Prompt library

Cybersecurity prompts

Defensive security prompts: threat models for a design, secure code review, and incident timelines from logs.

  • threat modeling
  • stride
  • secure design
100/100 · 174 tokens

Threat model for a design

Builds a STRIDE threat model from a system description, with a mitigation for every threat.

Use it when: Reviewing a design before it is built, or documenting the risks of a system you own.

prompt
You are a security engineer threat-modeling a system the reader owns.

## Task
Produce a threat model for the system described below, using the STRIDE categories.

## Requirements
- Identify the trust boundaries before listing threats.
- List at least one threat for each STRIDE category that applies, and say which categories do not apply.
- Tie every threat to a component or data flow named in the description.
- Give one mitigation per threat and rate its priority as high, medium, or low.
- Describe threats at the design level; never include exploit techniques or attack steps.

## Output format
Return markdown with three sections: Trust boundaries (bulleted list), Threats (a table with the columns Category, Component, Threat, Mitigation, and Priority), and Assumptions (bulleted list).

## Input
<system>
{{system}}
</system>

Variables

{{system}}
The components, data flows, users, and where data is stored.

Example input

system: a browser app calls a public API that writes to Postgres; uploads go to object storage; admins sign in with passwords.

Example output

## Trust boundaries
- Internet to API

## Threats
| Category | Component | Threat | Mitigation | Priority |
|---|---|---|---|---|
| Spoofing | Admin sign-in | Stolen passwords grant admin access | Require multi-factor authentication | High |

Illustrative: written to show the expected shape, not generated by a model.

  • secure coding
  • owasp
  • code review
100/100 · 151 tokens

Secure code review

Reviews code for injection, broken access control, and unsafe handling of secrets and input.

Use it when: Reviewing a change that handles user input, authentication, or sensitive data.

prompt
You are an application security engineer reviewing code for vulnerabilities.

## Task
Review the code below for security vulnerabilities.

## Requirements
- Check for injection, missing authorization checks, unsafe deserialization, hard-coded secrets, and unvalidated input.
- Report only vulnerabilities you can point to in the code, quoting the line.
- Name the weakness class for each finding.
- Give the corrected code for every finding.
- Explain the impact in one sentence without writing an exploit.

## Output format
Return a markdown table with the columns Line, Weakness, Impact, and Corrected code, ordered by severity. If there are no findings, return the single line "No vulnerabilities found in the code provided."

## Input
<code>
{{code}}
</code>

Variables

{{code}}
The code to review, with the language named.

Example input

code: a Node route that builds a SQL string with the id from the query string.

Example output

| Line | Weakness | Impact | Corrected code |
|---|---|---|---|
| `db.query('SELECT * FROM users WHERE id = ' + req.query.id)` | SQL injection | A caller can read or change other rows | `db.query('SELECT id, name FROM users WHERE id = $1', [req.query.id])` |

Illustrative: written to show the expected shape, not generated by a model.

Make it yours

Edit the requirements to match your standards, then check the result. Theprompt analyzer re-scores it as you type, theoptimizer removes filler without dropping a requirement, and thesecurity scanner flags secrets and personal data before you send it to a model.

More categories