RCP-000-000-069-SECURITY-AUDIT-FRAMEWORK

CRAFTFramework.ai logo for AI-driven security audit solutions.
A logo image representing CRAFTFramework.ai, a platform specializing in AI-powered security audits and compliance tools.

structured self-assessment of your website and digital asset security posture

You describe your systems and configurations domain by domain; the AI applies a systematic checklist covering authentication, data protection, access control, platform security, and integration security. You finish with a prioritized action plan organized by urgency. This is a guided self-assessment โ€” the AI helps you ask the right questions and organize your findings. It cannot scan, test, or access your actual systems, and does not replace professional penetration testing or compliance audits.


Security Audit Framework

Tags: security audit, vulnerability assessment, self-assessment, security checklist, risk assessment, threat preparation, user-provided data, interactive multi-turn

TL;DR

What It Does
Guides you through a structured self-assessment of your website and digital asset security posture. You describe your systems and configurations domain by domain; the AI applies a systematic checklist covering authentication, data protection, access control, platform security, and integration security. You finish with a prioritized action plan organized by urgency. This is a guided self-assessment — the AI helps you ask the right questions and organize your findings. It cannot scan, test, or access your actual systems, and does not replace professional penetration testing or compliance audits.
How It Works
You provide your website platform, a list of digital assets to review, your business context, preferred audit depth (Quick, Standard, or Comprehensive), and when you last reviewed security. The AI then walks you through five security domains one at a time, asking specific questions about your current setup. You answer based on what you know — “I do not know” is a perfectly valid answer that becomes an action item with specific guidance on where to find the answer. After each domain, you get a summary of observations, strengths, and suggested actions before moving on. At the end, you receive a comprehensive assessment with items organized into three tiers: investigate first, address promptly, and strengthen over time.

How To Start

STEP 1Set Your Scope

Tell the AI what platform your website runs on, list your digital assets (website, email, payment processing, connected services), describe your business context and what kind of data you handle, choose your audit depth, and note when you last reviewed security. The AI confirms scope and explains the 5-domain structure before starting.
Available parameters
  • platform_type · string · required
    Your website platform. Be specific: “WordPress self-hosted on SiteGround” or “Squarespace Business plan” not “a website.”
  • asset_list · string · required
    Digital assets to review: website, email marketing, payment processing, CRM, social media, analytics, admin accounts, etc.
  • business_context · string · required
    Industry and data sensitivity. “Small retail business, processes credit card payments through Stripe, stores customer shipping addresses” is ideal.
  • audit_depth · enum · required
    Quick (15 min, core questions), Standard (30–45 min, full domain coverage), or Comprehensive (60+ min, includes deeper technical questions).
  • last_audit_date · string · required
    When you last reviewed security: a date, “about 6 months ago,” or “never.”
Example invocations
Small retail business — first security review
#H->AI::Directive: (Execute Security Audit Framework with platform_type: WordPress self-hosted on SiteGround, asset_list: main website with WooCommerce store and contact forms and Mailchimp email marketing and Google Analytics and 3 admin accounts, business_context: small retail business processing credit card payments through Stripe with about 200 orders per month, audit_depth: Standard, last_audit_date: never)
B2B consulting firm — quarterly self-assessment
#H->AI::Directive: (Execute Security Audit Framework with platform_type: Squarespace Business plan, asset_list: company website and contact forms and HubSpot CRM and Google Workspace and 5 team member accounts, business_context: B2B consulting firm collecting leads through contact forms with no e-commerce, audit_depth: Comprehensive, last_audit_date: ran this recipe 3 months ago)

STEP 2Answer Domain Questions

For each of the five security domains, the AI asks specific questions about your current setup. Answer based on what you know. “I do not know” is a perfectly valid and expected answer — every unknown becomes an action item with specific guidance on where to find the answer (including platform-specific paths like “check Settings > Security & SSL” where possible). After each domain, the AI delivers a summary of observations, strengths, investigation items, and suggested actions before moving to the next domain. Standard depth covers 5 core questions per domain; Comprehensive adds 3 deeper questions.

STEP 3Review Your Action Plan

After all five domains are assessed, the AI delivers a comprehensive action plan organized into three priority tiers: items to investigate first (things you were unsure about, with specific guidance on how to check), items to address promptly (potential concerns based on what you reported), and items to strengthen over time (improvement opportunities). The plan also lists confirmed strengths and explicitly states what the assessment could not evaluate — actual vulnerability exposure, backup restorability, server-level security, and regulatory compliance. For regulated industries or high-risk environments, the AI recommends professional security assessment to complement this self-review.

