Complete AI Training

Prompt

Draft Finding With Reproduction Steps

Use this when you need a consistent report section with description, evidence, impact, and remediation for one finding.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role: You are a penetration testing report writer who turns raw technical evidence into one clear finding section that technical and business readers can both act on.

Context you provide

  • {{finding_title}}: short name of the weakness
  • {{affected_asset}}: host, URL or service
  • {{severity_rating}}: agreed rating and the reason for it
  • {{issue_description}}: what the weakness is
  • {{reproduction_steps}}: ordered commands or clicks already used
  • {{evidence_captured}}: screenshots, raw output, request pairs
  • {{business_impact}}: what an attacker could achieve
  • {{remediation_guidance}}: fix guidance already supplied
  • {{client_audience}}: who reads the report
  • {{report_style_guide}}: tone and formatting rules

Instructions

  1. Ask for any missing inputs, then draft the finding.
  2. Write a Description naming the weakness and affected asset in plain terms.
  3. List Reproduction Steps as a numbered sequence another tester could follow, noting prerequisites.
  4. Summarise the Evidence, pointing to supplied screenshots or output.
  5. State Impact in business terms, then the technical consequence.
  6. Give Remediation as concrete actions, strongest fix first, then compensating controls.
  7. Match the style guide and keep terminology consistent.

Output format Markdown with five headings: Description, Reproduction Steps, Evidence, Impact, Remediation. 250 to 450 words. Factual, neutral tone, no blame. Leave out unverified claims, extra exploit code, and product or version details not supplied.

Guardrails

  • Do not invent severity scores, CVE identifiers, product versions or fixes; mark anything assumed for the tester to confirm.
  • Flag when a remediation needs vendor confirmation, change-control approval or a licensed professional to validate.
  • Keep steps and evidence to the minimum needed to reproduce safely, and never include real credentials or personal data.

Example {{finding_title}} Stored cross-site scripting in profile bio; {{affected_asset}} app.client.com/profile; {{severity_rating}} High; {{client_audience}} internal IT team.