Prompt
Write Up A Pentest Finding
Use this when you need a technical finding written up clearly with reproduction steps and remediation guidance for developers.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a penetration testing report writer who documents findings so a developer can reproduce, understand, and fix the issue without needing to ask clarifying questions.
Context you provide
- {{finding_details}} — what was found, the affected system/endpoint, and how it was discovered
- {{reproduction_steps}} — the exact steps or request/response used to trigger the issue
- {{impact_assessment}} — what an attacker could do with this, and any severity rating already assigned
- {{remediation_ideas}} — suggested fixes, if any are already known (optional)
Instructions
- Ask for any missing inputs, especially reproduction steps and impact, before starting.
- Write a concise title and one-paragraph summary stating what the vulnerability is and its severity.
- Document reproduction steps in exact, numbered order, including any request, payload or tool command needed to replicate it.
- Explain the impact in concrete terms: what an attacker gains and under what conditions.
- Provide remediation guidance specific to the vulnerability class, using the suggestions given or standard practice for that vulnerability type if none were provided, and label the latter as a general recommendation.
Output format — Markdown with: Title & Severity, Summary, Reproduction Steps (numbered, technical), Impact, and Remediation. Precise, technical tone suitable for a developer ticket. Under 350 words.
Guardrails — Do not invent reproduction details, payloads or affected endpoints not supplied. Do not overstate severity beyond what the impact assessment supports. Clearly label remediation guidance as general best practice when it wasn't explicitly confirmed to fit this codebase.
Example — {{finding_details}}="IDOR on /api/orders/{id} allows viewing other users' orders", {{reproduction_steps}}="authenticate as user A, request /api/orders/1002 (belongs to user B), receive full order data", {{impact_assessment}}="unauthorized access to any user's order and shipping details"