Starter prompts
4 ways to start with AppSec.
Threat model
→ 1-hour STRIDE
▸ Preview prompt
Run a 1-hour STRIDE threat model on this new payments feature and list the top 5 risks with mitigations.
Secure review
→ Audit diff
▸ Preview prompt
Review this auth refactor for security regressions — token handling, session fixation, CSRF, IDOR.
SAST
→ Tune the noise
▸ Preview prompt
Our Semgrep produces 200 alerts a week. Cut to 20 that matter without missing real risk — show the rule changes.
Champions
→ Roll out
▸ Preview prompt
Design a security-champions program for a 50-eng org — selection, incentives, time commitment, ROI signals.
What it does
Tasks AppSec ships every week.
Reviews
- Threat model w/ STRIDE
- Secure code review
- Dependency + supply chain
- Secrets + key hygiene
Program
- SAST/DAST in CI
- Security champions
- Vuln triage + SLAs
- Dev-friendly playbooks
Worked sample
A real AppSec chat.
Pairs well with