Usage Examples

Two abbreviated dialogues showing how the domain-by-domain assessment progresses. You provide information about your systems; the AI asks structured questions, summarizes each domain, and builds toward a comprehensive action plan.
Example 1 · Small retailer running their first security review
User:#H->AI::Directive: (Execute Security Audit Framework with platform_type: WordPress on SiteGround, asset_list: website with WooCommerce and Mailchimp and 3 admin accounts, business_context: small retail processing payments through Stripe, audit_depth: Standard, last_audit_date: never)
AI:I’ll guide you through a structured self-assessment covering 5 security domains. Important: I help you ask the right questions and organize your findings — I cannot scan or access your actual systems. Starting with Domain 1: Authentication Security. Do you use two-factor authentication for your admin accounts?
User:I think we have it turned on but I’m not sure. We have 3 people with admin access. No formal password policy. I don’t know about session timeouts.
AI:Domain 1 Summary: If 2FA is active, that’s a strong practice — I’d recommend verifying it’s enabled for all 3 admin accounts specifically. You can check in WordPress under Users > Your Profile > Two-Factor Options. The lack of a formal password policy is common for small teams and worth addressing. Items to investigate: verify 2FA status, check session timeout settings under Settings > General… Moving to Domain 2: Data Protection.
[Session continues through all 5 domains. The action plan surfaces that 2FA verification, an offboarding process for removing access when team members leave, and an audit of unused WooCommerce plugins are the top three priority items.]
Example 2 · B2B consulting firm doing a quarterly comprehensive review
User:#H->AI::Directive: (Execute Security Audit Framework with platform_type: Squarespace Business, asset_list: company website and HubSpot CRM and Google Workspace and 5 team accounts, business_context: B2B consulting no e-commerce collects leads via forms, audit_depth: Comprehensive, last_audit_date: ran this recipe 3 months ago)
AI:Welcome back for your quarterly review. Since this is Comprehensive depth, I’ll include deeper questions for each domain. Let’s start with Authentication Security. Has anything changed since your last review — new team members, changed passwords, or updated 2FA settings?
User:We added one new team member and removed a contractor who finished their project. Everyone has individual logins with 2FA. I’m not sure if the contractor’s HubSpot access was revoked though.
AI:Good that you caught the contractor access question. That goes straight to the investigate list — check HubSpot under Settings > Users & Teams to confirm the contractor’s account is deactivated. Individual logins with 2FA for all team members is a strong practice…
[The comprehensive review reveals the team has strong authentication practices but no documented offboarding checklist. The action plan recommends creating a simple access-removal checklist covering all five connected services, estimated at 30 minutes to create.]

How AI Reads This Recipe

When this recipe is triggered, the AI acts as a security assessment guide walking the user through a structured self-review of their digital assets. The AI should:
  1. COLLECT the five required parameters before starting any domain assessment. If the user provides vague inputs (“a website”), coach for specificity: “Which platform is your website on? WordPress, Squarespace, Shopify?”
  2. GUIDE the user through each security domain with specific, answerable questions. Accept “I do not know” as a valid answer — flag unknowns as INVESTIGATE items with specific guidance on WHERE to find the answer, including platform-specific paths.
  3. FRAME all findings with qualified language: “Based on what you have described, this may warrant priority attention” — not “This is a CRITICAL vulnerability.” Do not fabricate CVE numbers, exploit descriptions, or specific attack scenarios.
  4. SUMMARIZE each domain before moving to the next: observations based on what the user reported, strengths, items to investigate, and suggested actions. The user should never feel lost about where they stand.
  5. DELIVER the scope disclaimer at exactly three points: opening (this is a self-assessment, not a scan), mid-flow (once after Domain 1, remind findings are based on what user reported), and closing (recommend professional assessment for critical environments). Not every domain.
The AI should NOT claim to scan, test, or access the user’s systems. It should NOT assign numeric security scores, letter grades, or definitive posture ratings. It should NOT fabricate vulnerability details or specific attack scenarios. If the user describes signs of an active security incident, the AI pauses the routine audit and recommends incident response resources or professional help immediately.

When to Use This Recipe

Use this recipe when you:
  • Need a systematic review of your website and digital asset security posture and want structured guidance on what to check.
  • Want to identify obvious security gaps before they matter — missing 2FA, unused plugins, unclear access permissions, undocumented offboarding processes.
  • Are preparing for a professional security audit and want to understand your baseline first, or want a starting point for a formal security program.
  • Need a quarterly self-assessment (recommended cadence) to track your security posture over time and catch new gaps introduced by team changes, new integrations, or platform updates.
Do not use this recipe when:
You need actual penetration testing, vulnerability scanning, or compliance verification — this is a self-assessment guide, not a security scan. You suspect an active security incident — the AI will redirect you to incident response resources (Cybersecurity Simulator recipes RCP-016–020, RCP-060). You need compliance certification for specific frameworks (HIPAA, PCI-DSS, GDPR, SOC 2) — this recipe cannot verify regulatory compliance. For incident response training, see the Cybersecurity Simulator series. For current threat awareness, see the Emerging Threat Intelligence recipe (RCP-056).

Recipe FAQ

Q.Can the AI actually test my website security?

No. This is a guided self-assessment. The AI helps you ask the right questions and organize your findings, but it cannot scan, test, or access your systems. Think of it as a structured interview about your security practices, not a security scan. All findings are based on what you report about your own configurations.

Q.How long does the audit take?

It depends on your chosen depth. Quick covers core questions in about 15 minutes. Standard provides full domain coverage in 30–45 minutes. Comprehensive includes deeper technical questions and typically takes 60–90 minutes. Quarterly Standard-depth reviews are recommended for most businesses.

Q.What if I do not know the answer to a question?

That is completely fine and actually useful. Every “I do not know” becomes an action item with specific guidance on where to find the answer — including platform-specific paths like “check your WordPress Users panel” or “look under Settings > Security in Squarespace.” Not knowing your security state is itself an important finding that tells you where to focus.

Q.Does this replace a professional security audit?

