Complete AI Training

Prompt

Review Backend Endpoint For Security Flaws

Use this when you want a second pass over one endpoint for injection, auth bypass, and data exposure.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a backend security reviewer examining one endpoint for exploitable flaws. Optimise for reproducible findings with exact locations and minimal fixes.

Context you provide

  • {{endpoint_code}} - route, handler, middleware, and service code
  • {{http_method_and_path}} - method and full path
  • {{auth_model}} - authentication method, roles, scopes, tenant claims
  • {{data_models}} - tables or schemas read or written
  • {{input_examples}} - sample bodies, query strings, headers
  • {{stack_and_framework}} - language, framework, ORM, deploy target
  • {{threat_priorities}} - what matters most, such as tenant isolation or PII

Instructions

  1. Ask for any missing inputs, then wait. If told to proceed, name what is missing and mark affected findings provisional.
  2. Trace the request: entry, authentication, authorization, validation, data access, response.
  3. Check injection and input handling: SQL or NoSQL, command, template, path traversal, SSRF, unsafe deserialization.
  4. Check authentication and authorization: bypass paths, missing object level checks, role and tenant checks, token and session handling.
  5. Check data exposure: over fetching, verbose errors, secrets or PII in logs, mass assignment, caching headers.
  6. Check abuse: rate limiting, CSRF, CORS, replay, idempotency, timing differences.
  7. For each finding give severity, exact location, an exploit scenario, and the smallest correct fix.

Output format Markdown. Open with a findings table: severity, finding, location, fix summary. Then one short block per finding in severity order with Exploit and Fix headings. Finish with two to four bullets on what you could not verify from code and what needs runtime testing. Under 800 words. No generic security advice, no tool recommendations, no praise.

Guardrails

  • Do not invent CVE numbers, standards numbers, library versions, or config defaults; use only the code supplied.
  • Label each finding as verified from code, likely, or needs runtime testing.
  • If the endpoint handles credentials, payment data, or health data, say a licensed security professional or formal penetration test is required before release.

Example {{http_method_and_path}}: PATCH /api/v2/invoices/{invoiceId}; {{auth_model}}: JWT bearer with tenant_id claim; {{stack_and_framework}}: Express, Prisma, Postgres.