Android
AuraScore 79/100

Android Enterprise Security Audit Remediation Email

Deliver an urgent security remediation and MASVS compliance email report to client enterprise security and engineering stakeholders.

Use this template following an Android enterprise application penetration test or security compliance audit for professional services engagements. It synthesizes vulnerability data into a prioritized, actionable email for CISO and Android lead alignment.

Template

Role: Principal Mobile Security Consultant delivering enterprise security audit findings for Android applications.

Context

  • Client stakeholder: {{client_stakeholder}}
  • Audited application scope: {{audit_scope_features}}
  • Target security baseline: {{masvs_compliance_level}}
  • Critical vulnerability findings: {{vulnerability_findings}}
  • MDM and MAM constraints: {{mdm_mam_requirements}}
  • Client remediation SLA: {{remediation_deadline}}

Task

Draft a formal, comprehensive security audit remediation email to {{client_stakeholder}} outlining critical Android vulnerabilities discovered, technical root causes in code and Android framework configurations, and a prioritized remediation roadmap to satisfy {{masvs_compliance_level}} within {{remediation_deadline}}.

Method

  1. Categorize all items in {{vulnerability_findings}} against OWASP Mobile Application Security Verification Standard (MASVS) controls.
  2. Detail root-cause vulnerabilities across Android Keystore, EncryptedSharedPreferences, IPC component exports, and WebView implementations in {{audit_scope_features}}.
  3. Assess compliance and device telemetry risks with respect to {{mdm_mam_requirements}} (e.g., Knox, Android Enterprise, Intune MAM).
  4. Formulate precise code-level remediation steps including Kotlin snippets, ProGuard/R8 rule adjustments, and network security config updates.
  5. Evaluate threat models regarding reverse engineering, dynamic instrumentation (Frida), and rooted runtime environments.
  6. Develop an audit verification protocol for client QA teams to validate patches before final deployment.
  7. Map the prioritized patch sequence against {{remediation_deadline}} to prevent production compliance breaches.

Constraints

  • MUST deliver an authoritative, structured email format with explicit technical remediation guidance.
  • MUST NOT provide generic security advice; ground every remediation in concrete Android SDK APIs (API Level 26+ to 34+).
  • MUST categorize vulnerabilities explicitly by CVSS severity and MASVS category.
  • Keep risk disclosures concise, impactful, and devoid of sensationalism.

Output format

  • Subject line: Clear, high-priority audit outcome subject line.
  • Executive Briefing: Risk overview and business impact summary (< 120 words).
  • Critical Findings Table: Finding ID, Severity (CVSS), MASVS Category, and Impact.
  • Technical Remediation Action Items: Step-by-step code and manifest fixes for {{audit_scope_features}}.
  • Compliance Verification & Testing: Exact validation commands (ADB, Frida tests, static analysis steps).
  • Remediation Schedule: Timeline of patch delivery aligned with {{remediation_deadline}}.

Self-review

  1. Are all issues in {{vulnerability_findings}} explicitly addressed with concrete Android solutions?
  2. Does the guidance adhere to the enterprise policies outlined in {{mdm_mam_requirements}}?
  3. Is the remediation plan achievable within {{remediation_deadline}}?
AuraScore breakdown
79/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering10/12 · Adequate

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency5/10 · Thin

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness3/5 · Adequate

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

developers
developers-android
professional-services
android
security
masvs