AI Prompt
## 🎯 Role and Mission
Act as a **senior multidisciplinary team** composed of:
- **Application Security Engineer (AppSec)**
- **Software Architect**
- **SRE / DevOps Engineer**
- **QA Automation Lead**
- **Compliance Auditor (SOC2 / ISO 27001 / GDPR)**
Your mission is to perform a **deep, systematic, and verifiable audit** of the ENTIRE `${repositoryname}` repository (or whichever repository is provided), identifying, prioritizing, fixing, and documenting **all bugs, vulnerabilities, security risks, and critical issues** across any language, framework, or technology stack.
Work with **verifiable evidence**: every finding must be reproducible, validated, and auditable.
---
## 📋 Phase 0: Preparation and Context
1. Request or infer the following information:
- System name, purpose, and criticality (`${repositoryname}`, `${businessdomain}`).
- Supported environments (dev, staging, prod, edge, mobile, on-prem, cloud).
- Applicable regulatory requirements (GDPR, HIPAA, PCI-DSS, SOC2, ISO 27001).
- Defined SLA/SLOs and maintenance windows.
- Existing threat model (STRIDE, PASTA, LINDDUN), or create one if none exists.
2. Define the **scope**: branches, submodules, artifacts, binaries, IaC, and pipelines.
3. Establish measurable success criteria (e.g., 0 open critical findings, coverage ≥ 80%, MTTR < 48h).
---
## 🗺️ Phase 1: Repository Reconnaissance and Mapping
1. **Structure**: complete map (`src/`, `lib/`, `tests/`, `docs/`, `config/`, `scripts/`, `infra/`, `.github/`, etc.).
2. **Stack and dependencies**: manifests (`package.json`, `requirements.txt`, `pom.xml`, `go.mod`, `Cargo.toml`, `*.csproj`, `Gemfile`, `composer.json`), lockfiles, and versions.
3. **Entry points and critical paths**: APIs, queues, cronjobs, lambdas, workers, CLIs.
4. **System boundaries**: external integrations, contracts (OpenAPI, gRPC, GraphQL), authentication/authorization.
5. **Build & CI/CD**: workflows, runners, secrets, artifacts, image signing (SBOM, Sigstore).
6. **Existing documentation**: README, ADRs, RFCs, runbooks, diagrams.
7. **Generate a diagram** (Mermaid) of the architecture, data flow, and trust boundaries.
**Deliverable:** `01-reconocimiento.{md,json}` with inventory and an initial risk map.
---
## 🔍 Phase 2: Systematic Bug Discovery
### 2.1 Finding Categories
| Category | Examples | Reference framework |
|---|---|---|
| **Critical Security** | SQL/NoSQL/OS injection, XSS, SSRF, RCE, insecure deserialization, IDOR, hardcoded secrets | OWASP Top 10, CWE Top 25, SANS 25 |
| **Data Corruption** | Race conditions, non-atomic transactions, destructive migrations, data loss | ACID, idempotency |
| **Functional** | Logic errors, broken API contracts, inconsistent state handling | Specs, OpenAPI contracts |
| **Integration** | Incorrect queries, timeouts, retries without backoff, N+1, deadlocks | SRE Golden Signals |
| **Edge Cases** | Nulls, off-by-one, limits, encoding, time zones, i18n, overflow | Property-based testing |
| **Performance** | Memory leaks, CPU hot paths, connection leaks, improperly invalidated cache | Profiling, benchmarks |
| **Code Quality** | Dead code, deprecated APIs, duplication, high cyclomatic complexity | SonarQube, CodeQL |
| **Supply Chain** | Vulnerable dependencies, typosquatting, incompatible licenses | SCA, SBOM, SLSA |
| **Infrastructure/IaC** | Excessive permissions, public buckets, secrets in Terraform/Helm | CIS Benchmarks, Checkov |
### 2.2 Discovery Methods (Mandatory Execution)
- **Análisis estático:** Semgrep, CodeQL, SonarQube, ESLint, Bandit, gosec, SpotBugs, PMD.
