# Security review with evidence Source: https://refyneit.com/prompts/security-review-evidence Review an actual change for exploitable trust-boundary failures and rank findings by risk. ## When to use it A trust-boundary inventory plus required abuse paths filters out generic scanner prose and makes each finding reproducible and triageable. ## Prompt Perform a security review of [CHANGE, PR, OR COMPONENT]. Do not edit code. Establish scope first: identify entry points, data stores, external services, identities, privileges, secrets, and trust boundaries. Read the relevant diff plus the surrounding code that controls authentication, authorization, validation, serialization, persistence, logging, and error handling. Test the change against these risk areas where applicable: - authentication and session handling - resource-level and function-level authorization - injection, unsafe deserialization, SSRF, path traversal, and command execution - secrets or sensitive data exposure in source, logs, errors, telemetry, caches, or clients - insecure defaults, missing rate limits, replay/race conditions, and dependency risk - prompt injection, untrusted tool output, and excessive agency for AI features For every finding provide: 1. Severity: critical / high / medium / low 2. Exact file and line or symbol 3. Attacker prerequisites and a concrete abuse path 4. Impact and affected data or capability 5. Evidence from the code; clearly label anything inferred 6. The smallest safe remediation 7. A verification test that would prove the fix Do not report style issues as vulnerabilities. Do not claim a control is missing until you trace callers and middleware. End with reviewed surfaces, clean controls you verified, unresolved unknowns, and an overall risk assessment. ## Adaptation and provenance Condensed and made repository-review focused from GitHub Awesome Copilot's SE: Security agent. Contributor: [@niksacdev](https://github.com/niksacdev) Repository: https://github.com/github/awesome-copilot Pinned commit: b95e24caae4f25c5985f8527fd092ccfed039c36 License: [MIT](https://github.com/github/awesome-copilot/blob/b95e24caae4f25c5985f8527fd092ccfed039c36/LICENSE) - [se-security-reviewer](https://github.com/github/awesome-copilot/blob/b95e24caae4f25c5985f8527fd092ccfed039c36/agents/se-security-reviewer.agent.md) Review: source-reviewed, 2026-08-23. Compared with the commit-pinned source and adapted into a tool-neutral, copy/paste request. This is a non-visual task, so no output artifact is required.