CtrlK
BlogDocsLog inGet started
Tessl Logo

redteam-report-template

Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendation / PoC structure used for external red-team engagements (not bug-bounty platform reports). Different audience, different tone, different cadence. Built from an authorized engagement deliverable where 14 findings were packaged into a 52KB MD + 2.2MB DOCX with 16 embedded screenshots. Use when the engagement is "external red team for an enterprise client" (not H1/Bugcrowd/Intigriti), when generating the final report, when the client has specified a custom report format, or when packaging findings into DOCX/PDF.

71

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

High

Do not use without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

77%

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced body with executable code and a strong delivery checklist, but it is long for a SKILL.md and leans on engagement-provenance metrics as filler; the template-library references are signposted but not backed by actual bundle files, leaving progressive disclosure partially unrealized.

Suggestions

Trim or move the 'Real engagement metric' calibration numbers (byte counts, paragraph/heading counts) — they pad context without guiding action; keep at most the finding-count breakdown if calibration matters.

Materialize the referenced templates/ bundle (executive_summary.md, methodology.md, cleanup_statement.md, reference.docx) so the signposted one-level-deep references actually resolve, moving the canned boilerplate out of SKILL.md to lift progressive_disclosure.

Move the 'Audience translation' and 'Findings that are sometimes wrongly excluded' illustrative tables into a reference file, keeping SKILL.md as the overview pointing to them.

DimensionReasoningScore

Conciseness

Mostly efficient and well-organized, but at ~340 lines it over-explains context Claude largely already knows — e.g. the "Real engagement metric" section (52,737 bytes / 2,262,484 bytes DOCX / 414 paragraphs) and the exhaustive DOCX byte-counts are calibration padding that competes with context for little actionable value.

2 / 3

Actionability

Provides copy-paste-ready executable guidance throughout — a complete runnable pandoc command, a python3-docx verification snippet, a concrete image filename convention with examples, and a fully populated 6-section finding template with sample HTTP requests.

3 / 3

Workflow Clarity

Multi-step processes are explicitly sequenced with validation checkpoints — the DOCX pipeline ends in a programmatic image-count verification, and the "Quality checks before delivery" is a 12-item checklist functioning as a feedback loop that catches errors before delivery.

3 / 3

Progressive Disclosure

The body references external materials (templates/executive_summary.md, reference.docx, etc.) but these are described as future boilerplate to maintain rather than provided bundle files — no references/, scripts/, or assets/ directories exist — so navigation is signaled but the split is not actually realized, and the 340-line SKILL.md itself carries content that could live in those template files.

2 / 3

Total

10

/

12

Passed

Description

100%

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, explicit "Use when" triggers, and active disambiguation against the neighboring bug-bounty reporting skills. The engagement-provenance detail (14 findings, 52KB/2.2MB) adds credibility without obscuring the trigger logic.

DimensionReasoningScore

Specificity

Lists multiple concrete actions and structural elements — "codifies the Subject / Observations / Description / Impact / Recommendation / PoC structure" and "packaging findings into DOCX/PDF" — naming specific deliverable artifacts rather than vague verbs.

3 / 3

Completeness

Explicitly answers both what ("client-facing red-team deliverable format ... codifies the ... structure") and when ("Use when the engagement is 'external red team for an enterprise client' ... when generating the final report ... when packaging findings into DOCX/PDF").

3 / 3

Trigger Term Quality

Covers natural user-facing terms — "external red team," "final report," "custom report format," "DOCX/PDF," "packaging findings" — alongside explicit platform negations (H1/Bugcrowd/Intigriti) a user would actually mention.

3 / 3

Distinctiveness Conflict Risk

Carves a clear niche — external red-team / enterprise client deliverables — and explicitly negates the overlapping bug-bounty case ("not bug-bounty platform reports," "not H1/Bugcrowd/Intigriti"), making wrong-skill triggering unlikely.

3 / 3

Total

12

/

12

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

relative_links

Relative link issues: 1 missing

Warning

Total

14

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.