The weekend-prompts guide has the one-shot version of this. This is the expanded version, broken down by attack surface, for anyone about to put real money or real user data in front of real strangers.
Run each of these as its own pass, not one giant prompt. A model going deep on one surface at a time catches more than one prompt trying to cover everything at once.
Auth
Try to get into an account that isn't mine. Look for: signup flows that let you claim someone else's email, password reset flows that leak whether an email exists, session tokens that don't actually expire, and any way to access a page meant for a logged-in user without being logged in. List every path you find, ranked by how bad it is.
Payments
Try to get paid access without paying, or pay less than the actual price. Check the checkout flow for client-side price manipulation, coupon logic that can be abused, and any state where a user can flip themselves to "subscribed" without a successful payment actually completing.
Sessions and cookies
Look at how sessions and cookies are created, signed, and verified. Can any value be forged or replayed? Can a cookie from one account be reused to access another? Is anything about identity trusted from the client that should be verified server-side instead?
Data access
For every place this app reads or writes user data, check whether a user could access, modify, or delete another user's data by changing an ID in a request. This is the single most common real-world vulnerability in apps like this — check it exhaustively, not just on the obvious endpoints.
Rate limiting and abuse
What stops someone from hitting this app's expensive endpoints (search, AI calls, email sends) thousands of times in a minute? What's the actual cost to me if someone does that right now?
Run all five before the first real customer, not after. A polite "review my code" pass missed real holes on Insidr that only showed up once the prompt got this specific — full story in How I Built Insidr.
This is the exact security pass behind Insidr — see it live.
Try Insidr →Brands: partner with me
Keep reading
- SecurityThe ChatGPT Privacy Checklist I Actually UseTurn off model training, clean Memory, use Temporary Unpersonalized chats — plus shared links, apps, and what never to paste.
- BuildingHow I Use Claude/ChatGPT to Build a Real SaaS SoloHow I go from a blank page to a live product with AI doing most of the heavy lifting.
- PromptsThe Exact Prompts I Use to Go From Idea to Live Product in a WeekendThe prompts I use to go from a rough idea to something working without spending days going in circles.