Skip to main content

Claude/ChatGPT Prompt to Run a Security Audit on Your App

Security audit prompt covering OWASP Top 10, auth bypasses, injection, and data exposure with severity ratings and remediation code.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
You are a senior application security engineer. Audit my code seriously and return exploit scenarios plus working remediation code, not generic warnings.

Context:
- Language and framework: PHP / Laravel
- Authentication type: session-based
- Sensitive areas to check: API responses, logs, error messages, and config files
- Code or routes to review: <paste controllers and routes>

Check for and report:
1) OWASP Top 10 vulnerabilities present in the code.
2) Authentication and authorization flaws, including the access-control gaps specific to my auth type.
3) SQL injection and XSS vectors with the exact tainted path.
4) Sensitive data exposure across the areas above.
5) CSRF gaps, missing rate limiting, and brute-force exposure.
6) Dependency vulnerabilities worth flagging.

For each issue return: severity (critical/high/medium/low), specific code location, a concrete exploit scenario, and the remediation code. Sort by severity, highest first.

What this prompt does

This prompt drives ChatGPT through a systematic, seven-point security checklist against your specific language and framework combination. By naming both [language] and [framework], you force the model to give framework-specific advice — Laravel CSRF middleware versus Express.js helmet(), for example — rather than generic security platitudes that apply to nothing in particular.

The most valuable structural decision in this template is the output format it demands: severity tier, exact code location, an exploit scenario, and remediation code for every finding. That four-part structure means you get actionable tickets, not a list of vague warnings. A junior dev reading the output knows what to fix, where to find it, and what the working patch looks like.

The [areas] variable for sensitive data exposure is intentional scope control. Point it at API responses, logs, error messages and you get a different audit than pointing it at database queries, session storage — both are necessary, and running them as separate focused passes beats one unfocused sweep.

When to use it

  • Before opening a pull request that touches authentication, payments, or user data.
  • During a pre-launch checklist when no dedicated security engineer is on the team.
  • When onboarding to a legacy codebase and you need a fast first-pass threat model.
  • After adding a third-party package or SDK — fill [areas] with dependency callbacks, webhook handlers.
  • When scoping a bug bounty program and you want to pre-empt the obvious OWASP findings yourself.
  • Before a penetration test, to reduce billable hours on low-hanging fruit.

Example output

For PHP / Laravel with [auth_type] = JWT and [areas] = API responses, error messages:

FINDING: JWT Algorithm Confusion (Severity: CRITICAL)
Location: app/Http/Middleware/AuthenticateJWT.php:34
Exploit: If the server accepts 'alg: none', an attacker strips the
         signature and forges any payload without a secret key.
Fix:
  // Before
  JWT::decode($token, $key, ['HS256', 'none']);

  // After
  JWT::decode($token, $key, ['HS256']);
  // Whitelist only the expected algorithm. Never include 'none'.

Pro tips

  • Run the prompt twice with different [areas] values — data exposure in logs and stack traces surfaces different issues than API payloads and headers. Each pass stays focused.
  • For [auth_type], be precise: session-based with remember-me tokens gives sharper results than just session. The more specific the variable, the less generic the output.
  • Always ask for remediation code in the same language/framework you named — if ChatGPT drifts into pseudocode, re-prompt with "show the fix as actual [framework] code, not pseudocode."
  • Pair the output with composer audit or npm audit to validate the dependency findings it surfaces — ChatGPT can miss CVE version specifics that package managers catch precisely.
  • Treat severity ratings as a starting point, not gospel. ChatGPT can misclassify context-dependent issues. Re-evaluate anything marked critical against your actual threat model before escalating it.

Frequently Asked Questions

Can this prompt replace a real penetration test?
No, and it does not claim to. ChatGPT audits what you paste — it has no runtime visibility, no network access, and cannot discover misconfigurations in your server or cloud environment. Use this for code-level static analysis and treat it as preparation for a pentest, not a substitute.
How much code should I paste in with this prompt?
Paste the specific files relevant to each audit area rather than your entire codebase. For the auth section, include your middleware, guards, and token handling. For SQL injection, include your query builders and raw DB calls. Focused context produces focused findings — dumping 3,000 lines produces noise.
What do I put in [areas] if I'm not sure where my sensitive data lives?
Start with: 'API JSON responses, server error messages, application logs, session data'. These four cover the most common accidental exposure patterns across most web applications. Once ChatGPT returns findings, you can run a second pass targeting whatever specific areas it flags as higher risk.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in ChatGPT Prompts for Developers

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support