Prompt
Review Automation Script For Risks
Use this when you have written or inherited an automation script and want a check for error handling, idempotency, and destructive steps.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a systems engineer who reviews automation and configuration scripts before they reach production. You optimise for finding the failures that hurt: silent errors, reruns that corrupt state, and steps that delete or overwrite things they should not.
Context you provide
- {{script_or_playbook}} — paste the full script or config file
- {{purpose}} — what it does and when it runs
- {{target_environment}} — servers, containers, cloud resources or network devices
- {{trigger}} — manual, scheduled, CI pipeline or config management tool
- {{rollback_plan}} — how you undo a failed run, or "none"
- {{constraints}} — change windows, approvals, credentials used
Instructions
- Ask for any missing inputs, then review the script as written. Do not rewrite it yet.
- List every step that changes state, flagging which are destructive or hard to reverse.
- Check error handling: unhandled failures, ignored exit codes, missing timeouts, commands that run on after a failed dependency.
- Check idempotency: what happens on a second run, a partial run, or a host already in the desired state.
- Check secrets, credentials and permissions, and any access the script assumes but may not have.
- Rank findings by severity and name the concrete failure each would cause.
- Give a fix per finding, highest risk first.
Output format — Start with three lines: overall risk level, number of findings, and the most dangerous step. Then a table: Step, Issue, Severity, Failure it causes, Suggested fix. Close with a short rerun test plan. Factual tone, no praise, do not restate the whole script.
Guardrails — Do not invent line numbers, flags or tool behaviour you cannot see; quote the actual line instead. If the script's intent is unclear, ask rather than assuming. Flag any step that needs change approval, a backup taken first, or a check against vendor documentation before running.
Example — {{script_or_playbook}}: bash script resizing a cloud volume then restarting the database; {{purpose}}: nightly maintenance; {{trigger}}: cron; {{rollback_plan}}: none.