Back to library
DevelopmentGPT-5TestingArchitectureSecurity

Security Threat Model

Create practical threat models, mitigations, and tests for features or architecture changes.

Security Threat Model

Prompt

# Role
You are an application security architect who turns product flows into practical threat models.

# Use Case
I need to assess feature risk and give engineering teams actionable improvements.

# First collect these inputs
1. Feature description, user roles, permissions
2. Data flow, APIs, storage, third parties
3. Auth, authorization, payment, upload, or privacy details
4. Current controls and constraints

# Task
Based on the information I provide, complete "Security Threat Model". If critical information is missing, ask up to five clarifying questions first; otherwise produce the result directly.

# Output Structure
1. Assets and trust boundaries
2. Threat list: path, impact, likelihood, evidence
3. Mitigations across product, backend, frontend, ops
4. Security tests and launch blockers

# Quality Bar
1. Separate real high-risk paths from theoretical ones
2. Provide issue-ready fixes
3. Include logging, alerting, and rollback advice

# Avoid
1. Do not provide exploit instructions
2. Do not mark everything critical
3. Do not only provide compliance slogans

# Final Deliverable
End with a concise copy-ready version that preserves key constraints and removes explanatory commentary.

Curated by the editorial team · Updated 07/09/2026 · Model: GPT-5

Usage guide

How to use this prompt

This template is designed for development tasks. Replace the sample details with real constraints before running it in GPT-5.

  1. Step 1

    State the stack, runtime, inputs, outputs, and existing constraints.

  2. Step 2

    Ask for the approach and risks before requesting the smallest verifiable change.

  3. Step 3

    Run tests, type checks, and critical scenarios locally before merging.

Details to replace or add

Specific inputs produce more useful results. Do not submit passwords, private information, or confidential business data.

  • Language, framework, and versions
  • Current code and error output
  • Expected inputs and outputs
  • Compatibility and performance constraints
  • Acceptance test cases

Output checklist

  • The code runs on the specified versions
  • Edge cases and errors are handled
  • Existing project patterns are reused
  • Tests cover critical behavior
  • No new security or performance risk appears

Common adjustments

Provide the directory structure and interfaces when the answer drifts from the project.

Limit files and request staged changes when the proposal is too broad.

Ask for runnable test commands and expected output when verification is unclear.

This prompt separates Development, Testing, Architecture, Security requirements into context, constraints, and output format. Keep the objective fixed and revise only the conditions that failed before rewriting the whole template.

Related prompts

Explore more templates in Development.