Security advisory
Condense a supplied advisory without losing exposure limits or mitigation steps.
Condense the supplied security advisory for affected users who need to assess exposure and act. This is an editing task, not a new vulnerability assessment or an instruction to test an exploit. Lead with the affected product, versions, and required exposure conditions. State the documented impact. Preserve authentication requirements, configuration limits, fixed versions, mitigations, and whether a workaround reduces or removes the stated exposure. Keep advisory identifiers and links supplied for verification. Separate confirmed exploitation, no known exploitation, and exploitation status unknown. Preserve uncertainty and the date of time-sensitive claims. Remove repeated severity adjectives, background that does not affect action, and unnecessary exploit detail. Do not invent a severity score, assign an identifier, or expand affected versions by inference. Output Exposure, Action, and Evidence lines as supported. Retain operational costs of a mitigation. Do not state that a system is safe merely because it uses a workaround, or claim that an update has been applied.
Example
Fictional gateway maintainer notice
Before 93 words
This maintainer notice covers Sample Gateway versions 1.8.0 through 1.8.3 when public file sharing is enabled. In that configuration, an unauthenticated requester can retrieve file metadata from another workspace; file contents are not exposed by this issue. Version 1.8.4 fixes the issue. Users who cannot upgrade immediately can disable public file sharing, which blocks the affected endpoint but also makes existing public share links unavailable. As of June 12, the maintainers have no evidence of exploitation, but their review is ongoing. Deployments with public file sharing disabled are not affected by this issue.
After 55 words
Exposure: Sample Gateway 1.8.0–1.8.3 with public file sharing enabled. Unauthenticated requests can expose another workspace's file metadata, not contents. Sharing-disabled deployments are unaffected. Action: Upgrade to 1.8.4, or disable public file sharing to block the endpoint; existing public share links will stop working. Evidence: Maintainers report no exploitation evidence as of June 12; review ongoing.
Examples illustrate the method. They do not measure model output.
Files and sources
- prompt.txt Complete prompt as plain text.
- SKILL.md The same prompt with a skill header.
- llms.txt (JSON) Prompt, metadata, example, and sources.
- LICENSE MIT license text.
An original sho.rten.it skill. Source notes.