security / tooling 2026

Pentest Report Builder

Technical test data turned into client-ready security reports. Test planning, evidence, vulnerability classification and client communication all come from the same structured source data.

What it does

Started as a tool to generate professional reports with a consistent layout, fixed insertable elements to save time, and a number of automatic tools to simplify ranking, classification and the like.

Expanded with a task list that on one hand brings structure to the way testing is done, and on the other offers the client a transparent overview by showing which tests were run on which endpoints.

Report sections

SectionContent
Executive summaryRisk table at management level - understandable without technical background.
OWASP Top 10Overview per vulnerability category, automatically built from findings.
Severity overviewAggregation of all findings per criticality level.
Finding pagesIndividual page per vulnerability - description, impact, evidence, remediation.
Endpoint coverageMatrix of which endpoints were tested for which vulnerability types.
Task boardOperational planning as evidence - shows scope, progress and links to findings.
Exploit annexTechnical details of executed exploit chains.
Remediation planPrioritized action list for the dev team.

The tasklist layer

Every task gets a unique ID linked to the Caido Replay collections. This keeps test tasks, requests, payloads and technical evidence logically connected to the report structure.

Every task describes which vulnerability category was tested, which endpoints were involved, the associated OWASP category, the status and any linked findings. During testing, this brings structure to execution. After the test, the same data is used as evidence toward the client.

The report shows not only which vulnerabilities were found, but also which endpoints were tested for which vulnerability types. That makes the final report more defensible.

The end product

A single-file HTML report: standalone, clickable and searchable. All CSS, JavaScript and images are embedded so the report can be shared or archived without extra dependencies. The client gets one navigable file.

PDF export via WeasyPrint for those who need it. Both formats come from the same source data with no extra manual work.

Technical stack

ToolRole
QuartoMarkdown-to-HTML render engine - write in plain text, output a professional report.
PythonPre-render scripts for parsing YAML source data and report generation.
Lua filtersAutomatic finding headers and cross-references within the report.
DockerReproducible builds - same output on every machine.
MonolithStandalone HTML export - all assets embedded in one file.
WeasyPrintPDF export from the same source data.
VS Code snippetsFast, consistent reporting - less typing, fewer errors.

Status

Developed during my internship at Fox&Fish Cyberdefence, further personalized and expanded into my daily work tool for running pentests.