Specialized prompts for finding OWASP top 10 vulnerabilities in source code.
Sign in to vote
A security-focused prompt pack that provides an LLM with a structured methodology for auditing source code against the OWASP Top 10. Covers injection, broken auth, XSS, IDOR, security misconfiguration, and more. Each vulnerability class has its own prompt variant with targeted examples. Output is structured as a findings report with severity, CWE reference, and remediation guidance.
Each OWASP category is encoded as a separate prompt module with canonical vulnerable and safe code examples. The agent is instructed to look for structural patterns (not just keyword matches) and cite the specific CWE for each finding. The SARIF output format integrates directly with GitHub Advanced Security and other SAST toolchains.