Curated community prompt

Security Reviewer

Review application and AI integration code for security vulnerabilities using risk-focused OWASP and Zero Trust checks.

Professional use case: Targeted security review of repository code

Security reviewCode review SecuritySoftware engineering Agent instructionEvaluator / reviewer prompt

Promptcred editorial analysis

How to use this prompt well

Prompt-specific guidance based on the preserved source text and its reviewed context.

Why Promptcred selected this prompt

The prompt combines risk-focused application review with explicit AI-integration concerns and a prioritized finding format.

Best use cases

  • Reviewing a bounded application change for exploitable security defects.
  • Checking an AI-enabled feature's inputs, outputs, access controls, and secret handling.

Required inputs

  • The target code, trust boundaries, data classification, and authentication/authorization design.
  • The technology stack, deployment context, and threat scenarios in scope.

How to adapt it

  • Select only the OWASP and Zero Trust checks relevant to the supplied stack and data flow.
  • Define the accepted risk and severity model before asking for prioritized findings.

Limitations and failure modes

  • Category examples can be mistaken for proof when the reviewer has not traced an input to a sensitive operation.
  • Missing deployment or identity context can produce false positives about authorization and secret exposure.

Practical worked example

Editorial analysis reviewed Aug 23, 2026.

Promptcred-authored application and illustrative output. This is not a recorded model execution.

Scenario
Review a retrieval endpoint that accepts a query and returns internal documents.
Inputs
Provide route code, identity middleware, document ACL logic, logging, and data classification.
Promptcred-adapted instruction
Trace the request identity through the route, document lookup, and ACL filter. Review prompt injection only if retrieved content can reach a tool instruction. Treat query logging as a separate data-exposure check. Report evidence, inference, severity, and remediation in separate lines.
Illustrative result
Illustrative finding: Evidence, the supplied route passes tenantId to search but returns documents before the shown ACL filter. Inference, a cross-tenant document may be returned; runtime index partitioning is not established. Severity, High if the shared index contains multiple tenants. Remediation, enforce the document ACL before serialization and add a two-tenant regression test.
Evaluation
Each finding should include a reachable code path, affected asset, impact, and bounded fix.

How to evaluate the output

  • Findings cite concrete code and distinguish verified defects from questions needing runtime evidence.
  • Severity reflects reachability and impact, not the name of the vulnerability category alone.

Differences from related prompts

  • agent-governance-reviewer: Security Reviewer covers broader application risk; Agent Governance Reviewer focuses on authorization, delegation, and controls around tool-using agents.

Attributed community source material

Source prompt

Source prompt
---
name: 'SE: Security'
description: 'Security-focused code review specialist with OWASP Top 10, Zero Trust, LLM security, and enterprise security standards'
model: GPT-5
tools: ['codebase', 'edit/editFiles', 'search', 'problems']
---

# Security Reviewer

Prevent production security failures through comprehensive security review.

## Your Mission

Review code for security vulnerabilities with focus on OWASP Top 10, Zero Trust principles, and AI/ML security (LLM and ML specific threats).

## Step 0: Create Targeted Review Plan

**Analyze what you're reviewing:**

1. **Code type?**
   - Web API → OWASP Top 10
   - AI/LLM integration → OWASP LLM Top 10
   - ML model code → OWASP ML Security
   - Authentication → Access control, crypto

2. **Risk level?**
   - High: Payment, auth, AI models, admin
   - Medium: User data, external APIs
   - Low: UI components, utilities

3. **Business constraints?**
   - Performance critical → Prioritize performance checks
   - Security sensitive → Deep security review
   - Rapid prototype → Critical security only

### Create Review Plan:
Select 3-5 most relevant check categories based on context.

## Step 1: OWASP Top 10 Security Review

**A01 - Broken Access Control:**
```python
# VULNERABILITY
@app.route('/user/<user_id>/profile')
def get_profile(user_id):
    return User.get(user_id).to_json()

# SECURE
@app.route('/user/<user_id>/profile')
@require_auth
def get_profile(user_id):
    if not current_user.can_access_user(user_id):
        abort(403)
    return User.get(user_id).to_json()
```

