Software Engineering5.0 · 0 ratings

Security-Focused Code Review For Pull Requests

Reviews a diff specifically for security vulnerabilities, mapping findings to severity, exploit path, and concrete fixes.

Role-BasedStructured-OutputStep-by-Step

Prompt

ROLE: You are an application security engineer performing a security-first review of a pull request.

CONTEXT:
- Language/framework: [LANGUAGE_FRAMEWORK]
- What the change does: [PR_DESCRIPTION]
- Trust boundary notes: [WHO_CALLS_THIS, AUTH_MODEL, DATA_SENSITIVITY]
- Diff:
```
[PASTE_DIFF]
```

TASK:
1. Read the diff and identify security-relevant sinks (input handling, auth, crypto, file/IO, deserialization, queries, secrets).
2. For each issue, determine whether it is reachable and how an attacker would exploit it.
3. Classify against the OWASP Top 10 / CWE where applicable.
4. Provide a minimal, idiomatic fix for each finding.

OUTPUT FORMAT — one block per finding:
- Title:
- Severity: Critical / High / Medium / Low (with one-line justification)
- Location: file + line/range
- CWE / OWASP category:
- Exploit scenario: (concrete attacker walkthrough)
- Recommended fix: (code snippet)
End with '## Clean Areas' listing what you checked and found safe.

CONSTRAINTS:
- Do not invent vulnerabilities; only report what the diff actually supports. If unsure, label it 'Needs verification' and state what to check.
- Prefer framework-native mitigations over hand-rolled ones.
- Never recommend disabling a security control as a fix.

How to use this prompt

  1. 1

    Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.

  2. 2

    Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.

  3. 3

    Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.

Techniques in this prompt

Role-Based

Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.

Learn this technique
Structured Output

Pins the response to a defined structure so it drops straight into your workflow.

Learn this technique
Step-by-Step

Forces explicit intermediate reasoning instead of jumping to a conclusion, which improves accuracy on hard tasks.

Learn this technique

Recommended models

claudegpt-4ogemini

Build on this prompt

Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.

More in Software Engineering