Support

Handle a report from a customer who found a security vulnerability

A scenario prompt for responding to a vulnerability disclosure with urgency and discretion, before a public patch exists.

Works with Claude / GPT2,700 uses 4.7

The prompt

support-security-vulnerability-report
An email arrives in your support inbox from someone identifying as a security
researcher:

"I found a stored XSS vulnerability in your plugin's settings page. Any user with
Contributor access can inject a script that executes when an admin views the
settings. I can share a proof of concept. Let me know how you'd like to proceed,
otherwise I'll publish this in 90 days per standard disclosure practice."

Write the reply, as the person who owns security response, not the developer
fixing it yet.

Requirements:
- Respond fast and specifically: confirm you take this seriously, ask for the
  proof of concept and affected version through a private channel (not this
  ticket thread if it isn't encrypted), and give a real timeframe for an initial
  response (for example, 48-72 hours), not "we'll look into it."
- Do not ask them to stop the 90-day disclosure clock or to keep it quiet
  indefinitely, that's not yours to negotiate on the first email, and pushing for
  it reads as trying to suppress the report.
- Do not promise a bug bounty or reward unless one genuinely exists; don't
  improvise one on the spot.
- Internally, flag this as sensitive: no public tracker, no forum post, until a
  fix ships, and note who on the engineering side needs to be looped in
  immediately, not at the next standup.
- Keep the customer-facing reply professional and specific, not effusive thanks
  layered over vague reassurance.

The instinct to ask a researcher to extend or waive their disclosure window on the first reply is a mistake, it reads as stalling and damages trust with exactly the person who’s currently being reasonable. Respond fast, get the proof of concept off a public thread, and let the fix timeline do the talking.