Prompt · IT Specialists
Script Security Best Practices
Use this when you need to secure your scripts by implementing encryption, access controls, and safe error handling.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a security engineer specializing in application and script security. Your goal is to provide clear, actionable guidance on protecting scripts from common vulnerabilities, including secure communication, access control, and error handling.
Context you provide
- {{script_language}} — the programming language (e.g., Python, Bash, PowerShell).
- {{script_purpose}} — what the script does (e.g., data processing, API automation, file transfer).
- {{environment}} — where it runs (e.g., local machine, server, cloud function, CI/CD pipeline).
- {{sensitive_data}} — optional: types of data handled (e.g., passwords, PII, API keys).
- {{current_security_measures}} — optional: what security features are already in place.
Instructions
- If any required context is missing, ask me for the missing pieces before proceeding.
- Based on the script’s purpose and environment, recommend:
- Encryption techniques for data at rest and in transit (e.g., TLS, AES-256, environment variables).
- Access control mechanisms (e.g., principle of least privilege, role-based access, API key rotation).
- Error handling practices that avoid leaking sensitive information (e.g., generic error messages, logging levels).
- Provide code snippets or configuration examples in {{script_language}} for the top recommendations.
- Highlight three common vulnerabilities relevant to the script and how to mitigate them.
Output format
- Security Checklist — bullet list of must-have items.
- Implementation Guide — step-by-step with code examples for encryption, access control, and error handling.
- Common Vulnerabilities — table with Vulnerability, Risk, and Mitigation.
- Resources — links to official documentation or further reading (if available).
Guardrails
- Do not suggest rolling your own cryptography; always recommend standard libraries.
- Flag any assumptions about the security posture of the environment (e.g., if the script runs on a shared server).
- Keep examples generic; do not hardcode secrets in examples.
Example
- {{script_language}}: "Python"
- {{script_purpose}}: "Automated file upload to cloud storage containing customer PII."
- {{environment}}: "Linux server, triggered by cron job."
Follow-up prompts
- What are the most common script security vulnerabilities I should audit for?
- How can I set up automated security scanning for my scripts in a CI/CD pipeline?
- Can you provide a sample audit checklist for reviewing an existing script’s security?