What it does
Started as a tool to generate professional reports with a consistent layout, fixed insertable elements to save time, and a number of automatic tools to simplify ranking, classification and the like.
Expanded with a task list that on one hand brings structure to the way testing is done, and on the other offers the client a transparent overview by showing which tests were run on which endpoints.
Report sections
| Section | Content |
|---|---|
| Executive summary | Risk table at management level - understandable without technical background. |
| OWASP Top 10 | Overview per vulnerability category, automatically built from findings. |
| Severity overview | Aggregation of all findings per criticality level. |
| Finding pages | Individual page per vulnerability - description, impact, evidence, remediation. |
| Endpoint coverage | Matrix of which endpoints were tested for which vulnerability types. |
| Task board | Operational planning as evidence - shows scope, progress and links to findings. |
| Exploit annex | Technical details of executed exploit chains. |
| Remediation plan | Prioritized action list for the dev team. |
The tasklist layer
Every task gets a unique ID linked to the Caido Replay collections. This keeps test tasks, requests, payloads and technical evidence logically connected to the report structure.
Every task describes which vulnerability category was tested, which endpoints were involved, the associated OWASP category, the status and any linked findings. During testing, this brings structure to execution. After the test, the same data is used as evidence toward the client.
The report shows not only which vulnerabilities were found, but also which endpoints were tested for which vulnerability types. That makes the final report more defensible.
The end product
A single-file HTML report: standalone, clickable and searchable. All CSS, JavaScript and images are embedded so the report can be shared or archived without extra dependencies. The client gets one navigable file.
PDF export via WeasyPrint for those who need it. Both formats come from the same source data with no extra manual work.
Technical stack
| Tool | Role |
|---|---|
| Quarto | Markdown-to-HTML render engine - write in plain text, output a professional report. |
| Python | Pre-render scripts for parsing YAML source data and report generation. |
| Lua filters | Automatic finding headers and cross-references within the report. |
| Docker | Reproducible builds - same output on every machine. |
| Monolith | Standalone HTML export - all assets embedded in one file. |
| WeasyPrint | PDF export from the same source data. |
| VS Code snippets | Fast, consistent reporting - less typing, fewer errors. |
Status
Developed during my internship at Fox&Fish Cyberdefence, further personalized and expanded into my daily work tool for running pentests.