ChatGPT Prompt to Review Code for Bugs, Style, and Security Issues
This code review prompt turns ChatGPT, Claude, or Gemini into a thorough reviewer that checks a diff or file for bugs, style problems, and security issues before it reaches a human reviewer or gets merged. It's built for developers, tech leads, and teams who want a consistent first pass on pull requests, especially when review bandwidth is tight or a change touches unfamiliar code.
Instead of a vague "check my code" request, the prompt sets explicit review categories (correctness, security, readability, performance, test coverage) and asks the model to cite specific line numbers or code snippets for each finding, rather than giving general praise or vague warnings. This makes the output something a developer can act on directly, and it keeps the model from skipping categories it finds less interesting.
Because review quality depends heavily on how the instructions are structured, running this template through the Prompt Optimizer in Coding mode before using it on a large or unusual codebase can tighten the constraints and catch ambiguity that would otherwise lead to shallow feedback.
Prompt template
Want it sharper? Optimize this prompt with Prompt Optimizer, check it with the Prompt Debugger or shorten it with the Token Optimizer.
Example input
Example output
-
Correctness [Blocking] Line: db.execute(query) Issue: No validation that new_email is a well-formed email address before writing it to the database. Suggested fix: Validate the email format (e.g. with a regex or a validation library) before running the update.
-
Security [Blocking] Line: query = "UPDATE users SET email = '" + new_email + "' WHERE id = " + user_id Issue: SQL injection vulnerability β user_id and new_email are concatenated directly into the query string with no sanitization. Suggested fix: Use parameterized queries, e.g. db.execute("UPDATE users SET email = %s WHERE id = %s", (new_email, user_id)).
[Should-fix] Line: user_id = request.form['user_id'] Issue: No check that the requesting user is authorized to update this specific user_id β any authenticated (or unauthenticated) request could update an arbitrary account. Suggested fix: Verify user_id matches the authenticated session's user before applying the update.
-
Readability [Nitpick] Function: update_email Issue: Function has no docstring explaining what it does or what parameters it expects. Suggested fix: Add a short docstring describing the endpoint's purpose and expected form fields.
-
Performance No issues found β this is a single lightweight update operation.
-
Test coverage [Should-fix] Issue: No tests included for invalid email formats, missing fields, or unauthorized update attempts. Suggested fix: Add tests covering a valid update, an invalid email format, a missing field, and an unauthorized user_id.
Overall verdict: Request changes.
When to use it
- Before opening a pull request, to catch obvious bugs and style issues the author missed
- As a first-pass reviewer on PRs from junior developers or contractors before a senior engineer reviews them
- When reviewing unfamiliar code you inherited, such as a legacy module or a teammate's work while they're out
- When a CI pipeline doesn't run a linter or static analysis tool and you need a quick manual check for common issues
Best practices
- Paste the actual diff or full file contents, not a description of the change, so the model can cite real line numbers
- Tell the model the language, framework, and any style guide you follow (e.g. PEP 8, Airbnb JS) so it doesn't flag non-issues
- Ask for findings ranked by severity (blocking, should-fix, nitpick) so you can triage quickly instead of reading a flat list
- For security-sensitive code (auth, payments, user input handling), ask the model to specifically check for injection, access control, and data exposure risks rather than relying on a generic pass
Common mistakes
- Pasting only the changed lines without surrounding context, which makes it impossible for the model to spot issues caused by how the change interacts with the rest of the function
- Not specifying the language or framework, leading to generic feedback that doesn't account for framework-specific conventions
- Treating the review as final instead of verification β the model can miss issues that depend on runtime behavior or data it can't see
- Asking for a review and a rewrite in the same prompt, which often produces a rewritten version that silently fixes issues instead of explaining them, so you don't learn what was wrong
FAQs
What's the best ChatGPT prompt for reviewing a pull request?
The most effective prompts give the model explicit review categories (correctness, security, readability, performance, test coverage), ask it to cite specific line numbers for each finding, and request a severity label for every issue. A vague "review this code" request tends to produce generic praise instead of actionable feedback, so structure matters more than wording.
Can AI code review catch security vulnerabilities like SQL injection?
Yes, for common patterns like string-concatenated SQL queries, unvalidated user input, or missing authorization checks, a model reviewing the actual code can flag these reliably. It's less reliable for vulnerabilities that depend on how the code behaves at runtime or interacts with infrastructure it can't see, so it should supplement rather than replace a security-focused review or scanning tool.
Should I use ChatGPT or Claude for code review?
Both can perform structured code review well when given the same category-based prompt; the meaningful difference tends to be context window size for reviewing large diffs or multi-file changes rather than which model is "better" at spotting bugs. Test the same prompt on a known problematic snippet in each to see which catches more of your team's common issues.
How do I get consistent code review feedback across different PRs?
Reuse the same structured prompt template for every review rather than writing a new ad hoc request each time, and keep the category list and severity labels identical. This is also what makes AI review output comparable across PRs and easier for a team to standardize on.
Which Cuelara tool can help me strengthen this code review prompt before using it on a large codebase?
Prompt Optimizer β its Coding mode is built to tighten vague or loosely structured instructions into the kind of explicit, category-based prompt that produces specific, line-cited findings instead of generic feedback.