Security Audit Checklist
Generates a structured security audit checklist for code review, covering authentication, input validation, data protection, API security, and infrastructure concerns.
When to use this prompt
Use this when you need a comprehensive security review framework tailored to a specific application's language, type, and data handling requirements. It's appropriate for pre-deployment audits, security assessments, or establishing ongoing code review standards.
You are a security engineer who conducts thorough code audits. Create a security audit checklist for a [LANGUAGE/FRAMEWORK] application. Application type: [TYPE] Key features: [FEATURES] Sensitive data handled: [DATA] Check for: 1. Authentication & Authorization - Session management - Password policies - Access control 2. Input Validation - SQL injection - XSS vulnerabilities - Command injection - File upload security 3. Data Protection - Encryption at rest - Encryption in transit - PII handling - Secrets management 4. API Security - Rate limiting - Authentication - Input validation - Error handling 5. Infrastructure - HTTPS configuration - Headers security - Dependency vulnerabilities For each item: what to check, common vulnerabilities, remediation guidance.
Free to use — the optimizer tailors this template to your exact task and target AI.
How to customize it
- [LANGUAGE/FRAMEWORK]: Specify the technology stack (e.g., Python/Django, Node.js/Express, Java/Spring) to get language-specific security considerations
- [TYPE]: Define the application category such as web app, REST API, mobile backend, or microservice to focus relevant security areas
- [FEATURES]: List core functionality like user authentication, payment processing, or file sharing that may introduce specific vulnerabilities
- [DATA]: Identify what sensitive information the application handles—user credentials, payment data, health records, or personal identifiable information
What you'll get back
A structured checklist organized into five security domains (authentication, input validation, data protection, API security, infrastructure), with each item including what to examine during audit, common vulnerability patterns to look for, and guidance on how to fix issues found.
More Coding prompts
Code Reviewer
Instructs AI to perform a comprehensive code review covering bugs, security, performance, style, and best practices with severity ratings and corrections.
Legacy Code Modernization
Generates a structured modernization plan for legacy code, including assessment, migration options, phased implementation, testing strategy, and risk management.
Regex Pattern Builder
Generates a regex pattern with detailed explanations, test cases, variations, and implementation code for your specific matching requirements.
Microservice Design
Generates a complete microservice architecture design including API endpoints, data management, infrastructure setup, and integration patterns for a specific functionality.
Make this prompt yours
PromptWizz rewrites this template around your specific task, audience, and target AI — and shows you why each change works.
Try the Optimizer Free