DISCOVER ON TOOLFINDINGSElephasAI writing and knowledge assistant for Apple devices and personal workflows.Explore Tool
Coding · Intermediate

Secure Code Review

Secure Code Review is a practical, reusable AI prompt for coding, template, practical. For “Secure Code Review”, interpret this guidance in the context of the real task rather than as a generic prompting rule: This expanded guide turns the prompt page into a complete working reference: what to prepare, how to use the prompt, how to improve the first response and how to validate the final result.

When to use this prompt

To improve “Secure Code Review”, define this point for the actual input and output: use it when you need a repeatable result with clear constraints instead of a vague one-line instruction. When using “Secure Code Review”, make this checkpoint specific to the source material and acceptance criteria: Before starting, define the business or personal objective, the intended audience, relevant background information and the exact deliverable you expect.

Information to provide

  • Objective: state the outcome, decision or asset you need.
  • Context: To improve “Secure Code Review”, define this point for the actual input and output: provide facts, source material and background the model must respect.
  • Audience: identify who will read, approve or act on the result.
  • Constraints: When using “Secure Code Review”, apply this prompt-specific requirement: specify tone, scope, length, exclusions, policies or brand requirements.
  • Output structure: For “Secure Code Review”, use this task-specific prompting checkpoint: request the exact headings, steps, fields, table columns or format you need.
  • Acceptance criteria: describe what a useful final answer must include.

Step-by-step usage

For “Secure Code Review”, use this task-specific prompting checkpoint: replace every placeholder with concrete information before submitting the prompt. For “Secure Code Review”, apply this guidance to the exact input, audience and output required: Run the first version, then compare the response against the acceptance criteria rather than judging it only by fluency. For “Secure Code Review”, apply this guidance to the exact input, audience and output required: If something is missing, make a targeted follow-up request that identifies the exact section and correction required.

Refinement strategy

For “Secure Code Review”, use this task-specific prompting checkpoint: for style-sensitive work, provide a short example of the desired voice or format. To improve “Secure Code Review”, connect this principle to the requested format and downstream use: For fact-sensitive work, supply authoritative source material and ask the model to distinguish supplied facts from assumptions or recommendations. When using “Secure Code Review”, make this checkpoint specific to the source material and acceptance criteria: Ask for alternatives only when they help the decision; otherwise keep the model focused on improving the selected direction.

Model and difficulty guidance

This prompt is classified as intermediate. Listed model guidance: ChatGPT, Claude, Gemini. Related topics include coding, template, practical. When using “Secure Code Review”, make this checkpoint specific to the source material and acceptance criteria: Different assistants may interpret the same wording differently, so preserve the objective, inputs, constraints and output specification when adapting it.

Accuracy and safety checks

AI output can contain outdated or invented details. For “Secure Code Review”, apply this guidance to the exact input, audience and output required: Independently verify important names, dates, figures, quotations, links and claims. For “Secure Code Review”, apply this guidance to the exact input, audience and output required: For legal, medical, financial, security or other high-impact decisions, use appropriate qualified review rather than relying on generated text alone.

Final checklist

  • All placeholders contain real information.
  • For “Secure Code Review”, make this instruction specific to the requested result: the response addresses the stated objective and audience.
  • The requested structure and constraints were followed.
  • Important factual claims were checked.
  • Unsupported assumptions were corrected or removed.
  • For “Secure Code Review”, make this instruction specific to the requested result: the final output was edited for clarity, relevance and practical use.
ChatGPT Claude Gemini
Full prompt

Prompt text

Act as a senior software engineer performing a security-aware code review.

CODE
{code}

OBJECTIVE
Review the supplied code before rewriting anything.

ANALYSE:

1. CORRECTNESS
- logical errors
- edge cases
- invalid assumptions
- error handling
- concurrency/state issues where relevant

2. SECURITY
Check where applicable:
- input validation
- output escaping
- SQL injection
- command injection
- authentication
- authorisation
- CSRF
- file upload/path handling
- secret exposure
- insecure direct object references
- dangerous deserialisation
- external requests

3. DATA SAFETY
- destructive operations
- transaction handling
- duplicate writes
- data leakage
- unexpected NULL/empty values

4. MAINTAINABILITY
- duplicated logic
- confusing naming
- unnecessary coupling
- unreachable code
- fragile assumptions

5. PERMISSIONS
Explain which operations require access controls and whether the supplied code enforces them.

RANK FINDINGS:
Critical / High / Medium / Low / Informational

FOR EACH FINDING:
- location
- problem
- impact
- evidence from code
- recommended fix

ONLY AFTER THE REVIEW:
Provide a corrected example for issues that clearly require code changes.

Do not redesign unrelated working code.

OUTPUT FORMAT

## Executive Summary
## Risk-Ranked Findings
## Corrected Code
## Regression Risks
## Required Tests
## Assumptions / Missing Context
Expected structure

What a useful answer should look like

A risk-ranked code review with evidence, security and correctness findings, focused corrected code, regression risks and required tests.
Use responsibly

How to get a better result

Add real context

Replace every placeholder and include constraints, audience and source material.

Verify claims

Open original sources for factual, legal, medical, financial or time-sensitive information.

Iterate deliberately

Ask for revisions against a rubric instead of accepting the first output.

Questions from ToolQuestions

Practical ChatGPT Q&A

Continue your research with relevant published questions and concise answers from ToolQuestions.

View all questions ↗
Page 1 of 7
Questions from ToolQuestions

Practical Claude Q&A

Continue your research with relevant published questions and concise answers from ToolQuestions.

View all questions ↗
?
Business

What should I document after a Claude pilot?

For Claude, regarding “What should I document after a Claude pilot?”: Treat Claude as a team process, not only a tool: assign an owner, define review rules, document permissions, measure outcomes and keep a fallback f...

Read answer →
Page 1 of 8

Related research and practical resources

Move between explanation, evaluation and practical use without losing context.