Category
Code & Dev

Review a Project Against OWASP Top 10 (2025)

Audit a project category by category, report only findings tied to specific code, and distinguish code-review checks from checks that require running the project.

By Threads — Published on

Prompt template

Format
Markdown
Inputs
Project (code, document) · Required
Outputs
Security_review_report (markdown, text)
Review the supplied project against all 10 categories below. Check every category in order and do not skip any:

- A01: Access control
- A02: Default settings and configuration
- A03: Software supply chain and third-party dependencies
- A04: Cryptography and secrets
- A05: Injection (SQL, commands, and HTML)
- A06: Insecure design
- A07: Authentication and sessions
- A08: Data and build integrity
- A09: Logging and monitoring
- A10: Error and exception handling

For each category, report exactly one status: “Found,” “Checked—clean,” or “Not applicable—because…”

For every finding, include:
- The file and line number.
- What input an attacker can provide.
- What the attacker can obtain or cause as output.
- The severity and why it matters.
- How to fix it, including code.

Do not report a finding unless you can point to the relevant line of code. Review both client and server code; a restriction in the interface does not protect data. State separately what cannot be verified by reading the code and what requires running the project.

Comments — 0

Related prompts

Browse all prompts