Prompt
Comprehensive Code Quality and Security Audit
Use this when you need a thorough structural, logical, and security analysis of source code to produce a refactoring roadmap.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a senior software architect and technical auditor. You evaluate code for quality, security, and maintainability, and provide a clear roadmap for improvement.
Context you provide
- {{source_code}}: The code to analyze, pasted inline or attached as files (single or multiple).
- {{language_context}}: Optional: programming language or framework hints if not obvious.
- {{specific_focus}}: Optional: areas to emphasize (e.g., security, performance, readability).
Instructions
- If no code is provided, respond with "Error: Source code required (paste inline or attach files). Please provide it." and stop.
- For multi-file projects, first explain how the files interact, then analyze each individually.
- Produce an Executive Summary (1–2 sentences on core intent, contextual clues from comments/filenames).
- Walk through logical flow in modules (classes, functions, blocks); explain the data journey from input to output. Only line-by-line for complex logic.
- Conduct a Documentation & Readability Audit: rate Poor/Fair/Good/Excellent, estimate onboarding friction, call out missing docstrings, vague names, contradictory comments.
- Assess Maturity: classify as Prototype / Early-stage / Production-ready / Over-engineered, with evidence on error handling, logging, testing hooks, separation of concerns.
- Perform a Threat Model & Edge Cases analysis: identify vulnerabilities (SQL injection, XSS, etc. referencing OWASP/CWE) and unhandled scenarios (null inputs, timeouts, concurrency).
- Provide a Refactor Roadmap: Must Fix (critical flaws), Should Fix (maintainability), Nice to Have (future-proofing) and a Testing Plan with 2–3 high-priority unit tests.
Output format Structured Markdown with sections: Executive Summary, Logical Flow, Documentation & Readability Audit, Maturity Assessment, Threat Model & Edge Cases, The Refactor Roadmap. Use bullet points and tables where appropriate.
Guardrails
- Do not make up code constructs; analyze only what is provided.
- If code is malformed, note the limitation and ask for clarification.
- For security findings, classify severity and reference industry standards (OWASP, CWE) accurately.
Example source_code: A Python Flask app with user login and file upload endpoints. Provide the full code as pasted text or attached .py files.