Our security team just tried using Claw (the AI writing assistant) to help draft penetration test reports. We usually spend days on the write-up after the actual testing.
We fed it our raw findings: vulnerability names, CVSS scores, and proof-of-concept steps. The goal was to get a first draft of the executive summary and detailed descriptions faster.
It was… okay? It structured the executive summary clearly for non-technical readers. But for the technical sections, it sometimes made the impact sound more generic than it was. We had to fact-check and add specific context about our web app stack.
Has anyone else tried this for security or audit reports? I'm curious if better prompting, like including more about our tech stack upfront, would help. Or if it's just not suited for highly technical details. 👋