Finding Writer by Gregory Towns
Compose one clean, di Compose one clear, disclosure-ready vulnerability write-up. Offline, no accounts, no network. sclosure-ready vulnerability write-up. Offline, no accounts, no network.
Extension Metadata
About this extension
Finding Writer turns a vulnerability you found in your own lab into a clean, disclosure-ready
write-up. You describe the finding once, score it, and export a report you can paste into a
lab write-up, a bug-bounty submission, or your coursework.
It is built for people learning offensive security: students working through Hack The Box,
TryHackMe, or a local Kali VM, and anyone studying toward CEH, OSCP, or CompTIA Security+. You
already know a finding when you see one; this tool helps you write it up so a defender can act
on it.
What you get:
Privacy, by design:
CVSS is owned by FIRST and used by permission. Category codes reference the OWASP Web Security
Testing Guide, licensed CC BY-SA 4.0.
write-up. You describe the finding once, score it, and export a report you can paste into a
lab write-up, a bug-bounty submission, or your coursework.
It is built for people learning offensive security: students working through Hack The Box,
TryHackMe, or a local Kali VM, and anyone studying toward CEH, OSCP, or CompTIA Security+. You
already know a finding when you see one; this tool helps you write it up so a defender can act
on it.
What you get:
- A guided form with inline coaching on each part of a finding: title, affected asset,
reproduction steps, impact, remediation, and a disclosure note. - A built-in CVSS calculator for both version 3.1 and version 4.0, with the base score,
severity, and vector string shown as you set each metric. - An optional OWASP WSTG category reference so a reader can place the finding in a methodology.
- A live preview, plus one-click export to Markdown or a self-contained HTML file.
Privacy, by design:
- Everything you enter stays in your browser. Finding Writer makes no network requests and
keeps no account. - It asks for a single permission, local storage, used only to save your draft so it
survives closing the tab. - Use it for your own practice targets and authorised tests. It is a study aid, not a place
for confidential client findings.
CVSS is owned by FIRST and used by permission. Category codes reference the OWASP Web Security
Testing Guide, licensed CC BY-SA 4.0.
Rated 0 by 0 reviewers
Permissions and data
More information
- Add-on Links
- Version
- 1.0.0
- Size
- 71.78 KB
- Last updated
- 11 days ago (Sep 15, 2026)
- Related Categories
- License
- All Rights Reserved
- Privacy Policy
- Read the privacy policy for this add-on
- Version History
- Add to collection