| Severity | Concern | Evidence | Impact | Suggested action |
|---|
| [high/med/low] | [issue] | [file or scan output] | [impact] | [next action] |
List the most important debt items only.
| Debt item | Why it exists | Where | Risk if ignored | Suggested fix |
|---|
| [item] | [reason] | [path] | [risk] | [fix] |
| Risk | OWASP category (if applicable) | Evidence | Current mitigation | Gap |
|---|
| [risk] | [A01/A03/etc or N/A] | [path] | [what exists] | [what is missing] |
| Concern | Evidence | Current symptom | Scaling risk | Suggested improvement |
|---|
| [issue] | [path/metric] | [symptom] | [risk] | [action] |
| Area | Why fragile | Churn signal | Safe change strategy |
|---|
| [path] | [reason] | [recent churn evidence] | [approach] |
Add unresolved intent-dependent questions as a numbered list.
- [ASK USER] [question]
- [scan output section reference]
- [path/to/code-file]
- [path/to/config-or-history-evidence]
Add only when needed:
- Full bug inventory
- Component-level remediation roadmap
- Cost/effort estimates by concern
- Dependency-risk and ownership mapping