💻 Coding
Semgrep Rule Finding Checklist from Security Notes (No Invented CVE Counts)
Compile a Semgrep rule finding checklist from pasted security notes only. No invented CVE counts, severity ranks, or scan scoreboards. Not a live Semgrep sync.
0Reviews
Prompt
Act as a Semgrep rule finding checklist engineer who only uses pasted notes. You compile a rule finding checklist the notes already support. You do not invent CVE counts, severity ranks, scan scoreboards, risk promises. This is not a live Semgrep sync, not CodeQL merge, and not penetration-test or compliance advice. You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs. Inputs: - Notes I lock (rule stubs, finding cues, path fragments): [SecurityNotes] - Semgrep version or ruleset notes I lock: [Version] - Repo or org label I may quote (or UNKNOWN): [RepoLabel] - Rule ids already present (or UNKNOWN): [RuleIds] - Finding cues already present (or UNKNOWN): [FindingCues] - Path cues already present (or UNKNOWN): [PathCues] - Owner cues already present (or UNKNOWN): [OwnerCues] - Words I must not use: [Banned] - What I must never invent (CVE counts, severity ranks, scan scoreboards, risk promises): [Never] - Output format: [Format] - Language: [Lang] Generate: 1. Honesty ledger: SecurityNotes nouns, Version, RepoLabel, RuleIds, FindingCues, PathCues, OwnerCues, Lang. Banner: not penetration-test or compliance advice; not a live Semgrep sync. Forbidden: invented CVE counts, severity ranks, scan scoreboards, risk promises. 2. Rule finding checklist: one checkbox row per RuleIds entry. Attach only FindingCues named beside that entry in SecurityNotes. Missing finding write NOT IN INPUTS. 3. Path sketch: for each PathCues entry, list rows that name it. Do not invent a 14 CVEs claim if absent. 4. Owner caution block: quote OwnerCues only. Extra packs not in SecurityNotes stay NOT IN INPUTS. 5. Refuse list: inventing 14 CVEs values, inventing severity ranks, inventing scan scoreboards, inventing risk promises. 6. Compliance pass: quote Banned and Never hits. Cut them. Print counts from SecurityNotes only. Format as Format. Constraints: - Rule finding checklist from SecurityNotes only. No invented CVE counts. - Honor Version. No emojis. Not a live Semgrep dashboard. Not penetration-test or compliance advice.
Instructions
Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.
Generated Output
This image was generated using the prompt above.

Examples
Example Input
SecurityNotes: rule id rule.harbor.quay.sql as pasted finding cue Finding Pier Query Concat as pasted path cue Path src/pier/cart.py as pasted; rule id rule.quay.storm.ssrf as pasted finding cue Finding Storm URL Fetch as pasted. CVE invent NONE. Severity invent NONE. Version: Semgrep as pasted (do not invent unreleased AI coach) RepoLabel: Cedar Pier app repo as pasted RuleIds: rule.harbor.quay.sql as pasted; rule.quay.storm.ssrf as pasted. CI gate rule UNKNOWN. FindingCues: Finding cues Finding Pier Query Concat as pasted for rule.harbor.quay.sql; Finding cues Finding Storm URL Fetch as pasted for rule.quay.storm.ssrf. Ignore pack UNKNOWN. PathCues: Path cues Path src/pier/cart.py as pasted for rule.harbor.quay.sql; rule.quay.storm.ssrf pathcues NOT IN INPUTS. OwnerCues: Owner cues Owner Pier Sec Reviewer as pasted for rule.harbor.quay.sql. Extra pack UNKNOWN. Banned: 14 CVEs, severity rank #1, guaranteed scan scoreboard Never: invent CVE counts, severity ranks, scan scoreboards, risk promises Format: ledger + rule finding checklist + path sketch + owner caution + refuse + compliance Lang: English
Example Output
1. Ledger. SecurityNotes: rule id rule.harbor.quay.sql as pasted finding cue Finding Pier Query Concat as pasted path cue Path src/pier/cart.py as pasted; rule id rule.quay.storm.ssrf as pasted finding cue Finding Storm URL Fetch as pasted. CVE invent NONE. Severity invent NONE. Version Semgrep. RepoLabel Cedar Pier app repo. RuleIds rule.harbor.quay.sql; rule.quay.storm.ssrf. FindingCues Finding Pier Query Concat for rule.harbor.quay.sql; Finding Storm URL Fetch for rule.quay.storm.ssrf. PathCues Path src/pier/cart.py for rule.harbor.quay.sql; rule.quay.storm.ssrf pathcues NOT IN INPUTS. OwnerCues Owner Pier Sec Reviewer for rule.harbor.quay.sql. Extra pack UNKNOWN. Lang English. Banner: not penetration-test or compliance advice; not a live Semgrep sync. Forbidden: invented CVE counts, severity ranks, scan scoreboards, risk promises, 14 CVEs, severity rank #1, guaranteed scan scoreboard. 2. Rule finding checklist. [ ] rule.harbor.quay.sql | Finding Pier Query Concat as pasted. [ ] rule.quay.storm.ssrf | Finding Storm URL Fetch as pasted. Ignore pack not attached. CI gate rule not added. 3. Path sketch. Path src/pier/cart.py | row rule.harbor.quay.sql as pasted. rule.quay.storm.ssrf pathcues | NOT IN INPUTS. Cve counts NOT IN INPUTS so do not invent 14 CVEs. Second Path src/pier/cart.py cue not invented. 4. Owner caution. Owner Pier Sec Reviewer as pasted for rule.harbor.quay.sql. Extra pack UNKNOWN. Do not invent risk promises packs. 5. Refuse. 14 CVEs: refused. severity ranks: refused. scan scoreboards: refused. risk promises: refused. Unreleased AI coach: refused. 6. Compliance. Banned hits none. Primary rows 2. Secondary named 2. Format ledger+rule finding checklist+path sketch+owner caution+refuse+compliance. Gaps: rule.quay.storm.ssrf pathcues, Ignore pack, CI gate rule, Extra pack, CVE counts. Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.