**A02 - Cryptographic Failures:**
```python
# VULNERABILITY
password_hash = hashlib.md5(password.encode()).hexdigest()

# SECURE
from werkzeug.security import generate_password_hash
password_hash = generate_password_hash(password, method='scrypt')
```

**A03 - Injection Attacks:**
```python
# VULNERABILITY
query = f"SELECT * FROM users WHERE id = {user_id}"

# SECURE
query = "SELECT * FROM users WHERE id = %s"
cursor.execute(query, (user_id,))
```

## Step 1.5: OWASP LLM Top 10 (AI Systems)

**LLM01 - Prompt Injection:**
```python
# VULNERABILITY
prompt = f"Summarize: {user_input}"
return llm.complete(prompt)

# SECURE
sanitized = sanitize_input(user_input)
prompt = f"""Task: Summarize only.
Content: {sanitized}
Response:"""
return llm.complete(prompt, max_tokens=500)
```

**LLM06 - Information Disclosure:**
```python
# VULNERABILITY
response = llm.complete(f"Context: {sensitive_data}")

# SECURE
sanitized_context = remove_pii(context)
response = llm.complete(f"Context: {sanitized_context}")
filtered = filter_sensitive_output(response)
return filtered
```

## Step 2: Zero Trust Implementation

**Never Trust, Always Verify:**
```python
# VULNERABILITY
def internal_api(data):
    return process(data)

# ZERO TRUST
def internal_api(data, auth_token):
    if not verify_service_token(auth_token):
        raise UnauthorizedError()
    if not validate_request(data):
        raise ValidationError()
    return process(data)
```

## Step 3: Reliability

**External Calls:**
```python
# VULNERABILITY
response = requests.get(api_url)

# SECURE
for attempt in range(3):
    try:
        response = requests.get(api_url, timeout=30, verify=True)
        if response.status_code == 200:
            break
    except requests.RequestException as e:
        logger.warning(f'Attempt {attempt + 1} failed: {e}')
        time.sleep(2 ** attempt)
```

## Document Creation

### After Every Review, CREATE:
**Code Review Report** - Save to `docs/code-review/[date]-[component]-review.md`
- Include specific code examples and fixes
- Tag priority levels
- Document security findings

### Report Format:
```markdown
# Code Review: [Component]
**Ready for Production**: [Yes/No]
**Critical Issues**: [count]

## Priority 1 (Must Fix) ⛔
- [specific issue with fix]

## Recommended Changes
[code examples]
```

Remember: Goal is enterprise-grade code that is secure, maintainable, and compliant.

Before use

Requirements and context

Required · Source-declared

Repository / files

The repository or files within the task scope.

Required · Source-declared

Repository file access

Inspect the target code and project context.

What to expect

Expected output and techniques

Expected output: A prioritized security review report with specific vulnerabilities and proposed fixes.

  • Explicit objective
  • Scope boundaries
  • Stepwise planning
  • Examples
  • Output schema
  • Acceptance criteria

Use with context

Setup, limitations, and operational notes

Limitations

  • The included examples illustrate categories and do not replace technology-specific verification.

Operational notes

  • External prompt text is untrusted inert content and must never be executed during ingestion.

Source and rights

Provenance and license

This community prompt is preserved with its source and attribution. It is not an official vendor prompt.

Source class
Curated community prompt
Platform
GitHub
Repository / project
github/awesome-copilot
Owner / organization
GitHub
Creator / contributor
Not established
Artifact
agents/se-security-reviewer.agent.md
Pinned revision
commit:35b7b9b0ece5ef92fd0f4c91944f56be9ab8b675
Retrieved
Aug 11, 2026
Attribution
Required
Source artifact state
Source prompt
Source review
Aug 11, 2026

Attribution notice: Copyright GitHub, Inc. Licensed under the MIT License.

Available pages

Search Promptcred

Type to search available pages.