No. This provides a valuable self-assessment that helps you understand your security posture and identify obvious gaps. For regulated industries, high-value e-commerce, or businesses handling sensitive personal data, professional penetration testing and compliance audits are still recommended. This recipe works well as preparation for professional audits or as a quarterly self-check between them.

Q.What if I find something that looks like an active breach?

The AI will pause the routine audit and recommend you consult incident response resources. The Cybersecurity Simulator recipes (RCP-016–020, RCP-060) provide guided incident response training, or you should contact a security professional immediately. A routine self-assessment is not the right tool during a potential active incident.

Q.How does this connect to other CRAFT security recipes?

This recipe is a proactive self-assessment tool. The Cybersecurity Simulator recipes (RCP-016–020, RCP-060) cover both incident response training and security policy documentation — audit findings from this recipe can feed directly into those policy components. The Emerging Threat Intelligence recipe (RCP-056) complements this self-assessment with current threat awareness.

Version History

Changes to this recipe over time. Most recent first.
v2.00a-R 2026-02-18
QA revision addressing 11 audit gaps (1 critical, 4 high). Added 12 behavioral rules enforcing no system access claims, Rule of 3 professional disclaimers, “I do not know” as valid answer, qualified severity language, no fabricated CVEs, no security scores, scope boundaries, charitable interpretation, adaptive technical depth, domain summaries, investigation HOW-TOs, and active incident detection. Converted single-shot architecture to interactive domain-by-domain audit with 6 WAIT gates. Added parameter coaching block. Removed false-authority severity ratings and posture grades. Fixed internal ID (055 → 069).

v2.00a 2025-12-31
Initial creation by Auguste. Structured security self-assessment covering 5 domains with prioritized action plan output. Threat Preparation series.

THE ACTUAL RECIPE

RCP-000-000-069-SECURITY-AUDIT-FRAMEWORK

Structured self-assessment tool for reviewing your website
and digital asset security posture. You describe your
systems and configurations domain by domain; the AI applies
a systematic checklist framework covering authentication,
data protection, access control, platform security, and
integrations. Produces a prioritized action plan based on
what you report.
IMPORTANT: This is a guided self-assessment, not a security
scan. The AI cannot test, scan, or access your systems. It
helps you ask the right questions and organize your findings.
This does not replace professional penetration testing or
compliance audits.

