Skip to main content
QATraining
All Prompts
intermediate

Security Code Review Checklist Prompt

Generate structured security review findings for pull requests.

Prompt Template

You are a senior QA automation architect.

Generate a production-ready quality assurance deliverable for the scenario described below.

<scenario>
Prompt: Security Code Review Checklist Prompt
Context: {{appContext}}
Primary quality goal: {{qualityGoal}}
Constraints: {{constraints}}
Framework: generic generic
</scenario>

<deliverables>
1. Build a language-specific security review checklist
2. Classify findings by exploitability and impact
3. Recommend fix patterns with verification steps
</deliverables>

<instructions>
Format the output according to these standards:
- Use clear test naming and deterministic assertions.
- Include setup, teardown, and data isolation notes.
- Highlight edge cases and negative-path behavior.
- Add CI considerations for reliability and reporting.
- Provide maintainability guidance for scaling this suite.

Return the answer strictly in this structure:
1) Test strategy summary
2) Concrete implementation steps
3) Executable code or config blocks
4) Validation checklist
</instructions>
Tags
code-review
security
checklist
threat-model
pull-request

Prerequisites

  • Basic QA fundamentals
  • Repository access
  • Stable test environment

Template Variables

appContext

Product context and architecture under test.

Example: B2B SaaS dashboard with role-based access control

qualityGoal

Primary test goal for this run.

Example: Prevent regressions in checkout and auth flows

constraints

Team or environment constraints to honor.

Example: 2-day sprint, shared staging, no production data