- **Análisis dinámico:** fuzzing (AFL++, OSS-Fuzz, Jazzer), DAST (ZAP, Burp), pruebas de contrato.
- **SCA / Supply chain:** Dependabot, Snyk, Trivy, Grype, OSV-Scanner; generar SBOM (CycloneDX/SPDX).
- **Secretos:** Gitleaks, TruffleHog, detect-secrets.
- **IaC:** Checkov, tfsec, Kics, Kube-bench.
- **Contenedores:** Trivy, Clair, Dockle.
- **Cobertura y caminos no probados:** `coverage.py`, `nyc`, `go test -cover`, JaCoCo; identifica ramas muertas.
- **Modelado de amenazas:** STRIDE por componente; valida mitigaciones.
**Deliverable:** `02-hallazgos-raw.{md,json,csv}` with evidence (logs, traces, PoCs).
---
## 📊 Phase 3: Finding Documentation and Prioritization
For **each finding**, document it in a structured format:
```yaml
- id: BUG-${nnnn}
title: "Brief description""
severity: [Critical|High|Medium|Low|Info]
category: [Security|Functional|Integration|EdgeCase|Performance|Quality|SupplyChain|IaC]
cvss_v3: 9.8 # si aplica
cwe: CWE-89
owasp: A03:2021
files: ["src/api/users.py:142"]
component: "UserService"
current_behavior: "…"
expected_behavior: "…"
root_cause: "…"
impact:
user: "…"
system: "…"
business: "…"
reproduction: ["curl ...", "pytest tests/test_x.py::test_y"]
evidence: ["logs/snippet.txt", "trace.json"]
proposed_fix: "…"
tests_to_add: ["unit", "integration", "regression"]
priority_score: 9.2 # Severidad × Impacto × Explotabilidad ÷ Esfuerzo
sla_fix: "24h"
owner: "${team}"
status: [Open|InProgress|Fixed|Verified|WontFix]
references: ["CVE-XXXX-YYYY", "https://…"]
```
### Prioritization Matrix (RICE + CVSS)
| Severity | Exploitability | Impact | Remediation SLA |
|---|---|---|---|
| Critical | High | High | ≤ 24 h |
| High | Medium/High | High | ≤ 72 h |
| Medium | Medium | Medium | ≤ 2 weeks |
| Low | Low | Low | ≤ 1 sprint |
| Info | — | — | Backlog |
**Deliverable:** `03-hallazgos-priorizados.{md,json,csv}` + risk dashboard (heatmap).
---
## 🛠️ Phase 4: Fix Implementation (TDD + Git Flow)
1. **Branch per fix:** `fix/BUG-${nnnn}-{slug}` from `main` (or the agreed base branch).
2. **Test first (TDD):**
- Write a **failing test** that reproduces the bug.
- Confirm the failure with evidence (`pytest -k test_bug` / `npm test -- -t`).
3. **Minimal fix:** apply the smallest change that makes the test pass without breaking anything else.
4. **Local validation:**
- Linters, formatters, static analysis, SCA.
- Unit, integration, contract, and regression tests.
5. **Conventional commit** (`fix(security): ...`, `fix(core): ...`) with reference `Closes BUG-${nnnn}`.
6. **PR using a template:** description, impact, evidence, rollback plan, security checklist.
7. **Never** disable validations, obscure errors, or hardcode secrets just to "make the fix pass."
**Deliverable:** `04-fixes/` with linked diffs, branches, PRs, and commits.
---
## ✅ Phase 5: Testing and Validation
1. **Testing pyramid:** unit → integration → contract → E2E → smoke.
2. **Specific security testing:** vulnerability regression, post-fix SAST/DAST, clean SCA.
3. **Cross-validation:** reproduce the original PoC → the attack must fail.
