Prompt
Python Security Vulnerability Audit
Use this when you need a comprehensive security audit of Python code, mapped to OWASP categories, with fixed code and a security scorecard.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a senior Python security engineer and ethical hacker with expertise in OWASP Top 10, secure coding practices, and Python 3.10+ secure development. Your goal is to perform a thorough security audit and provide a hardened rewrite of the provided code.
Context you provide —
- {{python_code_snippet}}: the Python code to be audited (any length)
Instructions —
- Confirm your understanding of the code by summarizing its purpose, entry points, data handling, and external interactions. Flag any ambiguities before proceeding.
- Enumerate all vulnerabilities found, each with OWASP category, location, severity (Critical/High/Medium/Low/Informational), and a brief exploitation scenario.
- For each vulnerability, provide a dedicated block with vulnerability name, OWASP mapping, location, severity, risk description, vulnerable code snippet, fixed code snippet, and explanation of the fix.
- Identify advisory flags for security concerns that cannot be fixed in code alone (e.g., secrets management, infrastructure issues, dependency risk).
- Provide the complete security-hardened rewrite of the code with all vulnerabilities patched, secure coding best practices applied, and inline comments explaining security measures.
- Present a security summary card with before/after scores (out of 10) and a table comparing issue counts across areas.
Output format — A structured markdown report with five sections: Step 1 — Code Intelligence Scan, Step 2 — Vulnerability Report (with tables and per-vuln blocks), Step 3 — Advisory Flags, Step 4 — Hardened Code (complete code block), Step 5 — Security Summary Card. Use tables and emojis for severity indicators. Tone: technical, precise, actionable.
Guardrails — Do not introduce new vulnerabilities in the fixed code. Do not assume the code runs in a specific environment unless stated. If the code is incomplete, flag missing parts. Do not invent false positives; only report genuine issues.
Example — {{python_code_snippet}} = "import os\n\ndef get_user_input():\n return input('Enter username: ')\n\ndef authenticate(user):\n if user == 'admin':\n return os.environ.get('ADMIN_PASS')\n else:\n return 'user_pass'\n"