TechnicalCollectible prompt
Security review for an app built with AI tools
Act as a security reviewer for AI-built apps. Review my {{tech_stack}} app, which stores {{data_to_store}}, with these roles: {{user_roles}}. Read the code, database policies and server functions first.
Check for the mistakes AI builders make most:
1. Tables with row-level security off, or rules letting any signed-in user read or change every row
2. Rules letting users change a row's owner, their own role or an admin flag
3. Admin pages protected only by hiding links
4. Admin database, AI or payment keys in frontend code, env files or git history
5. Server functions that skip auth or trust a user ID from the browser
6. Public storage buckets holding private files
7. Views or privileged functions that bypass access rules
8. Prices, credits or discounts calculated in the browser
9. No rate limits on sign-in, forms and AI endpoints, so anyone could run up my bill
10. Payment webhooks without signature checks
11. Errors that leak queries or stack traces, and packages with known flaws
Return a table: issue, location, a one-sentence misuse scenario, severity and fix. If you have access, fix critical issues one at a time, and list exposed keys to rotate now.
Finish with a test I can run: sign up as two normal users and try to read and change each other's data through the API.
0 saves · 3 viewsnvoka.com/library/nvoka-security-review-for-an-ai-built-appScan to open
Technical
Security review for an app built with AI tools
Catch the holes AI builders often leave: open tables, exposed keys, weak roles and no rate limits.
Curated by Nvoka
3 viewsClaude CodeLovableCursorCodex
Make it yours
Fill in the blanks and change any word. Only your copy changes, never the card.
Fill in the blanks
0 of 3 filledYour prompt
Act as a security reviewer for AI-built apps. Review my {{tech_stack}} app, which stores {{data_to_store}}, with these roles: {{user_roles}}. Read the code, database policies and server functions first.
Check for the mistakes AI builders make most:
1. Tables with row-level security off, or rules letting any signed-in user read or change every row
2. Rules letting users change a row's owner, their own role or an admin flag
3. Admin pages protected only by hiding links
4. Admin database, AI or payment keys in frontend code, env files or git history
5. Server functions that skip auth or trust a user ID from the browser
6. Public storage buckets holding private files
7. Views or privileged functions that bypass access rules
8. Prices, credits or discounts calculated in the browser
9. No rate limits on sign-in, forms and AI endpoints, so anyone could run up my bill
10. Payment webhooks without signature checks
11. Errors that leak queries or stack traces, and packages with known flaws
Return a table: issue, location, a one-sentence misuse scenario, severity and fix. If you have access, fix critical issues one at a time, and list exposed keys to rotate now.
Finish with a test I can run: sign up as two normal users and try to read and change each other's data through the API.