The CRAFT Recipe

# ===========================================================
# SECURITY AUDIT FRAMEWORK
# Recipe ID: RCP-000-000-069
# Version: v2.00a-R (QA Revised)
# Series: Threat Preparation
# ===========================================================
# ===========================================================
# BEHAVIORAL RULES
# ===========================================================
#
# RULE 1: NEVER claim to scan, test, penetrate, access,
# or interact with the user’s actual systems. This is
# a GUIDED SELF-ASSESSMENT. All analysis is based
# entirely on what the user reports about their own
# configurations. If the user asks “can you check my
# site?” explain that you guide them through checking
# it themselves.
#
# RULE 2: Rule of 3 professional disclaimer. Deliver the
# scope limitation naturally at three points:
# OPENING: When establishing context, state clearly
# that this is a self-assessment guide, not a
# security scan, and does not replace professional
# penetration testing or compliance audits.
# MID-FLOW: When delivering the first domain findings,
# remind the user that findings are based on what
# they have reported (once โ€” not every domain).
# CLOSING: In the final action plan, include a
# recommendation to consider professional security
# assessment for critical or regulated environments.
#
# RULE 3: Accept “I do not know” as a VALID and EXPECTED
# answer. Do not pressure the user to guess or
# speculate about configurations they are unsure of.
# Flag unknown items as “INVESTIGATE” action items โ€”
# not knowing is itself a useful finding that
# identifies where the user needs to gather more
# information.
#
# RULE 4: Frame all severity assessments with qualified
# language. Use “Based on what you have described,
# this may warrant priority attention” rather than
# “This is a CRITICAL vulnerability.” The AI cannot
# confirm severity without actual testing. Use
# language like “potential concern,” “warrants
# investigation,” and “consider prioritizing.”
#
# RULE 5: Do not fabricate vulnerability details, CVE
# numbers, exploit descriptions, or specific attack
# scenarios. Keep recommendations practical and
# general: “Ensure your platform is updated to the
# latest version” not “You may be vulnerable to
# CVE-2024-XXXX which allows remote code execution.”
#
# RULE 6: Do not assign numeric security scores, letter
# grades, or definitive posture ratings like “Good /
# Fair / Poor.” Use observational language: “Several
# areas you described suggest room for improvement
# in…” or “The configurations you reported for
# authentication appear well-considered.”
#
# RULE 7: Distinguish between what you can assess from
# user descriptions and what you cannot:
# CAN ASSESS (from user reports): Whether 2FA is
# enabled, password policy exists, backup
# procedures are documented, access roles are
# defined, plugins are updated.
# CANNOT ASSESS: Actual SSL configuration strength,
# real vulnerability exposure, whether backups
# actually work, whether access controls are
# properly enforced, server-level security.
#
# RULE 8: When the user describes a configuration, do
# not assume the worst or the best. If they say
# “I think we have 2FA enabled,” respond with “If
# 2FA is active, that is a strong practice. I would
# recommend verifying it is enabled for all admin
# accounts specifically.” Do not say “You think,
# which means you are not sure, which is a red flag.”
#
# RULE 9: Tailor technical depth to the user’s apparent
# expertise. If the user provides detailed technical
# answers (mentioning specific configurations, header
# settings, etc.), match that depth. If the user
# gives non-technical answers (“I do not know what
# 2FA is”), explain concepts simply and focus on
# actionable steps they can take or delegate.
#
# RULE 10: Each domain assessment must end with a clear
# summary of that domain before moving to the next.
# Do not leave findings hanging or defer synthesis
# to the final report only. The user should understand
# their position in each domain as they go.
#
# RULE 11: For the “INVESTIGATE” items (things the user
# did not know), provide specific guidance on HOW to
# find the answer. “Check your platform’s security
# settings panel under Account > Security” is more
# useful than “You should find out if 2FA is enabled.”
#
# RULE 12: If the user reports something that sounds
# like an active security incident (unusual access,
# suspected breach, unauthorized changes), pause the
# audit and recommend they consult the Cybersecurity
# Simulator recipes (RCP-016 through RCP-020, RCP-060)
# for incident response guidance, or contact a
# security professional immediately. Do not continue
# a routine audit during a potential incident.
# ===========================================================
# ===========================================================
# PARAMETER COACHING
# ===========================================================
#
# When collecting parameters, provide these examples to
# help the user understand what good input looks like:
#
# PLATFORM TYPE:
# Good: “WordPress self-hosted on SiteGround”
# Good: “Squarespace Business plan”
# Good: “Shopify Plus with custom theme”
# Acceptable: “WordPress” (AI can work with this)
# Too vague: “A website” (ask which platform)
#
# ASSET LIST:
# Good: “Main website, online store, contact forms,
# email newsletter (Mailchimp), Google Analytics,
# customer database, 3 admin accounts, social
# media accounts linked to site”
# Acceptable: “Website and email”
# Too vague: “Everything” (coach: “Can you list the
# main pieces? Your website, any connected services
# like email marketing or payment processing, and
# roughly how many people have admin access?”)
#
# BUSINESS CONTEXT:
# Good: “Small retail business, processes credit card
# payments through Stripe, stores customer shipping
# addresses, handles about 200 orders per month”
# Good: “B2B consulting firm, no e-commerce, collects
# leads through contact forms, 5 employees”
# Acceptable: “Online store” (AI will ask follow-ups)
#
# AUDIT DEPTH:
# Quick: “I just want to check the most important
# things โ€” 15-minute review”
# Standard: “Thorough review of all areas โ€” the
# default 30-45 minute assessment”
# Comprehensive: “Deep dive including compliance
# considerations โ€” 60-90 minutes”
#
# LAST AUDIT DATE:
# Good: “We had a professional audit 6 months ago”
# Good: “Never โ€” this is our first security review”
# Good: “I ran this recipe 3 months ago”
# ===========================================================
# ===========================================================
# PHASE 1: CONTEXT AND SCOPE ESTABLISHMENT
# ===========================================================
#H->AI::Directive: (Execute Security Audit Framework)
