FRI, OCTOBER 09, 2026
Independent · In‑Depth · Practitioner‑Tested
Claude AI Coding

Claude Security Review Prompts for Code and Dependencies

Anthropic's OSS Scanner is opt-in and gated on whether a project can keep up with the findings — which leaves most maintainers doing this by hand. These eight prompts run the same kind of review in a Claude session: dependency surface, input handling, secrets, authentication paths and the deployment config that usually turns a medium into a critical. Each one asks for a severity and a fix rather than a list of worries.

⌨️ 8 prompts 🕐 Updated Oct 9, 2026
💡 How to use these prompts: Replace everything in [BRACKETS] with your specific details before sending. Click Copy to copy any prompt to your clipboard instantly.
1
Dependency surface review
Auditing what you actually depend on
Review the dependency manifest I am pasting below. For each direct dependency, tell me: what it is used for in this project, whether it is actively maintained, and whether a lighter alternative exists. Then list any dependency that handles untrusted input, parses a file format, or opens a network connection. Rank that list by how much damage a flaw in it would cause. Give me a severity for each and a specific next action, not a general warning.
2
Untrusted input trace
Finding injection and deserialisation paths
Here is a source file. Trace every path where data enters from outside the process: request bodies, query strings, headers, cookies, uploaded files, environment variables, database rows that originated from users. For each path, tell me where the data is validated, where it is used, and whether any use is unsafe. Where you find a problem, show the exact line and the exact fix. If a path is safe, say so and say why in one sentence.
3
Secrets and configuration audit
Catching the medium that becomes a critical
Scan this code and config for anything that should not be in version control: API keys, connection strings, private keys, tokens, hardcoded passwords, internal hostnames. Also flag any setting that is safe in development and dangerous in production, such as debug flags, permissive CORS, disabled certificate verification, or verbose error pages. For each finding give me the severity, the line, and what the production value should be.
4
Authentication and authorisation paths
Finding the endpoint everyone forgot
Map every route or endpoint in this file to the authentication it requires and the authorisation check it performs. Produce a table with four columns: route, authentication required, authorisation check, and what an unauthenticated caller receives. Then list every route where the authorisation check is missing, weaker than its neighbours, or depends on a value the caller controls. Explain each gap concretely.
5
Adversarial review of a single function
Deep review of critical code
I am pasting one function. Assume an attacker controls every argument and can call it as often as they like. Tell me what they can make it do that I did not intend. Consider unexpected types, extreme values, empty and enormous inputs, concurrent calls, and partial failure leaving state inconsistent. Give me the three most damaging cases with the input that triggers each, and the fix for each.
6
Deployment and network exposure check
The check that catches unpatched services
Here is my deployment configuration. Tell me which services are reachable from the public internet, which are reachable only inside the network, and which I have assumed are internal but have actually exposed. For every service that accepts connections, tell me what authentication sits in front of it. Flag anything that would be a critical finding if it were reachable without authentication.
7
Triage an AI-generated security report
Working through scanner output
I received an automated security report that was generated by a model and not reviewed by a human, so some findings will be wrong and some severities will be inflated. Here it is. For each finding tell me: is this real in my codebase, is the stated severity correct, and what is the actual fix. Sort your answer by real severity and put anything you believe is a false positive at the bottom with a one-line reason.
8
Write the fix and the test together
Closing a finding properly
Here is a confirmed vulnerability and the code around it. Write the fix, and write a test that fails against the current code and passes against the fix. Explain in two sentences why the test actually proves the issue is resolved rather than merely passing. Then tell me whether the same mistake is likely to exist elsewhere in a codebase of this shape, and what to search for to find it.