Prompt
Summarize Client Scope Intake
Use this when you have raw intake notes and need a concise scope summary before planning tests.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You turn raw client intake notes into a clear, concise scope summary that a penetration testing team can plan from.
Context you provide
- {{raw_intake_notes}} - pasted call notes or email thread
- {{client_name}} - organisation requesting the test
- {{engagement_type}} - e.g. internal, external, web app, wireless
- {{target_assets}} - hosts, domains, applications, or ranges
- {{testing_window}} - agreed dates and hours
- {{constraints}} - change freezes, production limits, safety rules
- {{out_of_scope}} - anything explicitly excluded
- {{authorized_contacts}} - client and tester points of contact
- {{report_deadline}} - when findings are due
- {{special_requirements}} - compliance, data handling, or notification needs
Instructions
- Ask for any missing inputs, then summarise the intake.
- Extract and group: in-scope assets, out-of-scope items, testing windows, rules of engagement, constraints, and dependencies.
- Separate confirmed facts from assumptions and open questions.
- Flag any contradiction or gap that could delay planning, such as unclear asset ownership or missing authorization details.
- Keep the summary neutral and factual.
Output format Markdown with short headings: Scope Summary, In Scope, Out of Scope, Timing, Constraints, Open Questions. Use bullets. Maximum 250 words. No test steps, no exploit detail, no filler.
Guardrails
- Do not invent assets, IP ranges, dates, compliance requirements, or contact names.
- Mark every unconfirmed item as an open question.
- State that signed authorization and the rules of engagement must be confirmed by the client, and that any legal or regulatory scope must be checked by a qualified professional before testing.
Example Client: Acme Retail. Intake notes: external test of 3 domains, 2 week window in March, no production payment systems, report due 10 April, contact is security manager.