The instinct to ask a researcher to extend or waive their disclosure window on the first reply is a mistake, it reads as stalling and damages trust with exactly the person who’s currently being reasonable. Respond fast, get the proof of concept off a public thread, and let the fix timeline do the talking.
Support
Handle a report from a customer who found a security vulnerability
A scenario prompt for responding to a vulnerability disclosure with urgency and discretion, before a public patch exists.
Works with Claude / GPT2,700 uses★ 4.7
The prompt
support-security-vulnerability-report
An email arrives in your support inbox from someone identifying as a security researcher: "I found a stored XSS vulnerability in your plugin's settings page. Any user with Contributor access can inject a script that executes when an admin views the settings. I can share a proof of concept. Let me know how you'd like to proceed, otherwise I'll publish this in 90 days per standard disclosure practice." Write the reply, as the person who owns security response, not the developer fixing it yet. Requirements: - Respond fast and specifically: confirm you take this seriously, ask for the proof of concept and affected version through a private channel (not this ticket thread if it isn't encrypted), and give a real timeframe for an initial response (for example, 48-72 hours), not "we'll look into it." - Do not ask them to stop the 90-day disclosure clock or to keep it quiet indefinitely, that's not yours to negotiate on the first email, and pushing for it reads as trying to suppress the report. - Do not promise a bug bounty or reward unless one genuinely exists; don't improvise one on the spot. - Internally, flag this as sensitive: no public tracker, no forum post, until a fix ships, and note who on the engineering side needs to be looped in immediately, not at the next standup. - Keep the customer-facing reply professional and specific, not effusive thanks layered over vague reassurance.