Bundle catalog

deliverables bundle

Security Assessment / Pen-Test Report

A free, open-source set of 4 Markdown files for drafting and reviewing Security Assessment / Pen-Test Report with explicit evidence, constraints, and approval boundaries.

Use this bundle to draft or review Security Assessment / Pen-Test Report with source evidence, open questions, owners, and approval gates kept explicit. The page previews a deliverable guide and an overview; the intended output is security assessment report and penetration-test report. Start source review with NIST SP 800-115.

Project-reviewed beta

4 Markdown files · 1,052 words · no signup · CC-BY-4.0

Inspect before downloading

See what is inside

These previews come from the published bundle files, so you can judge the method and writing before using it.

Is this bundle right for your task?

Who it is for

  • People drafting, reviewing, approving, or relying on Security Assessment / Pen-Test Report
  • Teams working in software, saas, information security

When to use it

  • A Security Assessment / Pen-Test Report draft needs a clear purpose, audience, evidence base, structure, and approval path.
  • An existing draft needs unsupported claims, missing sections, unresolved decisions, and reviewer comments addressed.

What you need to provide

  • The document purpose, audience, source evidence, required sections, constraints, approvers, and intended decision or action.
  • Existing drafts, templates, policies, examples, terminology, and review criteria that the output must follow.

Tasks and expected outputs

Questions it helps answer

  • structure a reviewable security assessment report
  • separate tester evidence from business risk decisions
  • prevent invented findings, severity, remediation, and authorization claims

What it helps produce

  • security assessment report
  • penetration-test report
  • finding review

Practical example

Use it with an agent

Load the bundle as context, provide the evidence named above, then adapt this example to your situation.

Provide the document purpose, audience, source evidence, required sections, constraints, approvers, and intended decision or action. Ask the agent to draft or review Security Assessment / Pen-Test Report and return security assessment report with material claims tied to evidence and assumptions, open questions, reviewers, and approval gates marked. Begin with NIST SP 800-115, then confirm that the reference is current and applicable. Inspect Security Assessment / Pen-Test Report source-backed guide before drafting.

Context path: bundles/deliverables/security-assessment-report

What the bundle includes

Frameworks

  • NIST SP 800-115
  • OWASP WSTG
  • PTES reporting
  • CVSS v4.0

Evaluations

  • security assessment report quality check

Sources used to build this bundle

These are the public references behind the role definition and operating guidance. The bundle does not replace current documentation or evidence from your site.

Limitations and safe use

Do not use this for

  • Publishing, approving, or acting on a draft before its material claims, source evidence, owners, and approval gates have been reviewed.

Known limitations

  • This bundle is a drafting and review aid, not authorization to test systems, legal or regulatory advice, an audit opinion, or proof of remediation.
  • Local scope, authorization, affected assets, evidence, dates, severity inputs, business impact, owners, deadlines, retest results, and approvals require current supplied or inspected evidence.
  • Do not infer findings, CVSS vectors, risk ratings, compliance status, remediation state, or accountable reviewers.

Safety notes

  • Minimize and redact sensitive evidence, secrets, credentials, personal data, and client identifiers.
  • Require explicit confirmation before disclosure, external distribution, risk acceptance, remediation-state changes, or live-system action.
  • Treat the bundle as a source-backed drafting aid and route qualified security, legal, privacy, compliance, and risk decisions to accountable reviewers.

Next step

Inspect it before relying on it

Download the bundle for use, review its source files and evidence, or read the agent guidance. If the project is useful, starring the repository helps others discover it.