Skip to main content

In this article

security-review-web

security-review-web
FieldValue
Kindprompt
Source.github/prompts/security/security-review-web.prompt.md
InvocationSlash command /security-review-web
InteractiveYes

What it does​

Run an OWASP Top 10 web vulnerability assessment without codebase profiling

When to use it​

Use this prompt for a focused OWASP Top 10 web application assessment when codebase profiling is unnecessary. Use the general security review when the technology or applicable security framework is uncertain.

How to use it​

Optionally provide the web application scope. The prompt runs the fixed web-assessment path and records evidence and findings for qualified security review; it does not certify the application as secure.

Example usage​

/security-review-web scope=src/web

The prompt assesses the sample web source boundary against the OWASP Top 10 and drafts reviewable findings.