Ethan Ha

Security2 min read

The Security Prompt Checklist I Run Before Every Launch

By Ethan Ha

The weekend-prompts guide has the one-shot version of this. This is the expanded version, broken down by attack surface, for anyone about to put real money or real user data in front of real strangers.

Run each of these as its own pass, not one giant prompt. A model going deep on one surface at a time catches more than one prompt trying to cover everything at once.

Auth

Prompt · copy & paste

Try to get into an account that isn't mine. Look for: signup flows that let you claim someone else's email, password reset flows that leak whether an email exists, session tokens that don't actually expire, and any way to access a page meant for a logged-in user without being logged in. List every path you find, ranked by how bad it is.

Payments

Prompt · copy & paste

Try to get paid access without paying, or pay less than the actual price. Check the checkout flow for client-side price manipulation, coupon logic that can be abused, and any state where a user can flip themselves to "subscribed" without a successful payment actually completing.

Sessions and cookies

Prompt · copy & paste

Look at how sessions and cookies are created, signed, and verified. Can any value be forged or replayed? Can a cookie from one account be reused to access another? Is anything about identity trusted from the client that should be verified server-side instead?

Data access

Prompt · copy & paste

For every place this app reads or writes user data, check whether a user could access, modify, or delete another user's data by changing an ID in a request. This is the single most common real-world vulnerability in apps like this — check it exhaustively, not just on the obvious endpoints.

Rate limiting and abuse

Prompt · copy & paste

What stops someone from hitting this app's expensive endpoints (search, AI calls, email sends) thousands of times in a minute? What's the actual cost to me if someone does that right now?

Run all five before the first real customer, not after. A polite "review my code" pass missed real holes on Insidr that only showed up once the prompt got this specific — full story in How I Built Insidr.

This is the exact security pass behind Insidr — see it live.

Try Insidr →

Brands: partner with me

Keep reading

← Back to Resources