Perform security scans

Perform security scans in Linux — with the four heights of help laid out: do it now, make it easier for the next person to accept, work out the right move when you are stuck, and learn the pattern so it stops coming back.

4prompt heights
Open it in the interactive atlas →

The four heights

The same task, four distances: today's deadline, the next reviewer, the stuck moment, the pattern.

Execute — do the immediate task

+
Run the full security scan suite against the web tier scheduled for tomorrow and deliver a…
Run the full security scan suite against the web tier scheduled for tomorrow and deliver a remediation ticket list to the security board by 10:00. Use the scanner profile high-checks on host web-01, include CVE severity and exploitable flags, and verify that false positives are suppressed for the legacy SSO component before you publish.

Improve — make it easier to accept

+
Before I hand the scan report to compliance, make it easy to act on. Put the top five exploitable…
Before I hand the scan report to compliance, make it easy to act on. Put the top five exploitable CVEs with their impact on the login flow at the top, make remediation steps for each vulnerability concise and owner-assigned, and flag anything that would require a change-window or client notification.

Decide — diagnose the stuck moment

+
The nightly scanner reported dozens of low-confidence vulnerabilities on web-02 that we don't see…

The automated scan found dozens of low-confidence vulnerabilities on a production host

The nightly scanner reported dozens of low-confidence vulnerabilities on web-02 that we don't see in staging. I'm the on-call engineer, the site reliability lead is Hannah, and we have a compliance audit next week. I'm worried reporting them verbatim will trigger an unnecessary incident and waste remediation time, but suppressing them might miss a real problem. I don't know whether these are scanner configuration issues or real drift. What's the most likely cause and the recommended immediate action?

Become — change the pattern

+
Across multiple audits we keep spending developer time chasing low-confidence scanner findings that…

We spend weeks chasing low-value scan findings

Across multiple audits we keep spending developer time chasing low-confidence scanner findings that never pan out. I'm responsible for the scan program, the engineering managers rotate ownership, and we use two different scanner tools. I think the problem is noisy rules and lack of triage but I'm unsure which policy change will reduce waste. What specific habit should we introduce to cut false-positive remediation time by half?

Next to this one

Other operating system work people do in Linux.

Every task here came from the work, not from a feature list — which is why the prompts name what you want done and never the button that does it. The tool changes; the work does not.
Copyright © LLOS.ai · 2026 — original pedagogy, voice, and design — all rights reserved.

The rest of the map

Same library, five ways in.