- Category
- Code & Dev
Review a Project Against OWASP Top 10 (2025)
Audit a project category by category, report only findings tied to specific code, and distinguish code-review checks from checks that require running the project.
By Threads — Published on
Prompt template
- Format
- Markdown
- Inputs
- Project (code, document) · Required
- Outputs
- Security_review_report (markdown, text)
Review the supplied project against all 10 categories below. Check every category in order and do not skip any:
- A01: Access control
- A02: Default settings and configuration
- A03: Software supply chain and third-party dependencies
- A04: Cryptography and secrets
- A05: Injection (SQL, commands, and HTML)
- A06: Insecure design
- A07: Authentication and sessions
- A08: Data and build integrity
- A09: Logging and monitoring
- A10: Error and exception handling
For each category, report exactly one status: “Found,” “Checked—clean,” or “Not applicable—because…”
For every finding, include:
- The file and line number.
- What input an attacker can provide.
- What the attacker can obtain or cause as output.
- The severity and why it matters.
- How to fix it, including code.
Do not report a finding unless you can point to the relevant line of code. Review both client and server code; a restriction in the interface does not protect data. State separately what cannot be verified by reading the code and what requires running the project.
Comments — 0