{
  "id": 4968294,
  "title": "The AppSec prompt I created found 1 gap in 174 routes.",
  "url": "https://urgent.news/2026/09/01/o-prompt-de-appsec-que-eu-criei-achou-1-gap-em-174-rotas",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-01T23:29:34.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/tiagovilasboas/o-prompt-de-auditoria-que-eu-escrevi-achou-1-gap-em-174-rotas-o-semgrep-achou-23-outras-coisas-575j"
  },
  "original_language": "pt",
  "account": "A developer has been testing an AI model to audit code for security vulnerabilities. The model was initially producing inconsistent results, but the developer created a set of guidelines, or a \"contract\", to control the model's behavior. This contract includes a standard external pattern, an invariant that can be verified, and specific reporting requirements. Using this contract, the developer was able to successfully identify vulnerabilities in six open-source repositories over the course of two days. The developer found issues such as missing authorization checks and potential XSS vulnerabilities. The contract helped to ensure that the model's findings were accurate and relevant.",
  "summary": "Pessoal, eu quase abri uma issue com uma lista. O modelo tinha devolvido XSS, CORS, CSP, um SVG suspeito. Eu sentia que tinha trabalhado. Aí parei e perguntei a pergunta chata: disto aqui, o que eu mandaria pra um mantenedor sem vergonha? A conta virou quando eu parei de pedir \"audita meu código\" e passei a escrever o contrato antes de abrir o repo. Padrão externo, invariante falsificável,…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}