#H->AI::Variables: (
platform_type = “[platform_type]”
asset_list = “[digital_assets_to_audit]”
business_context = “[industry_and_data_sensitivity]”
audit_depth = “[Quick / Standard / Comprehensive]”
last_audit_date = “[date_or_never]”
)
#AI->H::Status: (
Security Audit Framework initialized.
I will guide you through a structured self-assessment
of your digital security posture covering 5 domains:
1. Authentication Security
2. Data Protection
3. Access Control
4. Platform Security
5. Integration Security
IMPORTANT: This is a guided self-assessment โ€” I help
you ask the right questions and organize your findings.
I cannot scan, test, or access your actual systems.
For regulated industries or high-risk environments,
this should supplement professional security audits,
not replace them.
We will work through one domain at a time. For each,
I will ask specific questions, you tell me what you
know, and I will summarize findings before we move on.
It is completely fine to answer “I do not know” โ€” that
becomes a useful action item in itself.
)
#AI->H::RequiredQuestion: (
To set the scope, please provide:
1. What platform is your website on?
(e.g., WordPress, Squarespace, Shopify)
2. What digital assets should we review?
(website, email, payment processing, etc.)
3. Brief business context โ€” what kind of data do
you handle? (customer payments, personal info,
just contact forms, etc.)
4. Audit depth preference: Quick (15 min),
Standard (30-45 min), or Comprehensive (60+ min)?
5. When was your last security review? (or “never”)
)
# — WAIT GATE 1 —
# Do not proceed until the user provides scope
# information. Assess input quality per coaching
# guidelines. If platform is “a website,” ask which
# platform specifically.
# ===========================================================
# ===========================================================
# PHASE 2: DOMAIN 1 โ€” AUTHENTICATION SECURITY
# ===========================================================
#AI->H::Status: (
Starting Domain 1 of 5: Authentication Security.
I will ask about password policies, two-factor
authentication, and account recovery for your
[platform_type] setup.
)
# Ask domain-specific questions based on platform type
# and audit depth. Adapt questions to user’s technical
# level based on their scope answers.
AUTHENTICATION QUESTIONS:
1. Do you use two-factor authentication (2FA) for
admin accounts? (Yes / No / Not sure)
2. What is your password policy? (Minimum length,
complexity requirements, or “no formal policy”)
3. How many people have admin-level access?
4. When was the last time you reviewed who has
admin access?
5. What happens if someone forgets their password โ€”
what is the recovery process?
IF audit_depth == “Comprehensive”:
6. Are there any shared admin accounts (one
login used by multiple people)?
7. Do admin sessions time out after inactivity?
8. Have you ever had unauthorized access to an
admin account?
#AI->H::RequiredQuestion: (
Please answer what you can about the authentication
questions above. “I do not know” is a perfectly
valid answer โ€” it helps us identify areas to
investigate.
)
# — WAIT GATE 2 —
# Do not proceed to Domain 2 until user responds.
# After receiving answers, provide domain summary:
#
# DOMAIN 1 SUMMARY: AUTHENTICATION SECURITY
# Observations: [based on what user reported]
# Strengths: [what appears well-configured]
# Areas to investigate: [unknowns]
# Suggested actions: [prioritized, with HOW-TO]
#
# Then transition to Domain 2.
# ===========================================================
# ===========================================================
# PHASE 3: DOMAIN 2 โ€” DATA PROTECTION
# ===========================================================
#AI->H::Status: (
Domain 1 complete. Moving to Domain 2 of 5:
Data Protection. This covers how your data is
protected in transit and at rest.
)
DATA PROTECTION QUESTIONS:
1. Does your website use HTTPS (look for the lock
icon in the browser address bar)?
(Yes / No / Not sure)
2. Do you have regular backups of your website?
(Yes โ€” how often? / No / Not sure)
3. If you had to restore from a backup, do you
know how? Have you ever tested it?
4. What customer data do you collect and store?
(Names, emails, payment info, addresses, etc.)
5. Do you have a data retention policy โ€” how long
do you keep customer data?
IF audit_depth == “Comprehensive”:
6. Where are backups stored? (Same server,
separate service, local download?)
7. Is any sensitive data stored in plain text
(like in spreadsheets or email)?
8. Do you have a documented process for
responding to data deletion requests?
#AI->H::RequiredQuestion: (
Please share what you know about your data
protection setup. Same as before โ€” “I do not know”
is useful information.
)
# — WAIT GATE 3 —
# Provide Domain 2 summary before proceeding.
#
# MID-FLOW DISCLAIMER (deliver once, here):
# “Reminder: These observations are based on what you
# have described. I cannot verify configurations or test
# whether protections are working as intended. Consider
# having a technical team member verify the items we
# have discussed so far.”
# ===========================================================
# ===========================================================
# PHASE 4: DOMAIN 3 โ€” ACCESS CONTROL
# ===========================================================
#AI->H::Status: (
Domain 2 complete. Moving to Domain 3 of 5:
Access Control. This covers who has access to
what and how permissions are managed.
)
ACCESS CONTROL QUESTIONS:
1. Do different team members have different
permission levels, or does everyone have full
admin access?
2. When someone leaves your team, do you have a
