Weekly application security report for engineering leadership
Every Monday at 8am, turn your open security issues into a plain English report in Notion and a five line summary in Slack.
Every Monday at 8am, write the weekly application security posture report for engineering leadership, publish it as a page in Notion, and post a short summary to Slack.
Start in Snyk. Use "List all Projects for an Org" to pull the full project inventory so I know everything that is under monitoring, and "Get issues by org ID" to pull the current vulnerability feed. If the Snyk organization ID is not already configured, resolve it first with "List accessible organizations". Join the issues back to the project list so that every project can be referred to by its real name rather than an internal identifier.
Work out the week over week picture from the issue data. Use the issue timestamps and status to separate three groups: issues that first appeared in the last seven days, with critical and high severity called out specifically; issues that were resolved or fixed since last Monday; and everything still open. Then rank the projects by concentration of risk, weighting critical and high severity far above the rest, so that a project with three critical issues outranks a project with thirty low severity ones.
Write a short narrative, not a data dump. Cover four things in order. First, the trend direction for critical and high severity issues, and whether the position improved or worsened this week. Second, which two or three projects carry the most concentrated risk, and what those systems actually do for the business. Third, what the team fixed since last week, giving credit where the backlog moved. Fourth, the two or three things the team should tackle next, in priority order, with a sentence on why each one matters.
Keep it readable for people who are not engineers. Lead with the direction of travel rather than the raw count, so open with wording like "security posture improved this week" before any numbers appear. Describe business impact in plain terms, for example "customer payment data is exposed in this service", rather than listing CVE identifiers, package names, or version strings. No jargon in the narrative. If nothing material changed this week, say so plainly in a couple of sentences rather than padding the report.
Publish the report using the Notion "Create a Page" operation, creating it as a child of my security reporting database. Title it with the report name and the week, for example "Application security posture, week of 9 August 2026". Structure the body with a one line headline summary at the top, followed by the four sections above as short readable prose.
Then post to Slack using "Send a Message" to the engineering leadership channel. Keep it to exactly five lines: the trend direction, the new critical and high severity issues, what got fixed, the project carrying the most concentrated risk, and the single top priority for the week. Finish with a link to the full Notion page so that anyone who wants the detail can click through. Do not paste the whole report into Slack.
Example output
What does this prompt do?
- Reviews every project you have under security monitoring, plus the full list of open issues, first thing Monday morning.
- Writes a short narrative that leads with the trend: whether critical and high risk issues went up or down this week, and why that matters.
- Names the two or three projects carrying the most concentrated risk, credits what the team fixed since last week, and lists what to tackle next.
- Files the full write up as a page in your Notion security reporting database, then posts a five line summary to Slack that links straight to it.
What do I need to use this?
- A Snyk account covering the projects you want reported on
- A Notion workspace with a database where security reports get filed
- A Slack workspace and the channel where your leadership team reads updates
How can I customize it?
- Change the timing: Monday at 8am is just a default, and a Friday wrap up or a monthly cadence works the same way.
- Point it at a different Notion database or Slack channel, or send the summary to more than one channel.
- Adjust what counts as worth reporting, for example critical issues only, or include medium severity if your team tracks it.
FAQs
Do I need to be technical to read this report?
What if nothing changed this week?
Will this work if we have a lot of projects?
Does the whole report get posted to Slack?
Can we keep a history of these reports?
Related templates
When your flight moves, your calendar times get corrected automatically and you get a Slack note naming the meetings you're about to miss.
Every 15 minutes, forwarded phishing reports get traced back to the server that really sent them, with a verdict in Slack and the worst senders reported.
Every weekday at 7am, sign in to the tender portals you track, filter new notices against your bid criteria, and open a deal for the ones worth chasing.
Every Monday, rank the week's matches by expected demand, put the big ones on your venue calendar, and post a rota-ready summary to Slack.
Every Monday, last week's survey answers and support conversations become one themed report in Notion, with the top five themes posted to Slack.
Every Tuesday we pull your best new reviews, draft social captions, email testimonials and product page quotes, then stage them in Notion for approval.
Stop rebuilding the security update by hand every Monday.
Let an agent read your security data, write the narrative, and put it where your leadership team already looks.