# LLM-Assisted Vulnerability Description Template

Use this prompt only with evidence from an authorized assessment. Do not include
secrets, personal data, exploit payloads, customer data, or unredacted tokens.
The model output must be reviewed by a qualified human analyst.

## Analyst Prompt
```text
You are helping draft a professional vulnerability report for an authorized
security assessment. Use only the evidence provided. Do not invent impact,
affected assets, exploitability, or remediation details.

Finding context:
- Title: <working title>
- Affected asset: <host/app/component>
- Scope authorization: <engagement ID or scope reference>
- Evidence summary: <redacted facts only>
- Safe reproduction summary: <non-destructive validation steps>
- Business context: <what the asset supports>

Write:
1. Executive summary in 2-3 sentences.
2. Technical root-cause explanation.
3. Realistic impact statement bounded by the evidence.
4. Remediation recommendations.
5. Retest criteria.

Tone: concise, professional, no hype. Mention uncertainties explicitly.
```

## Review Checklist
- Did the draft avoid unverified claims?
- Are all secrets and personal data redacted?
- Is impact bounded to the written scope?
- Are remediation steps actionable for engineering?
- Does the report preserve chain-of-custody references separately from the prompt?