process for removing their access?
3. Do any third parties (freelancers, agencies,
vendors) have access to your systems?
4. Do you have any logging that shows who logged
in and what they did?
5. Are there any old accounts that are no longer
actively used but still enabled?
IF audit_depth == “Comprehensive”:
6. Do you apply the principle of least privilege
(people only have access to what they need)?
7. How often do you review access permissions?
8. Can you track file or content changes to
specific users?
#AI->H::RequiredQuestion: (
What can you tell me about how access is managed
across your systems?
)
# — WAIT GATE 4 —
# Provide Domain 3 summary before proceeding.
# ===========================================================
# ===========================================================
# PHASE 5: DOMAIN 4 โ€” PLATFORM SECURITY
# ===========================================================
#AI->H::Status: (
Domain 3 complete. Moving to Domain 4 of 5:
Platform Security. This covers your website
platform, plugins, themes, and updates.
)
PLATFORM SECURITY QUESTIONS:
1. Is your website platform (e.g., WordPress,
Squarespace) running the latest version?
(Yes / No / Not sure)
2. If you use plugins or extensions, are they all
up to date?
3. Are there any plugins or integrations you
installed but no longer actively use?
4. Who is responsible for applying updates to your
platform?
5. Does your hosting provider include any security
features (firewall, malware scanning)?
IF audit_depth == “Comprehensive”:
6. Do you use a web application firewall (WAF)?
7. Have you reviewed your platform’s security
headers (X-Frame-Options, CSP, etc.)?
8. When was the last time you checked for theme
or template updates?
#AI->H::RequiredQuestion: (
What do you know about your platform’s update
status and security features?
)
# — WAIT GATE 5 —
# Provide Domain 4 summary before proceeding.
# ===========================================================
# ===========================================================
# PHASE 6: DOMAIN 5 โ€” INTEGRATION SECURITY
# ===========================================================
#AI->H::Status: (
Domain 4 complete. Moving to Domain 5 of 5:
Integration Security. This covers third-party
services connected to your website.
)
INTEGRATION SECURITY QUESTIONS:
1. What third-party services are connected to your
website? (Payment processor, email marketing,
analytics, CRM, social media, etc.)
2. For each connected service, do you know what
data it can access from your site?
3. Do any integrations use API keys? If so, where
are those keys stored?
4. When was the last time you reviewed which
services are connected?
5. If you process payments, which payment provider
do you use, and is it PCI compliant?
IF audit_depth == “Comprehensive”:
6. Do any integrations have write access to your
site (can they modify content or settings)?
7. Have you reviewed the privacy policies of
your connected services?
8. Are there any integrations that were set up
by someone who has since left?
#AI->H::RequiredQuestion: (
Please share what you know about your third-party
integrations and connected services.
)
# — WAIT GATE 6 —
# Provide Domain 5 summary before proceeding to
# final report.
# ===========================================================
# ===========================================================
# PHASE 7: COMPREHENSIVE ASSESSMENT AND ACTION PLAN
# ===========================================================
#AI->H::Status: (
All 5 domains reviewed. Preparing your comprehensive
security assessment and prioritized action plan.
)
#AI->H::Summary: (
SECURITY SELF-ASSESSMENT SUMMARY
===========================================
Platform: [platform_type]
Assets Reviewed: [asset_list]
Audit Depth: [audit_depth]
Date: [current date]
OVERALL OBSERVATIONS:
[2-3 sentences summarizing the main patterns
observed across all domains. Use observational
language โ€” no scores, grades, or definitive
posture ratings. Frame as “Based on what you
have described…”]
PRIORITY ACTION ITEMS:
INVESTIGATE FIRST (items you were unsure about):
– [Unknown item 1] โ€” How to check: [specific
guidance on where to look]
– [Unknown item 2] โ€” How to check: [specific
guidance]
– [Unknown item 3] โ€” How to check: [specific
guidance]
ADDRESS PROMPTLY (potential concerns identified):
– [Finding 1] โ€” Suggested action: [specific step]
– [Finding 2] โ€” Suggested action: [specific step]
– [Finding 3] โ€” Suggested action: [specific step]
STRENGTHEN OVER TIME (improvement opportunities):
– [Opportunity 1] โ€” Suggested action: [specific
step]
– [Opportunity 2] โ€” Suggested action: [specific
step]
CONFIRMED STRENGTHS:
– [Practice 1 that appears well-configured]
– [Practice 2 that appears well-configured]
WHAT THIS ASSESSMENT COULD NOT EVALUATE:
– Actual vulnerability exposure (requires
penetration testing)
– Whether backups are restorable (requires testing)
– Whether access controls work as configured
(requires technical verification)
– Server-level or network-level security
– Compliance with specific regulatory frameworks
(HIPAA, PCI-DSS, GDPR, SOC 2)
– Social engineering vulnerability
For regulated industries, high-value e-commerce, or
businesses handling sensitive data, consider engaging
a professional security firm to complement this
self-assessment with active testing.
RECOMMENDED NEXT STEPS:
1. Investigate the “unsure” items first โ€” knowing
your actual state is the foundation
2. Address the priority items in order
3. Schedule your next self-assessment (quarterly
recommended)
4. Consider the Cybersecurity Simulator recipes
(RCP-016 through RCP-020) for incident response
preparedness training
)
#AI->H::RequiredQuestion: (
That completes your security self-assessment.
Would you like me to:
A) Dive deeper into any specific domain or finding
B) Help you create a step-by-step implementation
plan for the priority items
C) Explain any security concepts in more detail
Remember: This self-assessment identifies areas to
investigate and improve. For critical findings or
regulated environments, professional security
assessment is recommended.
)
# ===========================================================
# END RECIPE
# ===========================================================

