Weekly application security report for engineering leadership

Every Monday at 8am, turn your open security issues into a plain English report in Notion and a five line summary in Slack.

Agentic Task
SnykNotionSlackEngineeringAI ReportsResearch & Monitoring
PromptCreate

Every Monday at 8am, write the weekly application security posture report for engineering leadership, publish it as a page in Notion, and post a short summary to Slack.

Start in Snyk. Use "List all Projects for an Org" to pull the full project inventory so I know everything that is under monitoring, and "Get issues by org ID" to pull the current vulnerability feed. If the Snyk organization ID is not already configured, resolve it first with "List accessible organizations". Join the issues back to the project list so that every project can be referred to by its real name rather than an internal identifier.

Work out the week over week picture from the issue data. Use the issue timestamps and status to separate three groups: issues that first appeared in the last seven days, with critical and high severity called out specifically; issues that were resolved or fixed since last Monday; and everything still open. Then rank the projects by concentration of risk, weighting critical and high severity far above the rest, so that a project with three critical issues outranks a project with thirty low severity ones.

Write a short narrative, not a data dump. Cover four things in order. First, the trend direction for critical and high severity issues, and whether the position improved or worsened this week. Second, which two or three projects carry the most concentrated risk, and what those systems actually do for the business. Third, what the team fixed since last week, giving credit where the backlog moved. Fourth, the two or three things the team should tackle next, in priority order, with a sentence on why each one matters.

Keep it readable for people who are not engineers. Lead with the direction of travel rather than the raw count, so open with wording like "security posture improved this week" before any numbers appear. Describe business impact in plain terms, for example "customer payment data is exposed in this service", rather than listing CVE identifiers, package names, or version strings. No jargon in the narrative. If nothing material changed this week, say so plainly in a couple of sentences rather than padding the report.

Publish the report using the Notion "Create a Page" operation, creating it as a child of my security reporting database. Title it with the report name and the week, for example "Application security posture, week of 9 August 2026". Structure the body with a one line headline summary at the top, followed by the four sections above as short readable prose.

Then post to Slack using "Send a Message" to the engineering leadership channel. Keep it to exactly five lines: the trend direction, the new critical and high severity issues, what got fixed, the project carrying the most concentrated risk, and the single top priority for the week. Finish with a link to the full Notion page so that anyone who wants the detail can click through. Do not paste the whole report into Slack.

Example output

Security posture is improving: critical and high risk issues are down 18% from last Monday. Three new high risk issues appeared this week, all in the customer payments service. The team closed 11 issues since last week, including the two longest running critical ones. Most concentrated risk sits in the payments service and the legacy billing worker. Next up: patch the payments service, retire the unused billing worker, and set a review date for the mobile backlog. Full report: [Notion link]

What does this prompt do?

  • Reviews every project you have under security monitoring, plus the full list of open issues, first thing Monday morning.
  • Writes a short narrative that leads with the trend: whether critical and high risk issues went up or down this week, and why that matters.
  • Names the two or three projects carrying the most concentrated risk, credits what the team fixed since last week, and lists what to tackle next.
  • Files the full write up as a page in your Notion security reporting database, then posts a five line summary to Slack that links straight to it.

What do I need to use this?

  • A Snyk account covering the projects you want reported on
  • A Notion workspace with a database where security reports get filed
  • A Slack workspace and the channel where your leadership team reads updates

How can I customize it?

  • Change the timing: Monday at 8am is just a default, and a Friday wrap up or a monthly cadence works the same way.
  • Point it at a different Notion database or Slack channel, or send the summary to more than one channel.
  • Adjust what counts as worth reporting, for example critical issues only, or include medium severity if your team tracks it.

FAQs

Do I need to be technical to read this report?
No. That is the point of it. The report leads with the direction of travel and describes business impact in plain language, so it skips vulnerability identifiers, package names, and engineering jargon. It is written for the people who need to know whether things are getting better or worse.
What if nothing changed this week?
You still get a short report confirming the position held steady, which is useful in itself when leadership is watching a trend. It stays brief rather than padding, and the Slack summary is still five lines.
Will this work if we have a lot of projects?
Yes. It reads your full project list, then concentrates the narrative on the handful of projects carrying the most risk instead of listing every one. A project with three critical issues gets attention ahead of one with thirty minor ones.
Does the whole report get posted to Slack?
No. Slack gets a five line summary covering the trend, what is new, what got fixed, the riskiest project, and the top priority, with a link to the full write up in Notion. The channel stays readable and the detail lives in one place.
Can we keep a history of these reports?
Yes. Each run creates a new page in your Notion database, so over time you build a running record of your security posture that you can look back through quarter by quarter.

Related templates

Auto-fix your calendar when a flight slips, and flag what's at risk

When your flight moves, your calendar times get corrected automatically and you get a Slack note naming the meetings you're about to miss.

Google Calendar
AviationStack
Slack
Agentic Task
Trace phishing emails to the sending IP and report abuse

Every 15 minutes, forwarded phishing reports get traced back to the server that really sent them, with a verdict in Slack and the worst senders reported.

AbuseIPDB
Gmail
Slack
Agentic Task
Turn procurement portal tenders into CRM deals each morning

Every weekday at 7am, sign in to the tender portals you track, filter new notices against your bid criteria, and open a deal for the ones worth chasing.

Anchor Browser
Google Sheets
HubSpot
+1
Agentic Task
Turn each week's football fixtures into a venue staffing plan

Every Monday, rank the week's matches by expected demand, put the big ones on your venue calendar, and post a rota-ready summary to Slack.

API-Sports
Google Calendar
Slack
Agentic Task
Weekly voice-of-customer report from surveys and support

Every Monday, last week's survey answers and support conversations become one themed report in Notion, with the top five themes posted to Slack.

Typeform
Intercom
Notion
+2
Agentic Task
Turn 5 star Yotpo reviews into a weekly marketing content queue

Every Tuesday we pull your best new reviews, draft social captions, email testimonials and product page quotes, then stage them in Notion for approval.

Yotpo
Notion
Slack
Agentic Task

Stop rebuilding the security update by hand every Monday.

Let an agent read your security data, write the narrative, and put it where your leadership team already looks.