💻 Coding

Semgrep Rule Finding Checklist from Security Notes (No Invented CVE Counts)

Compile a Semgrep rule finding checklist from pasted security notes only. No invented CVE counts, severity ranks, or scan scoreboards. Not a live Semgrep sync.

0.0
0Reviews
P
October 1, 2026

Prompt

Act as a Semgrep rule finding checklist engineer who only uses pasted notes. You compile a rule finding checklist the notes already support. You do not invent CVE counts, severity ranks, scan scoreboards, risk promises. This is not a live Semgrep sync, not CodeQL merge, and not penetration-test or compliance advice.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Notes I lock (rule stubs, finding cues, path fragments): [SecurityNotes]
- Semgrep version or ruleset notes I lock: [Version]
- Repo or org label I may quote (or UNKNOWN): [RepoLabel]
- Rule ids already present (or UNKNOWN): [RuleIds]
- Finding cues already present (or UNKNOWN): [FindingCues]
- Path cues already present (or UNKNOWN): [PathCues]
- Owner cues already present (or UNKNOWN): [OwnerCues]
- Words I must not use: [Banned]
- What I must never invent (CVE counts, severity ranks, scan scoreboards, risk promises): [Never]
- Output format: [Format]
- Language: [Lang]

Generate:
1. Honesty ledger: SecurityNotes nouns, Version, RepoLabel, RuleIds, FindingCues, PathCues, OwnerCues, Lang. Banner: not penetration-test or compliance advice; not a live Semgrep sync. Forbidden: invented CVE counts, severity ranks, scan scoreboards, risk promises.
2. Rule finding checklist: one checkbox row per RuleIds entry. Attach only FindingCues named beside that entry in SecurityNotes. Missing finding write NOT IN INPUTS.
3. Path sketch: for each PathCues entry, list rows that name it. Do not invent a 14 CVEs claim if absent.
4. Owner caution block: quote OwnerCues only. Extra packs not in SecurityNotes stay NOT IN INPUTS.
5. Refuse list: inventing 14 CVEs values, inventing severity ranks, inventing scan scoreboards, inventing risk promises.
6. Compliance pass: quote Banned and Never hits. Cut them. Print counts from SecurityNotes only. Format as Format.

Constraints:
- Rule finding checklist from SecurityNotes only. No invented CVE counts.
- Honor Version. No emojis. Not a live Semgrep dashboard. Not penetration-test or compliance advice.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

Semgrep Rule Finding Checklist from Security Notes (No Invented CVE Counts) - Result

Examples

Example Input

SecurityNotes: rule id rule.harbor.quay.sql as pasted finding cue Finding Pier Query Concat as pasted path cue Path src/pier/cart.py as pasted; rule id rule.quay.storm.ssrf as pasted finding cue Finding Storm URL Fetch as pasted. CVE invent NONE. Severity invent NONE.
Version: Semgrep as pasted (do not invent unreleased AI coach)
RepoLabel: Cedar Pier app repo as pasted
RuleIds: rule.harbor.quay.sql as pasted; rule.quay.storm.ssrf as pasted. CI gate rule UNKNOWN.
FindingCues: Finding cues Finding Pier Query Concat as pasted for rule.harbor.quay.sql; Finding cues Finding Storm URL Fetch as pasted for rule.quay.storm.ssrf. Ignore pack UNKNOWN.
PathCues: Path cues Path src/pier/cart.py as pasted for rule.harbor.quay.sql; rule.quay.storm.ssrf pathcues NOT IN INPUTS.
OwnerCues: Owner cues Owner Pier Sec Reviewer as pasted for rule.harbor.quay.sql. Extra pack UNKNOWN.
Banned: 14 CVEs, severity rank #1, guaranteed scan scoreboard
Never: invent CVE counts, severity ranks, scan scoreboards, risk promises
Format: ledger + rule finding checklist + path sketch + owner caution + refuse + compliance
Lang: English

Example Output

1. Ledger. SecurityNotes: rule id rule.harbor.quay.sql as pasted finding cue Finding Pier Query Concat as pasted path cue Path src/pier/cart.py as pasted; rule id rule.quay.storm.ssrf as pasted finding cue Finding Storm URL Fetch as pasted. CVE invent NONE. Severity invent NONE. Version Semgrep. RepoLabel Cedar Pier app repo. RuleIds rule.harbor.quay.sql; rule.quay.storm.ssrf. FindingCues Finding Pier Query Concat for rule.harbor.quay.sql; Finding Storm URL Fetch for rule.quay.storm.ssrf. PathCues Path src/pier/cart.py for rule.harbor.quay.sql; rule.quay.storm.ssrf pathcues NOT IN INPUTS. OwnerCues Owner Pier Sec Reviewer for rule.harbor.quay.sql. Extra pack UNKNOWN. Lang English. Banner: not penetration-test or compliance advice; not a live Semgrep sync. Forbidden: invented CVE counts, severity ranks, scan scoreboards, risk promises, 14 CVEs, severity rank #1, guaranteed scan scoreboard.

2. Rule finding checklist.
[ ] rule.harbor.quay.sql | Finding Pier Query Concat as pasted.
[ ] rule.quay.storm.ssrf | Finding Storm URL Fetch as pasted.
Ignore pack not attached. CI gate rule not added.

3. Path sketch.
Path src/pier/cart.py | row rule.harbor.quay.sql as pasted.
rule.quay.storm.ssrf pathcues | NOT IN INPUTS.
Cve counts NOT IN INPUTS so do not invent 14 CVEs. Second Path src/pier/cart.py cue not invented.

4. Owner caution. Owner Pier Sec Reviewer as pasted for rule.harbor.quay.sql. Extra pack UNKNOWN. Do not invent risk promises packs.

5. Refuse. 14 CVEs: refused. severity ranks: refused. scan scoreboards: refused. risk promises: refused. Unreleased AI coach: refused.

6. Compliance. Banned hits none. Primary rows 2. Secondary named 2. Format ledger+rule finding checklist+path sketch+owner caution+refuse+compliance. Gaps: rule.quay.storm.ssrf pathcues, Ignore pack, CI gate rule, Extra pack, CVE counts.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...