Security Review Report Template
# Security Review Report Template
## Executive summary
- Overall risk: Critical / High / Medium / Low
- Reviewed scope:
- Main risks:
- Recommended next steps:
## Findings
### Finding 1: <title>
- Severity: Critical / High / Medium / Low / Informational
- Confidence: High / Medium / Low
- Category: OWASP / Secrets / Auth / CI/CD / Dependency / Hardening
- Evidence:
- File:
- Function/route/config:
- Relevant snippet or behavior:
- Impact:
- Recommended fix:
- Verification test:
## Positive observations
- Controls that are implemented well.
## Assumptions and limitations
- Files or environments not reviewed.
- Missing runtime context.
- Areas needing human confirmation.
## Vietnamese quick format
### Tóm tắt
- Mức rủi ro tổng thể:
- Phạm vi đã review:
- Rủi ro chính:
- Việc nên làm tiếp:
### Finding: <tiêu đề>
- Mức độ:
- Độ tin cậy:
- Bằng chứng:
- Ảnh hưởng:
- Cách sửa:
- Cách kiểm chứng:when to use it
Community prompt sourced from the open-source GitHub repo theitm/ai-security-audit-rules (MIT). A "Security Review Report Template" style prompt — adapt the placeholders and specifics to your task. Imported as-is and not independently retested here, so check the output before relying on it.
tags
roleplaycommunitygeneral
source
theitm/ai-security-audit-rules · MIT