the OWASP coverage report.

When should I use Generating Executive Summary?

Generating Executive Summary fits situations like: : closing an engagement; preparing the exec-readout meeting; packaging for board review; producing a one-page narrative for auditor / insurer / board.

How do I install Generating Executive Summary in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a claude-code`. Or copy the skill folder (skills/.curated/generating-executive-summary in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/generating-executive-summary in your project. Claude Code loads it when a task matches its description.

How do I install Generating Executive Summary in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a codex`. Or copy the skill folder (skills/.curated/generating-executive-summary in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/generating-executive-summary in your project. Codex loads it when a task matches its description.

Can I use Generating Executive Summary in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill generating-executive-summary -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/generating-executive-summary, .gemini/skills/generating-executive-summary, .github/skills/generating-executive-summary and .opencode/skills/generating-executive-summary in your project.

What does Generating Executive Summary need to run?

Going by SKILL.md and its folder, Generating Executive Summary needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Bash(python3:*), Glob. Compatibility (from SKILL.md): Designed for Claude Code.

Does Generating Executive Summary access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Generating Executive Summary safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Generating Executive Summary use?

Generating Executive Summary is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Generating Executive Summary use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.6k tokens, read only when the agent opens those files.

What are the alternatives to Generating Executive Summary?

Skills that share tags, products or a category with Generating Executive Summary: Strix Code Vulnerability Scan (usestrix/strix, 68k stars), Code Audit (3stoneBrother/code-audit, 892 stars), Fix Strix Security Findings (usestrix/strix, 68k stars) and Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Generating Executive Summary?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.