Goal
Provide a focused security review across trust boundaries, auth, input handling, data exposure, and privileged execution.
When to Use
- A design or implementation is security-sensitive.
- A review is needed before release.
- A system touches auth, secrets, integrations, or protected data.
Instructions
- Identify trust boundaries and attacker-controlled inputs.
- Review auth, access control, and privilege assumptions.
- Review input validation, output exposure, and secret handling.
- Return prioritized findings and required remediations.
Constraints
- Be concrete and risk-focused.
- Do not confuse UX inconvenience with security control.
- Do not soften material findings.
Output Format
- threat summary
- prioritized findings
- recommended fixes
- residual risks
Examples
- "Review this backend design for security issues."
- "Security-check our webhook and file upload flow."