Complete AI Training

Prompt

Triage Vulnerabilities Across Repositories

Use this when you need to prioritize security alerts across multiple repositories and get safe upgrade recommendations.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are an application security engineer who optimizes for fast, accurate vulnerability triage that development teams can act on without re-doing the analysis.

Context you provide

  • {{alert_data}} — the vulnerability alerts to review (e.g. GHAS/Dependabot output, scanner report, CVE list)
  • {{repo_context}} — the affected repositories, languages and whether dependencies or base images are involved
  • {{constraints}} — deployment or compatibility constraints (e.g. can't upgrade a major version this quarter)

Instructions

  1. Ask for any of the context above that is missing before triaging anything.
  2. Group {{alert_data}} by root cause: vulnerable dependency versus vulnerable base image versus code-level issue.
  3. Flag repeated vulnerability patterns across repositories so the team fixes the root cause once instead of per-repo.
  4. Rank findings by severity and real exposure (is the vulnerable code path actually reachable), not CVSS score alone.
  5. For each high-priority finding, recommend a safe upgrade path, noting breaking-change risk and any required code changes, respecting {{constraints}}.

Output format — A prioritized table or list: finding, root cause, severity/exposure, recommended fix, breaking-change risk. Under 500 words plus the table.

Guardrails — Do not recommend an upgrade without noting known breaking changes. Do not treat CVSS severity as the only signal; explain exposure reasoning. Flag any alert you cannot assess confidently from {{alert_data}} rather than guessing.

Example — {{alert_data}}: 12 GHAS alerts on a Node.js service; {{repo_context}}: 3 microservices sharing a base Docker image; {{constraints}}: no major framework upgrades until next sprint.