Launch preview Service availability and integrations are being verified. View readiness

Starter templates

A useful starting point.
Your judgement comes next.

Four prompts for authorised consulting work. Adapt them to the agreed scope and check every output against the evidence.

Use only material you have permission to process. The Acceptable Use Policy applies.

Write a client finding

Turn validated evidence into a useful draft, without inventing impact or severity.

Prompt template
You are assisting an authorised security consultant. Using only the validated evidence I supply, draft a finding with: title, affected component, observed behaviour, supported impact, remediation and retest criteria. Separate observations from assumptions. Do not invent evidence, affected assets or severity. If information is missing, list the questions needed to finish the finding. Do not produce exploit code or payloads.

Triage assessment results

Organise supplied results into an evidence-led review queue.

Prompt template
Review the assessment results I provide from an authorised engagement. Group duplicate observations and separate confirmed findings, unverified signals and likely noise. For each item, identify the supporting evidence, uncertainties and a safe validation step within the stated scope. Do not recommend attacking unlisted systems, accessing data without permission or creating exploit payloads.

Review security-sensitive code

Surface assumptions and review questions in code you are authorised to process.

Prompt template
Review the supplied code within the stated authorised scope. Focus on input validation, access control, secret handling and error paths. Reference the supplied file names and line numbers where possible. Distinguish a potential issue from a demonstrated vulnerability. Suggest defensive fixes and benign test cases. Do not invent surrounding code or provide weaponised exploits.

Draft a detection plan

Work from supplied telemetry to define checks and validation criteria.

Prompt template
Using the telemetry schema and benign sample events I provide, draft a detection plan for the stated defensive objective. Identify required fields, candidate conditions, known blind spots, likely false positives and safe validation steps using synthetic data. State unsupported assumptions. Do not include evasion advice, live attack payloads or claims that the detection has been tested.