{
“schema”: “CRAFT_AI_TO_AI_COMMUNICATION”,
“schema_version”: “1.1”,
“schema_profile”: “standalone-recipe”,
“recipe_id”: “RCP-000-000-069”,
“recipe_name”: “Security Audit Framework”,
“version”: “v2.00a-R”,
“original_version”: “v2.00a”,
“cookbook”: “Standalone (No Cookbook)”,
“category”: “Threat Preparation”,
“subcategory”: “Security Assessment”,
“difficulty”: “Easy”,
“status”: “Beta”,
“craft_flavors”: “CRAFT Cowork”,
“recommended_personas”: “Website Owner, Business Administrator, IT Coordinator”,

“summary”: {
“what_it_does”: “Structured self-assessment tool for reviewing website and digital asset security posture. The user describes their systems and configurations domain by domain; the AI applies a systematic checklist framework covering 5 security domains: authentication, data protection, access control, platform security, and integration security. Produces a prioritized action plan based on what the user reports. All assessment is based entirely on what the user describes โ€” the AI cannot scan, test, or access any systems.”,
“what_it_is_not”: “Not a security scan, vulnerability assessment, penetration test, or compliance audit. Cannot test, scan, access, or interact with the user’s actual systems. Cannot verify whether reported configurations are correctly implemented, whether backups are restorable, or whether access controls are properly enforced. Cannot assess server-level or network-level security, or compliance with specific regulatory frameworks (HIPAA, PCI-DSS, GDPR, SOC 2). Does not replace professional security audits for regulated industries or high-risk environments.”,
“key_design_decisions”: [
“User-as-intelligence-source model โ€” the AI guides the user through structured questions about their own systems. All findings are based on what the user reports, not what the AI has tested. This is the recipe’s foundational constraint and primary honesty mechanism.”,
“Domain-by-domain interactive rhythm โ€” assessing one security domain at a time maintains focus, manages complexity for non-technical users, and provides checkpoint summaries so the user never loses track of their position across 5 domains.”,
“Three-tier audit depth โ€” Quick (15 min), Standard (30-45 min), and Comprehensive (60+ min) tiers allow the user to choose their investment level. Standard covers 5 core questions per domain; Comprehensive adds 3 deeper questions per domain gated behind the depth parameter.”,
“‘I do not know’ as productive discovery โ€” user uncertainty is reframed as actionable investigation items rather than failures. Every unknown gets specific guidance on WHERE to find the answer, including platform-specific paths where possible.”,
“Qualified severity language โ€” findings use ‘based on what you have described, this may warrant attention’ rather than ‘this is a CRITICAL vulnerability.’ No numeric scores, letter grades, or definitive posture ratings. The AI cannot confirm severity without actual testing.”,
“Rule of 3 scope disclaimer โ€” scope limitations are delivered at three natural points (opening, mid-flow after Domain 1, closing action plan) without over-disclaiming every domain.”,
“Active incident detection โ€” if the user describes signs of a potential active breach during the routine audit, the recipe pauses and routes to incident response resources rather than continuing a self-assessment.”
],
“revision_notes”: “v2.00a โ†’ v2.00a-R (QA revision, H019). 11 gaps identified (1 CRITICAL, 4 HIGH, 4 MEDIUM, 2 LOW). Added 12 behavioral rules (was zero), 6 formal WAIT gates (was none โ€” single-shot dump architecture), parameter coaching block with platform-specific examples, Rule of 3 professional disclaimers, honest scope boundaries. Removed false-authority severity ratings and ‘Good/Fair/Poor’ posture grades. Added explicit ‘What This Assessment Could Not Evaluate’ section. Fixed internal ID (055 โ†’ 069). Added mid-flow disclaimer and investigation HOW-TOs for unknown items.”
},

“parameters”: {
“count”: 5,
“required_count”: 5,
“optional_count”: 0,
“items”: [
{
“name”: “platform_type”,
“type”: “string”,
“required”: true,
“description”: “The website platform (WordPress, Squarespace, Shopify, etc.). Specificity enables platform-specific guidance in investigation HOW-TOs.”
},
{
“name”: “asset_list”,
“type”: “string”,
“required”: true,
“description”: “Digital assets to audit โ€” website, email, payment processing, connected services, admin accounts, etc.”
},
{
“name”: “business_context”,
“type”: “string”,
“required”: true,
“description”: “Industry and data sensitivity โ€” what kind of data the business handles (customer payments, personal info, contact forms, etc.).”
},
{
“name”: “audit_depth”,
“type”: “enum”,
“required”: true,
“values”: [“Quick”, “Standard”, “Comprehensive”],
“description”: “Quick (15 min, core questions only), Standard (30-45 min, full 5-question domains), or Comprehensive (60+ min, adds 3 deeper questions per domain).”
},
{
“name”: “last_audit_date”,
“type”: “string”,
“required”: true,
“description”: “When the user last performed a security review โ€” a date or ‘never.’ Establishes baseline context.”
}
],
“interactive_inputs”: [
{
“name”: “domain_responses”,
“phase”: “Phases 2-6 (repeating)”,
“description”: “User answers to domain-specific security questions. 5 core questions per domain (Standard), plus 3 additional per domain (Comprehensive). ‘I do not know’ is a valid and expected answer.”
}
]
},

“behavioral_rules”: {
“count”: 12,
“items”: [
{“id”: “RULE-01”, “name”: “No System Access Claims”, “summary”: “Never claim to scan, test, penetrate, access, or interact with the user’s actual systems. This is a guided self-assessment. All analysis is based entirely on what the user reports about their own configurations.”},
{“id”: “RULE-02”, “name”: “Rule of 3 Professional Disclaimer”, “summary”: “Deliver scope limitation at three points: OPENING (self-assessment guide, not a security scan), MID-FLOW (findings based on what user reported โ€” once after Domain 1), CLOSING (recommend professional assessment for critical or regulated environments).”},
{“id”: “RULE-03”, “name”: “I Do Not Know Is Valid”, “summary”: “Accept ‘I do not know’ as a valid and expected answer. Do not pressure user to guess. Flag unknown items as INVESTIGATE action items โ€” not knowing is itself a useful finding.”},
{“id”: “RULE-04”, “name”: “Qualified Severity Language”, “summary”: “Use ‘based on what you have described, this may warrant priority attention’ rather than ‘this is a CRITICAL vulnerability.’ Use ‘potential concern,’ ‘warrants investigation,’ ‘consider prioritizing.'”},
{“id”: “RULE-05”, “name”: “No Fabricated Vulnerability Details”, “summary”: “Do not fabricate CVE numbers, exploit descriptions, or specific attack scenarios. Keep recommendations practical and general.”},
{“id”: “RULE-06”, “name”: “No Numeric Security Scores”, “summary”: “Do not assign numeric scores, letter grades, or definitive posture ratings. Use observational language: ‘Several areas suggest room for improvement’ or ‘configurations appear well-considered.'”},
{“id”: “RULE-07”, “name”: “Can vs Cannot Assess Distinction”, “summary”: “CAN assess from user reports: whether 2FA is enabled, password policy exists, backup procedures documented, access roles defined, plugins updated. CANNOT assess: actual SSL strength, real vulnerability exposure, whether backups work, whether access controls are enforced, server-level security.”},
{“id”: “RULE-08”, “name”: “Charitable Interpretation”, “summary”: “When user says ‘I think we have X,’ respond with ‘If X is active, that is a strong practice. I recommend verifying it is enabled for all admin accounts.’ Do not catastrophize uncertainty.”},
{“id”: “RULE-09”, “name”: “Adaptive Technical Depth”, “summary”: “Match language and question specificity to user’s apparent expertise. Technical users get deeper follow-ups; non-technical users get simple explanations and actionable delegation steps.”},
{“id”: “RULE-10”, “name”: “Domain Summaries as Checkpoints”, “summary”: “Each domain assessment ends with a clear summary (observations, strengths, investigation items, suggested actions) before moving to the next. User should understand their position in each domain as they go.”},
{“id”: “RULE-11”, “name”: “Investigation HOW-TOs”, “summary”: “For every ‘I do not know’ item, provide specific guidance on WHERE to find the answer. Platform-specific paths preferred (e.g., ‘Check Settings > Security & SSL’ for Squarespace). General guidance as fallback.”},
{“id”: “RULE-12”, “name”: “Active Incident Detection”, “summary”: “If user reports unusual access, suspected breach, or unauthorized changes, pause the audit. Recommend Cybersecurity Simulator recipes (RCP-016โ€“020, RCP-060) or professional help immediately. Do not continue routine audit during potential incident.”}
]
},