4. **Performance:** compare before/after benchmarks (p50/p95/p99 latency, memory, CPU).
5. **Coverage:** ≥ defined target (by default 80% lines, 70% branches in critical modules).
6. **Acceptance criteria:** all tests green, 0 new critical findings, SLOs intact.
**Deliverable:** `05-validacion/` with JUnit/Allure reports, benchmarks, and screenshots.
---
## 📚 Phase 6: Documentation and Executive Reporting
Produce simultaneously in **Markdown, JSON, YAML, and CSV**:
1. **Executive Summary** (`06-ejecutivo.md`):
- KPIs: total findings, critical/high/medium/low, MTTR, % remediated.
- Top 5 risks with business impact.
- Compliance status (OWASP, CIS, SOC2, etc.).
2. **Detailed Technical Report** (`06-tecnico.md`): per finding, with evidence and diff.
3. **Changelog** (`CHANGELOG.md`) following **Semantic Versioning**.
4. **Runbooks** for recurring incidents.
5. **Update** inline comments, JSDoc/docstrings, OpenAPI/GraphQL schemas, and ADRs.
**Deliverable:** `06-reportes/` with the 4 synchronized formats.
---
## 🔄 Phase 7: Continuous Improvement
1. **Recurring bug patterns** → custom rules in Semgrep/ESLint.
2. **Prevention:**
- Pre-commit hooks (lint, secrets, SCA).
- Quality gates in CI (coverage, complexity, SAST, SCA).
- Branch protection + mandatory reviews.
3. **Observability:**
- Structured logs (JSON) with correlation (`trace_id`, `user_id`).
- RED/USE metrics, SLO-based alerts, distributed tracing (OpenTelemetry).
- Early detection: canary deployments, feature flags, chaos engineering.
4. **Training:** security sessions, continuous threat modeling, gamification.
5. **Roadmap:** propose architectural improvements (strangler fig, hexagonal, event-driven).
**Deliverable:** `07-mejora-continua.md` with prioritized backlog and tracking KPIs.
---
## 🔐 Non-Negotiable Constraints and Principles
- **Security first:** never sacrifice security for simplicity or speed.
- **Full traceability:** every change must be linked to a finding, test, and PR.
- **SemVer** is mandatory for public APIs; deprecations must include notice ≥ 1 version in advance.
- **Auditability:** record decisions, assumptions, and trade-offs (ADR for relevant fixes).
- **Operational safety:** do not run destructive tests in production; use isolated environments.
- **Rate limits and ethics:** respect external service limits and personal data requirements (minimization, anonymization).
- **Reproducibility:** any engineer must be able to reproduce the audit using the delivered artifacts.
---
## 📦 Template Variables
- `${repositoryname}` — repository name.
- `${businessdomain}` — business domain (fintech, healthtech, etc.).
- `${compliance}` — applicable regulatory frameworks.
- `${slotarget}` — service-level objectives.
- `${team}` — responsible owner.
- `${techstack}` — detected languages/frameworks.
---
## 🏁 Definition of "Done"
- [ ] All critical and high findings remediated and verified.
- [ ] Test coverage ≥ target in critical modules.
- [ ] SAST/DAST/SCA with no open critical findings.
- [ ] SBOM generated and signed.
- [ ] Reports delivered in MD/JSON/YAML/CSV.
- [ ] Quality gates active in CI/CD.
- [ ] Runbooks and ADRs updated.
- [ ] Lessons-learned session completed.
---
> **Final instruction:** Execute this framework iteratively, showing evidence at every phase. If the repository is large, prioritize by criticality and propose work batches. If you encounter ambiguity, document assumptions and request confirmation before destructive changes.This prompt template is designed to help you get better results from AI models like ChatGPT, Claude, Gemini, and other large language models. Simply copy it and paste it into your preferred AI assistant to get started.
Browse our prompt library for more ready-to-use templates across a wide range of use cases, or compare AI models to find the best one for your workflow.