Agent skill

Transilience Report Style

by transilienceai in transilienceai/communitytools

Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator.

MITAuto-check passedSecurity

Install Transilience Report Style

skills CLI
$ npx skills add transilienceai/communitytools --skill transilience-report-style -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install transilienceai/communitytools transilience-report-style --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/transilienceai/communitytools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/transilience-report-style .claude/skills/transilience-report-style && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
transilience-report-style
GitHub stars
563
Token cost
~1.7k tokens
SKILL.md length
642 words
Files
5
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator.

  • Works in 3 steps: Write report_data.json matching… → Run the generator → Verify by rendering a page (pdftoppm…
  • An engagement needs its final report/deliverable PDF in Transilience house style
  • SKILL.md covers When to use, How to use (3 steps), What it renders and Finding object (the important…, plus 2 more sections
  • Runs Python scripts from its folder; calls python3, pip and pdftoppm

What it does

Transilience Report Style is an agent skill from transilienceai/communitytools. Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator. Use whenever an engagement needs its final report/deliverable PDF in Transilience house style.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `reference/example-report-data.json`, `reference/generate_report.py` and `reference/report-data-schema.json`).

It sits in Security, covering Penetration testing and PDF. It works with pypdf. The repository describes itself as: Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research. The licence is MIT.

When your agent uses it

  • An engagement needs its final report/deliverable PDF in Transilience house style
  • Tasks that involve Penetration testing
  • Tasks that involve PDF

Example prompts

  • “/transilience-report-style”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Write report_data.json matching reference/report-data-schema.json. Only engagement and findings are required; every other key…
  2. Run the generator
  3. Verify by rendering a page (pdftoppm -png -r 100 -f 1 -l 1 out.pdf /tmp/p) and reading it before delivery.

What it can do on your machine

Read from SKILL.md and the folder at commit 95fdc12. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • pip
    • pdftoppm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Transilience Report Style loads about 1.7k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 642 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~71
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from transilienceai/communitytools at commit 95fdc12, republished under its MIT licence (© transilienceai). 642 words, ~1,695 tokens.

Download SKILL.mdSave it as .claude/skills/transilience-report-style/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
transilience-report-style
description
Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator. Use whenever an engagement needs its final report/deliverable PDF in Transilience house style.

Transilience Report Style

Turns a structured findings JSON into a branded A4 PDF (light theme by default — modern/minimal; --theme dark fallback; brand gradient rule, boxed code/samples, framed screenshots, colour-coded severity + CVSS-score, findings cards, severity metrics) — the standard Transilience deliverable. The generator is data-driven: you assemble one JSON, run one command. Design system: formats/transilience-report-style/SKILL.md §0 (theme/palette).

When to use

  • A pentest / vuln-assessment / network-scan / compliance engagement is finished and validated and needs its PDF deliverable.
  • You already have findings (ideally validated) with severity + CVSS + evidence + remediation.

How to use (3 steps)

  1. Write report_data.json matching reference/report-data-schema.json. Only engagement and findings are required; every other key (executive_summary, metrics, sections, cve_register, coverage_table, attack_pattern_coverage, ruled_out, tools_used, roadmap, disclaimer) is an optional section that is skipped if absent. See reference/example-report-data.json for a minimal working file.

    • Internal-only sections: a sections[] entry with "internal": true is retained in report_data.json (kept as the internal record) but is never rendered into the client PDF. Use it for internal QA logs such as blind-validation / independent-reproduction verdict tables — these must not appear in any client-facing PDF.
  2. Run the generator:

    bash
    python3 reference/generate_report.py <report_data.json> -o reports/My-Report.pdf

    Fonts + logo are auto-discovered from formats/transilience-report-style/. Override with --assets <dir> if running outside the repo. Requires reportlab (pip install reportlab).

  3. Verify by rendering a page (pdftoppm -png -r 100 -f 1 -l 1 out.pdf /tmp/p) and reading it before delivery.

Other editions of the same data
  • Executive edition — generate_report.py <data.json> --exec-only renders cover + KPI boxes + narrative + roadmap and no finding detail or technical registers, for circulation beyond the security team. The KPI counts still describe the whole engagement.
  • Machine-readable exports — python3 ../../tools/report_export.py <data.json> --format csv|xml -o findings.csv emits the findings register for a vulnerability-management import. Same rows as the PDF register and the xlsx: one projection, three renderings.

What it renders

Cover (logo, title lines, subtitle, metadata) → Executive Summary (auto KPI metric boxes from severity counts + narrative + key risks + positives) → free-form sections (Scope/Methodology) → finding cards grouped Critical→Info (severity bar, CVSS+vector, CWE/OWASP, status, affected, description, impact, optional PoC block — ordered steps each with prose + code-styled command + embedded screenshot, optional severity-calibration, optional per-finding CVE table, remediation) → optional CVE register, coverage table, Attack Pattern Coverage (deterministic surface-unit × attack-class matrix with colour-coded status), ruled-out appendix, Tools & Techniques Used, remediation roadmap, disclaimer. Section numbers are assigned automatically.

Show full SKILL.md (271 more words)Show less

Finding object (the important fields)

id, title, severity (Critical|High|Medium|Low|Info), cvss_score, cvss_vector, cwe, owasp, affected[], description, impact, recommendation + optional poc[], calibration, needs_live_confirmation, cves[], attack[]. attack[] carries MITRE technique ids — ATT&CK (T1190, T1059.001) or, for AI/LLM findings that have no ATT&CK technique, ATLAS (AML.T0051); it renders beside CWE/OWASP and appears in every export. poc is an ordered list of steps {description, command, image_url} (it merges the former evidence / poc_request / screenshot fields): each renders as a numbered prose description, an optional code-styled command, and an optional embedded image. PAN/Aadhaar/card-like values are defensively masked at render time — but redact real secrets/PII in your source text anyway.

