Ready-to-use AI prompts for code review — written for Software Engineer and easy to paste into ChatGPT, Claude or Gemini.
When you need code review done, these software engineer prompts give you a fill-in-the-blanks starting point covering code, review, pull request. Fill in fields like language, system type, priorities and paste the result into ChatGPT, Claude, or Gemini.
Structured pull request review
You are a senior [language] engineer reviewing a pull request on a [system type]. Our team values [priorities].
Here is the diff:
<diff>
[diff]
</diff>
Review it in this order and stop at what actually matters:
1. Correctness bugs, including edge cases, null/empty inputs, and concurrency issues.
2. Security and data-safety risks.
3. Performance problems that would show up at [expected scale].
4. Readability and convention drift.
Output a markdown table with columns: Severity (blocker / should-fix / nit), File:line, What is wrong, Concrete fix. Then write a two-sentence verdict on whether this should merge. Do not comment on style the linter already enforces, and do not invent problems if the diff is clean.
Review my code before I open the PR
Act as the most thorough reviewer on my team. I am about to submit this [language] change that [what it does]. Context you need: [context].
<code>
[code]
</code>
Before listing anything, restate in one sentence what you believe this code is supposed to do. If that differs from my description, say so first — that mismatch is the most important finding.
Then give me: (a) the three things a reviewer is most likely to reject this for, (b) any test case I am missing, and (c) one simplification that would remove code without changing behavior. For each point, quote the exact lines and show the replacement. Be direct; skip praise.
Security-focused review pass
You are an application security engineer. Review the following [language] code, which handles [data or action] in a [app type] running on [environment].
<code>
[code]
</code>
Walk the untrusted input from where it enters the system to where it is used. For each place it is trusted without validation, report: the input, the sink it reaches, the realistic attack, and the minimal fix in code. Check specifically for injection, broken access control, unsafe deserialization, secret leakage into logs, and missing rate limits.
Format as a numbered list ordered by exploitability. End with 'No issues found in scope' if that is the honest answer, and say what you could not evaluate without seeing more of the codebase.
How to use this prompt
Fill in the blanks. Type your details into each highlighted field of this code review prompt — fields like language, system type, priorities — and it rewrites itself live.
Copy the prompt. Press Copy prompt to put the finished code review prompt on your clipboard.
Paste into your AI model. Paste it into ChatGPT, Claude, Gemini, or any chat LLM to get your code review result.
Review and iterate. Read the response as a software engineer would, then adjust fields like language, system type, priorities and re-run to sharpen it.
Fill-in fields explained
language
Your language.
system type
e.g. high-traffic payments API
priorities
e.g. readability over cleverness, no new dependencies
diff
paste diff
expected scale
Your expected scale.
what it does
Your what it does.
context
surrounding architecture, framework, constraints
code
paste code
data or action
e.g. user-uploaded files, auth tokens
app type
web app / API / CLI
environment
Your environment.
Frequently asked
Which AI models does the Code Review prompt work with?
The Code Review prompts for Software Engineer are plain-text and model-agnostic — paste them into ChatGPT (GPT-4o), Claude, Gemini, Llama, or any other chat model.
How do I customize the Code Review prompt for my own use?
Fill in the 11 labelled fields (language, system type, priorities, …) before copying, or edit the [bracketed] text after you paste.
Are the Code Review prompts for Software Engineer free to use?
Yes. Every Code Review prompt here is free to copy and reuse, including for commercial and client work, with no sign-up.