A. Security & Data Safety · Prompt 2
Test Data & Seed Cleanup
Get the free PDFWhy it matters
A demo admin, a weak password, or an OTP bypass left in the login path can ship as a back door. Placeholder copy can ship as if it were real.
Modeled on
The staging-to-production data checks release teams run before cutover.
How to run this prompt
- Switch to a mode that does not edit files. In Cursor that is Ask or Plan. In Claude Code that is Plan mode.
- Paste the audit prompt. Wait for the report. It must stop and ask which IDs to fix.
- Read the report. Keep the IDs you agree with.
- Switch to a mode that can edit. Paste the fix prompt and the IDs you chose.
- Switch back to the read-only mode and paste the same audit prompt again. Confirm those IDs are gone.
- Cursor: audit in Ask mode or Plan mode. Fix in Agent mode.
- Claude Code: audit in Plan mode (Shift+Tab cycles to it). Fix in Normal mode, which can edit.
- Any other tool: audit in Chat, Discuss, or Plan mode, whichever answers without editing files. If the tool has no such mode, the prompt itself forbids edits. Fix in the mode that is allowed to edit files.
The audit prompt
MODE: AUDIT ONLY. Do not create, edit, or delete any file. Do not run commands
that change anything: no installs, migrations, git commits, deploys, or "--fix" flags.
If your tool has an Ask, Plan, Chat, or Discuss mode, use it for this prompt.
Before you start:
- Tell me the stack you detect (framework, language, database, auth, hosting,
payment provider) and which folders you will review.
- If a check below does not apply to this stack, write "Not applicable" and why.
- If you can run read-only commands, run the ones listed. If you cannot, list them
so I can run them and paste the output.
Test Data & Seed Cleanup: what to check
Find everything that exists only for development, and say whether it can still run in production. Do not delete anything in this pass.
1. List every seed script, fixture, mock-data file, and "create default user" routine. Show the file and how it is invoked (npm script, app startup, migration, CI job). Flag any path that runs when the app boots in production.
2. Find demo accounts in code, seed files, and schema comments: admin@test.com, test@example.com, demo users, and passwords such as password, 123456, or admin. Note any with an elevated role.
3. Find placeholder copy shown in the UI: lorem ipsum, "Test User", fake prices, sample products, stock photos named as placeholders, TODO copy, and dummy phone numbers or emails.
4. Find test-mode payment keys, sandbox API hosts, and staging webhook URLs that are selected by a hardcoded branch instead of an environment check.
5. Find bypass switches: skip OTP, skip payment, skip auth, a magic code, or a feature flag that defaults to on. Say whether the default is off in production.
6. Find routes or pages named test, debug, seed, or preview that are still registered in the production router.
7. Say how you would confirm the production database is a separate instance and was not loaded from a dev dump. If you cannot see the host, mark it Needs manual check.
8. Return two lists: safe to remove, and needs my decision before anyone deletes it.
Evidence rules:
- Every finding cites a file path and line number, or the exact command output used.
- Mark each finding Confirmed (seen in the code) or Needs manual check (depends on
something outside the repo, such as a dashboard setting or production data).
- Never print a full secret. Show the first 4 characters and the location only.
- If you are not sure, say so. Do not invent files, settings, or results.
Severity: Critical = exploitable now, or leaks real data or money. High = serious
with little effort. Medium = weakens defenses or needs a second bug. Low = hygiene.
Report:
- Summary: count of findings by severity.
- Table: ID | Severity | Confirmed? | Finding | Evidence | Why it matters | Suggested fix | Effort
(IDs for this prompt use the prefix P02, for example P02-1, P02-2.)
- Checked and fine: what you verified is already OK.
- Could not check: what I need to look at myself, and where.
Then stop. Do not fix anything. Ask me which IDs I want fixed.