Code security review prompt: find real risks

Paste a code snippet to get a focused security review covering injection, authorization, and secret-handling risks.

بواسطة ‪Ahmed Eid‬‏Claude0 نسخة

متى تستخدم هذا البرومبت

  • Before merging code that handles user input or authentication.
  • When reviewing a third-party contribution.
  • As a lightweight check before a full security audit.

نص البرومبت

Perform a security review of this {{language}} code. Look for injection risks, auth/authorization gaps, unsafe deserialization, and secret handling issues. Framework: {{framework}}.

{{CLIPBOARD}}
{{language}}{{framework}}{{CLIPBOARD}}

الكتلة {{CLIPBOARD}} تُستبدل تلقائياً بما نسخته قبل الضغط على «نسخ».

كيف تستخدمه

  1. انسخ البرومبت بالزر أو املأ المتغيرات أولاً.
  2. الصقه في ChatGPT أو Claude أو Gemini.
  3. عدّل النتيجة أو أعد الطلب بتغيير المتغيرات.

مثال على النتيجة

Finding: SQL query built with string concatenation of req.query.name, SQL injection risk.

Fix: use a parameterized query:
db.query('SELECT * FROM users WHERE name = $1', [name]);

Severity: High, user-controlled input reaches the database directly.

نصائح للاستخدام

  • Paste the full request-handling path, not just the vulnerable line, so context isn't missed.
  • Ask it to rank findings by severity if the snippet is large.
  • This is a lightweight first pass, not a substitute for a full security audit on sensitive systems.

النماذج الموصى بها

Claude

أسئلة شائعة

Is this a replacement for a professional security audit?
No, treat it as a fast first pass to catch common issues; sensitive or regulated systems still need a full audit.
Will it check for framework-specific vulnerabilities?
Yes if you specify the framework, since risks like mass assignment or CSRF differ significantly between them.

برومبتات ذات صلة

Generate a GraphQL Schema from a Description

Describe your data and operations in plain English and get a complete, documented GraphQL schema.

Design a GraphQL schema (types, queries, mutations) for: {{focus}}. Use {{language}} conventions and include field-level descriptions. {{CLIPBOARD}}

{{focus}}{{language}}{{CLIPBOARD}}

Generate Realistic Mock Data for Testing

Get realistic, varied mock data, including edge cases, matched to your schema, ready to seed a test database.

Generate {{focus}} realistic mock/test data records in {{language}} format for this schema or type, with varied and edge-case values. {{CLIPBOARD}}

{{focus}}{{language}}{{CLIPBOARD}}

Explain What This Legacy Code Actually Does

Paste unfamiliar or legacy code and get a plain-language walkthrough, with dead code and possible bugs flagged.

Walk through this {{language}} code line by line and explain what it does, in plain language. Flag anything that looks like dead code, a workaround, or a potential bug. {{CLIPBOARD}}

{{language}}{{CLIPBOARD}}

Generate a Dockerfile for Your App

Get a secure, optimized Dockerfile tailored to your language and framework, ready to build and run.

Write a production-ready Dockerfile for a {{language}} app using {{framework}}. Use multi-stage builds where useful, minimize image size, and run as a non-root user. Notes: {{focus}}. {{CLIPBOARD}}

{{language}}{{framework}}{{focus}}{{CLIPBOARD}}
المزيد في برمجة