Skip to main content
CodingArchitectureadvancedFeatured

Defensive Application Security & OWASP Code Vulnerability Audit

Conduct a defensive security audit targeting OWASP Top 10 vulnerabilities, IDOR, SSRF, and auth bypasses.

Compatibility & Specs

Compatible AI Models
ClaudeChatGPTGemini
Last UpdatedOct 3, 2026
Customizable Variables3 parameters

How to Use This Prompt

Follow this 3-step workflow to extract high-signal responses from any compatible AI model.

01

1. Tailor the Parameters

Use the interactive customizer above to substitute the bracketed placeholders with your exact context, requirements, and constraints.

02

2. Send to AI Model

Copy the prompt and paste it into Claude, ChatGPT, Gemini, or Copilot. These models follow structured multi-step constraints reliably.

03

3. Review and Iterate

Review the output against the verified benchmark below. Follow up in the conversation to stress-test edge cases or refine tone.

Prompt Variables & Parameters

Reference breakdown of every dynamic variable embedded in this prompt template.

PlaceholderParameter NameTypeStatusDescription & Guidance
[code_to_audit]Code to AudittextareaRequiredThe source code of the endpoint or serviceDefault: app.post('/api/user/webhook', async (req, res) => { const { targetUrl, metadata } = req.body; // Save webhook await db.query(`INSERT INTO webhooks (url, meta) VALUES ('${targetUrl}', '${JSON.stringify(metadata)}')`); // Send test ping const ping = await fetch(targetUrl, { method: 'POST', body: JSON.stringify({ event: 'ping' }) }); res.json({ success: true, status: ping.status }); });
[auth_model]Auth ModeltextRequiredHow requests are authenticated and authorizedDefault: Bearer JWT in Authorization header; `req.user` populated by middleware.
[data_sensitivity]Data Sensitivity LeveltextRequiredWhat data is stored or processedDefault: Enterprise customer tenant data and internal AWS infrastructure VPC access.

Example Execution & Benchmark Output

Sample input arguments and the verified AI response demonstrating expected quality and formatting.

Sample VariablesInputs
[code_to_audit]
app.post('/api/user/webhook', async (req, res) => { const { targetUrl, metadata } = req.body; // Save webhook await db.query(`INSERT INTO webhooks (url, meta) VALUES ('${targetUrl}', '${JSON.stringify(metadata)}')`); // Send test ping const ping = await fetch(targetUrl, { method: 'POST', body: JSON.stringify({ event: 'ping' }) }); res.json({ success: true, status: ping.status }); });
[auth_model]
Bearer JWT in Authorization header; `req.user` populated by middleware.
[data_sensitivity]
Enterprise customer tenant data and internal AWS infrastructure VPC access.
Expected AI ResponseVerified Result
### AppSec Security Audit Findings #### 1. Identified Critical Vulnerabilities - **Vulnerability 1: Server-Side Request Forgery (SSRF - Critical):** The code directly fetches an unvalidated user-supplied URL (`targetUrl`). An attacker can supply `http://169.254.169.254/latest/meta-data/` to steal AWS IAM role credentials from the AWS instance metadata service, or scan internal RFC 1918 private VPC addresses (`http://10.0.1.5:5432`). - **Vulnerability 2: SQL Injection (Critical):** `targetUrl` and `metadata` are concatenated directly into raw SQL strings without parameterization. - **Vulnerability 3: Missing Tenant Authorization (IDOR):** The webhook is inserted without binding to `req.user.tenant_id`. #### 2. Hardened Defensive Refactor ```typescript import { z } from 'zod'; import ipaddr from 'ipaddr.js'; const WebhookSchema = z.object({ targetUrl: z.string().url().refine(url => { const parsed = new URL(url); if (parsed.protocol !== 'https:') return false; // Reject private IP ranges (SSRF defense) const addr = ipaddr.parse(parsed.hostname); return addr.range() === 'unicast'; }, { message: 'Must be a public HTTPS URL' }), metadata: z.record(z.string()) }); // Use parameterized query bound to authenticated tenant await db.query( 'INSERT INTO webhooks (tenant_id, url, meta) VALUES ($1, $2, $3)', [req.user.tenant_id, validated.targetUrl, validated.metadata] ); ```

Best Use Cases

Scenarios and roles where this prompt produces maximum leverage.

Security engineers and developers reviewing code before enterprise customer compliance audits
Backend developers securing webhook receivers and third-party integrations against SSRF
Tech leads establishing automated secure coding standards across teams

Tips for Best Results

Techniques to elevate response fidelity

  • •Provide rich background context rather than one-sentence inputs to receive deep, non-generic responses.
  • •Engage in multi-turn conversation: use the initial output as a baseline, then ask the AI to sharpen specific sections.
  • •Prompt the model to highlight any hidden assumptions or missing trade-offs in its recommendations.

Common Mistakes to Avoid

Frequent failure modes and anti-patterns

  • •Giving minimal context and expecting nuanced, expert-level strategic output.
  • •Not validating factual references, citations, or statistical claims with verified primary sources.
  • •Skipping the customization step and pasting raw bracketed template variables into the AI chat.

Related AI Prompts

Complementary workflows in Coding

View all Coding prompts
Codingadvanced

Production Incident Post-Mortem & Root-Cause Synthesizer

Convert messy incident Slack logs and alerts into a blameless, rigorous post-mortem with corrective action items.

claudechatgptgemini
#post-mortem#root-cause-analysis#sre
Codingadvanced

REST & GraphQL API Design & Backwards Compatibility Review

Audit proposed API endpoints for idempotent operations, naming consistency, pagination schemas, and breaking change risks.

claudechatgptgemini
#api-design#rest-api#graphql
Codingadvanced

Production Bug Forensic Root-Cause Analysis & 5-Whys

Conduct a blameless post-mortem, trace crash telemetry, and execute a 5-Whys root cause investigation.

claudechatgptgemini
#root-cause-analysis#post-mortem#debugging

Related Engineering Guides

Deep-dive playbooks and system prompt methodologies for Coding

View all guides