Conventions

  • Severity is set by the CVSS band (≥9 Critical, ≥7 High, ≥4 Medium, >0 Low, 0 Info) unless deliberately env-adjusted — state the calibration in the calibration field (see formats/transilience-report-style/pentest-report.md §7).
  • No emoji; text severity labels only. Finding metadata as fields, not prose.
  • One finding = one validated issue. Group systemic instances rather than repeating near-duplicates.

References

© transilienceai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files in skills/transilience-report-style of transilienceai/communitytools.

  • SKILL.md
  • reference/example-report-data.json
  • reference/generate_report.py
  • reference/report-data-schema.json
  • reference/test_generate_report.py

Open the folder on GitHubat commit 95fdc12

Compare with similar skills

Transilience Report Style next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Transilience Report Style compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Transilience Report Style this skilltransilienceai/communitytools563—~1.7kAutomated safety check: PassMIT
Lov Any2pdflovstudio/any2pdf211—~2.4kAutomated safety check: NotesMIT
PDF ToolkitXiaomiMiMo/MiMo-Code14k—~1.7kAutomated safety check: PassApache-2.0
PDF Generation, Forms and Extractionpipeshub-ai/pipeshub-ai3.8k—~2.9kAutomated safety check: PassApache-2.0
PDFNousResearch/hermes-agent253k—~3.1kAutomated safety check: PassMIT
PDF ExploreHughYau/AcademicForge2.6k—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Lov Any2pdf

    lovstudio/any2pdf

    Convert Markdown documents to professionally typeset PDF files with reportlab.

    211 GitHub stars~2.4k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check: notes
  • PDF Toolkit

    XiaomiMiMo/MiMo-Code

    Reads, transforms, composes and fills PDFs with Python scripts for extraction, merging, watermarking, encryption, OCR and form filling.

    14k GitHub stars~1.7k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • Picks the right library for generating a new PDF, filling an existing PDF form, or extracting text and tables, defaulting to Node where possible.

    3.8k GitHub stars~2.9k tokensUpdated today
    Documents & OfficeAuto-check passed
  • PDF

    NousResearch/hermes-agent

    PDF files: create, read, merge, fill, OCR, edit text. An agent skill from NousResearch/hermes-agent.

    253k GitHub stars~3.1k tokensUpdated today
    Documents & OfficeAuto-check passed
  • PDF Explore

    HughYau/AcademicForge

    A skill your agent uses when the user has attached a PDF, paper, report, or other document and the answer needs content from more than one place in it: summarize the methods or any other section…

    2.6k GitHub stars~3.1k tokensUpdated 1 mo ago
    Documents & OfficeAuto-check passed
  • File Format Conversion

    pipeshub-ai/pipeshub-ai

    Picks the right library for converting between CSV, XLSX, JSON, images, DOCX and PDF text, and lists the conversions that are not supported so the agent does not attempt them.

    3.8k GitHub stars~865 tokensUpdated today
    Documents & OfficeAuto-check passed

More from transilienceai/communitytools

All 35 skills in this repo
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    563 GitHub stars~812 tokensUpdated 2 mo ago
    Auto-check: notes
  • Pci Secure Software

    transilienceai/communitytools

    Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

    563 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    563 GitHub stars~583 tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Update

    transilienceai/communitytools

    Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    563 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check: notes

Works with

Questions about Transilience Report Style

What does Transilience Report Style do?

Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator. Transilience Report Style is an agent skill from transilienceai/communitytools. Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator.

When should I use Transilience Report Style?

Transilience Report Style fits situations like: an engagement needs its final report/deliverable PDF in Transilience house style; tasks that involve Penetration testing; tasks that involve PDF.

How do I install Transilience Report Style in Claude Code?

Run `npx skills add transilienceai/communitytools --skill transilience-report-style -a claude-code`. Or copy the skill folder (skills/transilience-report-style in transilienceai/communitytools) into .claude/skills/transilience-report-style in your project. Claude Code loads it when a task matches its description.

How do I install Transilience Report Style in Codex?

Run `npx skills add transilienceai/communitytools --skill transilience-report-style -a codex`. Or copy the skill folder (skills/transilience-report-style in transilienceai/communitytools) into .agents/skills/transilience-report-style in your project. Codex loads it when a task matches its description.

Can I use Transilience Report Style in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add transilienceai/communitytools --skill transilience-report-style -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/transilience-report-style, .gemini/skills/transilience-report-style, .github/skills/transilience-report-style and .opencode/skills/transilience-report-style in your project.

What does Transilience Report Style need to run?

Going by SKILL.md and its folder, Transilience Report Style needs Python for the scripts in its folder and the command-line tools its instructions call (python3, pip and pdftoppm). Our summary lists: Python 3.

Does Transilience Report Style access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Transilience Report Style safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Transilience Report Style use?

Transilience Report Style is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Transilience Report Style use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Transilience Report Style?

Skills that share tags, products or a category with Transilience Report Style: Lov Any2pdf (lovstudio/any2pdf, 211 stars), PDF Toolkit (XiaomiMiMo/MiMo-Code, 14k stars), PDF Generation, Forms and Extraction (pipeshub-ai/pipeshub-ai, 3.8k stars) and PDF (NousResearch/hermes-agent, 253k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Transilience Report Style?

transilienceai (a GitHub organization) maintains it in transilienceai/communitytools, which has 563 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on July 29, 2026.

Source: transilienceai/communitytools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.