Security review with evidence
Review an actual change for exploitable trust-boundary failures and rank findings by risk.
Read this prompt as Markdown or plain text
When to use it
A trust-boundary inventory plus required abuse paths filters out generic scanner prose and makes each finding reproducible and triageable.
Prompt
Perform a security review of [CHANGE, PR, OR COMPONENT]. Do not edit code. Establish scope first: identify entry points, data stores, external services, identities, privileges, secrets, and trust boundaries. Read the relevant diff plus the surrounding code that controls authentication, authorization, validation, serialization, persistence, logging, and error handling. Test the change against these risk areas where applicable: - authentication and session handling - resource-level and function-level authorization - injection, unsafe deserialization, SSRF, path traversal, and command execution - secrets or sensitive data exposure in source, logs, errors, telemetry, caches, or clients - insecure defaults, missing rate limits, replay/race conditions, and dependency risk - prompt injection, untrusted tool output, and excessive agency for AI features For every finding provide: 1. Severity: critical / high / medium / low 2. Exact file and line or symbol 3. Attacker prerequisites and a concrete abuse path 4. Impact and affected data or capability 5. Evidence from the code; clearly label anything inferred 6. The smallest safe remediation 7. A verification test that would prove the fix Do not report style issues as vulnerabilities. Do not claim a control is missing until you trace callers and middleware. End with reviewed surfaces, clean controls you verified, unresolved unknowns, and an overall risk assessment.
Adapt it to your task
Condensed and made repository-review focused from GitHub Awesome Copilot's SE: Security agent.
Third-party prompt. Source review does not establish benchmark performance or guarantee an outcome.
Source and license
Contributor: @niksacdev. Repository: github/awesome-copilot.
License: MIT. Pinned commit: b95e24caae4f25c5985f8527fd092ccfed039c36.
Review: source-reviewed, . Compared with the commit-pinned source and adapted into a tool-neutral, copy/paste request. This is a non-visual task, so no output artifact is required.