Security-Focused Code Review For Pull Requests
Reviews a diff specifically for security vulnerabilities, mapping findings to severity, exploit path, and concrete fixes.
Prompt
ROLE: You are an application security engineer performing a security-first review of a pull request. CONTEXT: - Language/framework: [LANGUAGE_FRAMEWORK] - What the change does: [PR_DESCRIPTION] - Trust boundary notes: [WHO_CALLS_THIS, AUTH_MODEL, DATA_SENSITIVITY] - Diff: ``` [PASTE_DIFF] ``` TASK: 1. Read the diff and identify security-relevant sinks (input handling, auth, crypto, file/IO, deserialization, queries, secrets). 2. For each issue, determine whether it is reachable and how an attacker would exploit it. 3. Classify against the OWASP Top 10 / CWE where applicable. 4. Provide a minimal, idiomatic fix for each finding. OUTPUT FORMAT — one block per finding: - Title: - Severity: Critical / High / Medium / Low (with one-line justification) - Location: file + line/range - CWE / OWASP category: - Exploit scenario: (concrete attacker walkthrough) - Recommended fix: (code snippet) End with '## Clean Areas' listing what you checked and found safe. CONSTRAINTS: - Do not invent vulnerabilities; only report what the diff actually supports. If unsure, label it 'Needs verification' and state what to check. - Prefer framework-native mitigations over hand-rolled ones. - Never recommend disabling a security control as a fix.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniquePins the response to a defined structure so it drops straight into your workflow.
Learn this techniqueForces explicit intermediate reasoning instead of jumping to a conclusion, which improves accuracy on hard tasks.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Software Engineering
Production Incident Root Cause Analysis
Drives a disciplined RCA from symptoms to root cause and prevention, separating contributing factors from the true trigger.
Legacy Code Refactoring Strategist
Plans a safe, incremental refactor of tangled legacy code with characterization tests and reversible seams.
API Contract Designer With OpenAPI Output
Designs a consistent, versioned REST resource and emits a ready-to-use OpenAPI 3.1 fragment plus error model.
Unit Test Generator With Edge Case Coverage
Generates a complete test suite that maps each assertion to a behavior, prioritizing boundaries and failure modes.