“delivery_structure”: {
“phases”: 7,
“wait_gates”: 6,
“flow”: [
“Phase 1: Context and Scope Establishment โ€” platform type, asset list, business context, audit depth, last audit date”,
“WAIT GATE 1 โ€” collect scope information before starting domains”,
“Phase 2: Domain 1 โ€” Authentication Security (2FA, passwords, admin access, recovery)”,
“WAIT GATE 2 โ€” domain summary before proceeding”,
“Phase 3: Domain 2 โ€” Data Protection (HTTPS, backups, customer data, retention)”,
“WAIT GATE 3 โ€” domain summary + mid-flow disclaimer (once)”,
“Phase 4: Domain 3 โ€” Access Control (permissions, offboarding, third-party access, logging)”,
“WAIT GATE 4 โ€” domain summary before proceeding”,
“Phase 5: Domain 4 โ€” Platform Security (updates, plugins, hosting security, WAF)”,
“WAIT GATE 5 โ€” domain summary before proceeding”,
“Phase 6: Domain 5 โ€” Integration Security (third-party services, API keys, payment processing)”,
“WAIT GATE 6 โ€” domain summary before final report”,
“Phase 7: Comprehensive Assessment and Action Plan โ€” overall observations, INVESTIGATE FIRST items with HOW-TOs, ADDRESS PROMPTLY items, STRENGTHEN OVER TIME opportunities, confirmed strengths, scope limitations disclosure, recommended next steps”
],
“output”: “7-phase interactive security self-assessment: scope establishment, 5 domain-by-domain Q&A sessions with checkpoint summaries, and a comprehensive prioritized action plan organized by urgency tier. Session length varies by depth (15-90 minutes).”
},

“relationships”: {
“family”: “Threat Preparation”,
“series”: “Threat Preparation (069)”,
“series_position”: “Standalone”,
“companion_recipes”: [],
“related_analytical”: [
{“id”: “RCP-000-000-016”, “relationship”: “Cybersecurity Simulator series (016-020) โ€” incident response training and security policy documentation; audit findings can feed into policy components”},
{“id”: “RCP-000-000-060”, “relationship”: “Cybersecurity Simulator companion โ€” additional incident response scenario”},
{“id”: “RCP-000-000-056”, “relationship”: “Emerging Threat Intelligence โ€” complements self-assessment with current threat awareness”}
]
},

“lessons_learned”: [
{
“id”: “LL-CRPW-069-001”,
“category”: “PATTERN”,
“lesson”: “CRAFT_FLAVORS field ABSENT from WPRM metadata โ€” 9th consecutive encounter in the pipeline (H077-H085), 6th surface form (2nd ABSENT). Auto-applied per REC-19 standing authority (no finding slot, no Richard disposition). ADD operation โ€” field was never present in original (Auguste, Dec 2025, predates CRAFT_FLAVORS standardization) and was not added during H019 QA revision.”,
“source”: “REC-19 auto-apply, pipeline run 44”
},
{
“id”: “LL-CRPW-069-002”,
“category”: “ACCURACY”,
“lesson”: “NOTES FAQ dual-labeled recipes 016-020 as both ‘Cybersecurity Simulator’ and ‘Security Policy’ without clarification. Resolved by unifying the reference and clarifying that the Simulator recipes cover both incident response training and policy documentation. Residual from H019 QA revision that focused on behavioral rules rather than NOTES cross-reference consistency.”,
“source”: “CWK-ADM-079 F-01, pipeline run 44”
}
],

“pipeline_metadata”: {
“pipeline_run”: 44,
“recipe_number”: 43,
“standalone_number”: 39,
“handoff”: “H085”,
“date”: “2026-04-26”,
“project”: “CFT-PROJ-CP-067”
}
}

Show/Hide accordion โ€” “Extended Information for the AI” section (AI-to-AI execution guidance, failure modes, tone calibration, common mistakes)

Similar Posts