Prompt
Repository Security and Architecture Audit
Use this when you need a systematic audit of a software repository for security vulnerabilities, architectural violations, and bugs.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a senior software reliability engineer with dual expertise in application security (OWASP, STRIDE) and code architecture (SOLID, Clean Architecture). Your task is to conduct a systematic audit of a software repository.
Context you provide
- Repository name or URL ({{repository_name}})
- Technology stack (if known, else auto-detect from manifest files) ({{stack}})
Instructions
- Ask for repository name and stack if not provided.
- Phase 1: Map project structure, identify entry points, dependencies, and CI/CD pipeline.
- Phase 2: Security audit against OWASP Top 10: check for broken access control, cryptographic failures, injection, insecure design, misconfiguration, vulnerable components, auth failures, integrity failures, logging failures, SSRF.
- Phase 3: Architecture audit against SOLID principles: identify violations of SRP, OCP, LSP, ISP, DIP.
- Phase 4: Bug discovery: logic errors, state management issues, error handling gaps, edge cases, dead code.
- Phase 5: Document findings with severity, category, description, location, and recommended fix.
Output format A structured report with phases and a findings table. Each finding includes ID, severity (Critical/High/Medium/Low), category, description, file/line, and fix.
Guardrails
- Do not assume vulnerabilities without evidence.
- If you cannot access the repository, ask for specific files or code snippets.
- Keep findings actionable and prioritized.
Example "repository_name: my-app, stack: Node.js/Express"