{
  "slug": "report",
  "name": "Write the report",
  "category": "Research",
  "summary": "Produce a concise security record that separates observed evidence, bounded impact, uncertainty, and remediation.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Authorized observations",
    "Affected boundary and policy expectation",
    "Vendor or primary-source remediation context"
  ],
  "review": [
    {
      "title": "State the boundary",
      "body": "Name the intended security property, who or what it protects, and the precise condition that did not hold."
    },
    {
      "title": "Separate evidence from inference",
      "body": "Mark direct observations, reproduced local results, modeled impact, and unanswered questions distinctly."
    },
    {
      "title": "Minimize sensitive material",
      "body": "Use owned, redacted evidence that lets maintainers understand the issue without exposing unnecessary data or instructions."
    },
    {
      "title": "Make the fix testable",
      "body": "Recommend a control and a regression assertion tied to the failed invariant."
    }
  ],
  "outputs": [
    "Evidence-bounded finding",
    "Impact and uncertainty statement",
    "Testable remediation criteria"
  ],
  "pitfalls": [
    "Claiming impact beyond evidence",
    "Including secrets or third-party data",
    "Describing a fix without a security invariant"
  ],
  "references": {
    "resources": [
      {
        "id": "hackerone-quality-vulnerability-reports",
        "title": "Quality Reports",
        "url": "https://vulns.co/research/resources/hackerone-quality-vulnerability-reports/"
      },
      {
        "id": "owasp-security-logging-evidence-quality",
        "title": "OWASP Logging: trustworthy and minimal application evidence",
        "url": "https://vulns.co/research/resources/owasp-security-logging-evidence-quality/"
      },
      {
        "id": "owasp-secure-code-review-methodology",
        "title": "OWASP Secure Code Review: baseline and change-focused review",
        "url": "https://vulns.co/research/resources/owasp-secure-code-review-methodology/"
      }
    ],
    "diagrams": [
      {
        "id": "approval-version-integrity",
        "title": "Approval stays attached to the reviewed version",
        "url": "https://vulns.co/research/diagrams/approval-version-integrity/"
      }
    ],
    "reports": [
      {
        "id": "google-cloud-build-approval-toctou-2025",
        "title": "Cloud Build approval was not bound to immutable code",
        "url": "https://vulns.co/research/reports/google-cloud-build-approval-toctou-2025/"
      },
      {
        "id": "github-actions-reference-validation-2021",
        "title": "GitHub Actions trust depended on invalid repository references",
        "url": "https://vulns.co/research/reports/github-actions-reference-validation-2021/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/report/",
  "markdown_url": "https://vulns.co/skills/report/SKILL.md"
}
