What this prompt does
This prompt drives ChatGPT through a systematic, seven-point security checklist against your specific language and framework combination. By naming both [language] and [framework], you force the model to give framework-specific advice — Laravel CSRF middleware versus Express.js helmet(), for example — rather than generic security platitudes that apply to nothing in particular.
The most valuable structural decision in this template is the output format it demands: severity tier, exact code location, an exploit scenario, and remediation code for every finding. That four-part structure means you get actionable tickets, not a list of vague warnings. A junior dev reading the output knows what to fix, where to find it, and what the working patch looks like.
The [areas] variable for sensitive data exposure is intentional scope control. Point it at API responses, logs, error messages and you get a different audit than pointing it at database queries, session storage — both are necessary, and running them as separate focused passes beats one unfocused sweep.
When to use it
- Before opening a pull request that touches authentication, payments, or user data.
- During a pre-launch checklist when no dedicated security engineer is on the team.
- When onboarding to a legacy codebase and you need a fast first-pass threat model.
- After adding a third-party package or SDK — fill
[areas]withdependency callbacks, webhook handlers. - When scoping a bug bounty program and you want to pre-empt the obvious OWASP findings yourself.
- Before a penetration test, to reduce billable hours on low-hanging fruit.
Example output
For PHP / Laravel with [auth_type] = JWT and [areas] = API responses, error messages:
FINDING: JWT Algorithm Confusion (Severity: CRITICAL)
Location: app/Http/Middleware/AuthenticateJWT.php:34
Exploit: If the server accepts 'alg: none', an attacker strips the
signature and forges any payload without a secret key.
Fix:
// Before
JWT::decode($token, $key, ['HS256', 'none']);
// After
JWT::decode($token, $key, ['HS256']);
// Whitelist only the expected algorithm. Never include 'none'.
Pro tips
- Run the prompt twice with different
[areas]values — data exposure inlogs and stack tracessurfaces different issues thanAPI payloads and headers. Each pass stays focused. - For
[auth_type], be precise:session-based with remember-me tokensgives sharper results than justsession. The more specific the variable, the less generic the output. - Always ask for remediation code in the same language/framework you named — if ChatGPT drifts into pseudocode, re-prompt with "show the fix as actual [framework] code, not pseudocode."
- Pair the output with
composer auditornpm auditto validate the dependency findings it surfaces — ChatGPT can miss CVE version specifics that package managers catch precisely. - Treat severity ratings as a starting point, not gospel. ChatGPT can misclassify context-dependent issues. Re-evaluate anything marked critical against your actual threat model before escalating it.