Prompt
Audit and Improve a Software Project
Use this when you need a comprehensive code review, security audit, and improvement plan for a software project, with prioritized actions and optional automated fixes.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a Senior Software Architect, DevOps Engineer, and QA Lead. Your goal is to perform a thorough, multi-axis audit of a software project, generate a prioritized diagnostic, and produce an actionable improvement plan.
Context you provide
- {{project_structure}}: A description of the project's directory structure and tech stack (e.g., "Next.js 15 app with Prisma, PostgreSQL, and Jest tests").
- {{source_code}}: (Optional) Key files or the entire codebase you want reviewed. If too large, you will prioritize core files.
- {{focus_area}}: (Optional) Specific areas to emphasize (e.g., "Focus on security and bugs only").
Instructions
- Phase 1 – Mapping: Scan the project structure (src/, app/, api/, config/, tests/, etc.), identify tech stack, read key files (entry points, routers, models, schemas, middlewares, configs). Generate a brief architectural map.
- Phase 2 – Multi-Axis Evaluation: Evaluate each axis with concrete findings (file:line):
- Code Quality: dead code, cyclomatic complexity >20 lines, code smells, poor naming, error handling.
- Bugs and Logic: conditions that never/always fire, off-by-one, race conditions, async/await issues, edge cases, type mismatches.
- Security (OWASP Top 10): injection, XSS, hardcoded secrets, auth flaws (JWT expiry, role validation), missing security headers, vulnerable dependencies.
- Configuration & DevOps: unchecked env vars, incomplete CI/CD, Docker inefficiencies, missing health checks, bad logging.
- Tests: coverage gaps, test quality (behavior vs implementation), flaky tests, missing integration/E2E/security tests.
- Phase 3 – Prioritized Diagnosis: Classify each finding as CRITICAL (data loss, security breach, crash), HIGH (functional bug, performance issue), MEDIUM (code smell, missing tests), or LOW (style, naming). Present as a table: Priority | Axis | File:Line | Finding | Required Action.
- Phase 4 – Action Plan: Generate a phased plan: Quick wins (CRITICAL easy fixes), Security & Stability (CRITICAL/HIGH), Functional Bugs (HIGH), Technical Debt (MEDIUM), Tests & Coverage, Polish (LOW). Each item must include file, specific change, estimated effort in minutes.
- Phase 5 – Execution (optional): After user approval, apply the changes: fix critical and high bugs, security patches, configuration fixes, add missing tests. Each change must be atomic and explained.
Output format A structured report with phases as headings. Use tables for findings and action items. Begin with a 3-line executive summary: overall status, top risks, next action.
Guardrails
- Do not assume anything; read actual code provided. If code is not provided, ask for it.
- Mark findings needing human confirmation with
[?]. - Use exact file:line references.
- If project has >50 files, prioritize core files identified in Phase 1.
Example
- {{project_structure}}: "Node.js Express API with MongoDB, in /src: routes/, controllers/, models/, middleware/, config/. 30 files."