- Home
- Skills
- Business & Operations
- Audit to proposal
Audit to proposal
Convert technical audit findings into professional, tiered sales proposals and follow-up sequences.
Free
Works with the AI tools you already use
Audit to proposal
Example session with this skill installed
I ran a scan on a client's repo. Found: 1 live Stripe secret key (Critical), 3 outdated Docker images with high-severity CVEs, and 12 broken ARIA labels (Medium). My rate is $150/hr. Quote this.
- Read your context and instructions
- Compiled the audit to proposal
- Generated the document
I have processed your findings. I mapped the Stripe key to immediate financial risk and the Docker/ARIA issues to infrastructure and compliance risks.
| Severity | Count | Business Impact |
|---|---|---|
| Critical | 1 | Exposed Stripe key allows unauthorized financial transactions and full account access. |
| High | 3 | Known vulnerabilities in container images provide a direct entry point for remote attacks. |
| Medium | 12 | Accessibility failures increase legal compliance risk and degrade user experience for assistive tech users. |
Remediation Proposal: Security & Compliance Hardening
Executive Summary
A recent audit of your repository identified a critical credential leak and several high-risk infrastructure vulnerabilities. Leaving these unaddressed exposes the organization to immediate financial theft and unauthorized system access. This proposal outlines a tiered approach to securing your assets.
Engagement Options
- Tier 1: Emergency Response (Quick Wins)
*
Scope: Immediate rotation and revocation of the leaked Stripe key; patching the 3 critical Docker vulnerabilities.
* Timeline: 1 Day
* Investment: $1,200 (Fixed)
- Tier 2: Core Hardening
*
Scope: Everything in Tier 1, plus full remediation of all 12 ARIA accessibility findings and implementation of automated secret-scanning in your CI/CD pipeline to prevent future leaks.
* Timeline: 3-4 Days
* Investment: $3,600 - $4,800
- Tier 3: Full Verification
*
Scope: Everything in Tier 2, plus a comprehensive re-scan and a formal Attestation of Remediation for your records.
* Timeline: 5 Days
* Investment: $6,000
Next Steps
- Reply to this email to authorize the Tier 1 Emergency Response immediately.
- We can schedule a 15-minute call tomorrow to discuss the timeline for Tier 2 and 3.
Follow-up Sequence
Message 1 (Day 0 - Initial Send)
Attached is the remediation proposal based on the audit findings. The exposed Stripe key is a priority—I recommend we rotate that today regardless of the broader scope.
Message 2 (Day 3 - The Value Add)
Hi [Name], following up on the proposal. I noticed a few more teams in your industry are facing compliance audits this quarter; resolving those ARIA labels now would put you ahead of that curve. Any questions on the tiers?
Message 3 (Day 7 - The Low-Pressure Close)
Hi [Name], I haven't heard back, so I'll assume the full scope isn't a priority right now. Should we just handle the Stripe key rotation and Docker patches as a standalone fix to close the biggest security gap?
Note: Pricing is calculated at $150/hr. Project leads and client names are placeholders.
audit-to-proposal.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
About this skill
The problem
You have technical audit results from a scanner or checklist, but presenting a raw list of vulnerabilities to a client rarely closes a deal. Non-technical decision-makers buy risk reduction and business continuity, not technical debt clearance.
What it does
- Translates technical jargon like "SQL injection" or "CVE-2023-XXXX" into plain-English business risks.
- Groups raw findings into logical remediation tiers, from "Quick Wins" to "Full Hardening," providing client choice.
- Generates a professional proposal including scope, pricing ranges, and executive summaries.
- Drafts a 3-step follow-up sequence to handle common objections and keep the sales process moving.
Why this beats prompting it yourself
General-purpose prompts often produce generic "marketing" copy that developers hate and clients ignore. This skill uses a specific framework to map technical severity to financial risk while maintaining technical accuracy. It builds a multi-tier pricing strategy automatically, saving you hours of manual scoping and document formatting.
Use cases
- Converting a free lead-magnet audit into a paid security remediation contract.
- Pitching an emergency fix for leaked credentials or critical vulnerabilities.
- Drafting a Statement of Work (SOW) for WCAG accessibility or Core Web Vitals performance work.
- Following up with prospects who haven't responded to a delivered technical report.
Known limitations
Does not perform the actual audit or scan; you must provide the findings. Requires user confirmation for specific hourly rates and currency.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
4 people have installed this skill.
Trust & safety
Security scanned
Verified clean 18 days ago
- Free to download with an account