Selling defensive security prompts
Evaluation / rubric · Guardrails · Application security
Defensive prompts belong on a shelf: code review rubrics, hardening checklists, vulnerability triage. They help someone who already has permission to patch their own systems.
Offense does not. A listing that walks through an exploit, a PoC, a payload, or unauthorized access is not a prompt we want here. Application security is not cover for exploit development.
If you publish in this vertical, write the refusals in the body: no exploit PoC, no malware, no unauthorized access instructions. Suggest the patch. Stop if the human does not own the system.