A. Security & Data Safety · Prompt 5
Input Validation & Injection Defense
Get the free PDFWhy it matters
Form fields, URL parameters, headers, and file names are attacker-controlled. Most injection bugs start with one that was never checked on the server.
Modeled on
OWASP guidance on input validation and injection.
How to run this prompt
- Switch to a mode that does not edit files. In Cursor that is Ask or Plan. In Claude Code that is Plan mode.
- Paste the audit prompt. Wait for the report. It must stop and ask which IDs to fix.
- Read the report. Keep the IDs you agree with.
- Switch to a mode that can edit. Paste the fix prompt and the IDs you chose.
- Switch back to the read-only mode and paste the same audit prompt again. Confirm those IDs are gone.
- Cursor: audit in Ask mode or Plan mode. Fix in Agent mode.
- Claude Code: audit in Plan mode (Shift+Tab cycles to it). Fix in Normal mode, which can edit.
- Any other tool: audit in Chat, Discuss, or Plan mode, whichever answers without editing files. If the tool has no such mode, the prompt itself forbids edits. Fix in the mode that is allowed to edit files.
The audit prompt
MODE: AUDIT ONLY. Do not create, edit, or delete any file. Do not run commands
that change anything: no installs, migrations, git commits, deploys, or "--fix" flags.
If your tool has an Ask, Plan, Chat, or Discuss mode, use it for this prompt.
Before you start:
- Tell me the stack you detect (framework, language, database, auth, hosting,
payment provider) and which folders you will review.
- If a check below does not apply to this stack, write "Not applicable" and why.
- If you can run read-only commands, run the ones listed. If you cannot, list them
so I can run them and paste the output.
Input Validation & Injection Defense: what to check
Review untrusted input everywhere data enters from outside. Client-side checks are a convenience, not the control.
1. List input sources: form fields, JSON bodies, query and path parameters, headers, cookies, file names, webhook payloads, and fields copied from third-party API responses.
2. For each source that changes state or is used in a query, say whether the server checks type, length, format, allowed values, and required fields. Name the file. If the only check is in the browser, mark it High.
3. Find SQL or NoSQL queries built by string concatenation, template strings, or by passing a request object straight into a query operator. Parameterized queries and the ORM's bound API are the safe pattern.
4. Find user input rendered as HTML, passed to dangerouslySetInnerHTML or innerHTML, or placed in a URL or redirect. Say whether it is escaped or sanitized.
5. Check other injection paths: shell commands built from input, file paths that can contain .., template engines, and redirects to a user-supplied URL.
6. Check business numbers: negative quantities, huge numbers, decimals where an integer is required, and dates far in the past or future. Say whether the server rejects them.
7. Say whether validation is one shared schema (for example Zod or a similar library) or a different ad-hoc check in each handler.
8. Do not send exploit payloads at a live server. Describe the input that would prove the bug, and cite the line that would accept it.
Evidence rules:
- Every finding cites a file path and line number, or the exact command output used.
- Mark each finding Confirmed (seen in the code) or Needs manual check (depends on
something outside the repo, such as a dashboard setting or production data).
- Never print a full secret. Show the first 4 characters and the location only.
- If you are not sure, say so. Do not invent files, settings, or results.
Severity: Critical = exploitable now, or leaks real data or money. High = serious
with little effort. Medium = weakens defenses or needs a second bug. Low = hygiene.
Report:
- Summary: count of findings by severity.
- Table: ID | Severity | Confirmed? | Finding | Evidence | Why it matters | Suggested fix | Effort
(IDs for this prompt use the prefix P05, for example P05-1, P05-2.)
- Checked and fine: what you verified is already OK.
- Could not check: what I need to look at myself, and where.
Then stop. Do not fix anything. Ask me which IDs I want fixed.