Build a growing Do-NOT constraint list from every security issue found in AI-generated code, and include it in future security prompts.
/goal GOAL: Complete Security Do-NOT Constraint List for an application with security-sensitive code paths: Build a growing Do-NOT constraint list from every security issue found in AI-generated code, and include it in future security prompts. CONTEXT: - Before editing, read the nearest AGENTS.md/CLAUDE.md, current issue or PLAN.md, and any failing logs already in the repo. - Inspect auth, input handling, rendering, upload, and boundary tests. - Establish a baseline by running or locating evidence for: `npm audit && pytest -k security`. CONSTRAINTS: - Keep the scope limited to this goal; do not expand into unrelated cleanup. - Do not weaken tests, delete assertions, or mask errors to make verification pass. - Respect the repository's AGENTS.md/CLAUDE.md instructions and existing patterns. - Do not bypass authentication, authorization, validation, or audit checks. - Do not use eval, unsafe HTML injection, shell string concatenation, or string-built SQL. DONE WHEN: - The implementation or documentation directly satisfies: Build a growing Do-NOT constraint list from every security issue found in AI-generated code, and include it in future security prompts. - The verification command or evidence path succeeds: `npm audit && pytest -k security`. - The final diff is scoped to the relevant files and has no unrelated formatting churn. VERIFY: - Run `npm audit && pytest -k security` or the closest repo-local equivalent if the exact command is not available. - Capture before/after evidence for the behavior, metric, report, or artifact involved. - If verification cannot run locally, stop and report the missing dependency instead of guessing success. OUTPUT: - Summarize changed files, key decisions, verification output, and remaining risks. - Include any follow-up that is required for production rollout or human review. STOP RULES: - Pause if secrets, production access, stakeholder decisions, or destructive data operations are required. - Pause after three failed fix attempts on the same symptom and challenge the root-cause hypothesis. - Do not mark the goal complete until the current repository state has been audited against DONE WHEN.
原始来源: Prompt Engineering for Secure Code (Part 7) - Simon Roses
证据摘要: Every security issue you've found in AI-generated code becomes a "Do NOT" for future prompts.; source: Prompt Engineering for Secure Code (Part 7) - Simon Roses; type: third-party-tutorial; verification: npm audit && pytest -k security