AI CodingThrive Editorial

30 AI Prompts for Code Review

A good review identifies a concrete risk and a way to prove it. These prompts separate correctness, security and maintainability instead of asking for a generic verdict.

15 min read
Two developers discussing a highlighted code change on a screen.

The short version

  • A good review identifies a concrete risk and a way to prove it. These prompts separate correctness, security and maintainability instead of asking for a generic verdict.
  • Never paste credentials, private customer data or entire proprietary repositories into an unapproved assistant. Run suggested commands and tests in your own environment. A plausible patch is not evidence that the change works.

A good review identifies a concrete risk and a way to prove it. These prompts separate correctness, security and maintainability instead of asking for a generic verdict.

Never paste credentials, private customer data or entire proprietary repositories into an unapproved assistant. Run suggested commands and tests in your own environment. A plausible patch is not evidence that the change works.

How to use this collection

Pick the task closest to your work. Copy the prompt, replace the generic scene or code context with your own facts, and keep the constraints that help you judge the result. Change one variable at a time so you can tell what improved.

The approach follows the GitHub Copilot prompt engineering guide: provide concrete context and inspect the output rather than assuming a polished first pass is correct.

Diagnose prompts

This set focuses on diagnose. Supply your real code and test command before accepting the answer.

1. An authentication change

Help with an authentication change in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

2. A schema migration

Help with a schema migration in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

3. An API pagination update

Help with an API pagination update in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

4. A background queue worker

Help with a background queue worker in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

5. A file upload route

Help with a file upload route in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

6. A form validation change

Help with a form validation change in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

7. A caching layer

Help with a caching layer in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

8. A payment webhook

Help with a payment webhook in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

9. A dependency upgrade

Help with a dependency upgrade in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

10. A client-side state refactor

Help with a client-side state refactor in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then state competing hypotheses, request a minimal reproduction and identify evidence that separates them. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the proposed reproduction before applying a patch.

Two reviewers checking a code change for correctness, security and tests.

Implement prompts

This set focuses on implement. Supply your real code and test command before accepting the answer.

11. An authentication change

Help with an authentication change in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

12. A schema migration

Help with a schema migration in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

13. An API pagination update

Help with an API pagination update in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

14. A background queue worker

Help with a background queue worker in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

15. A file upload route

Help with a file upload route in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

16. A form validation change

Help with a form validation change in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

17. A caching layer

Help with a caching layer in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

18. A payment webhook

Help with a payment webhook in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

19. A dependency upgrade

Help with a dependency upgrade in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

20. A client-side state refactor

Help with a client-side state refactor in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then make the smallest change that satisfies the stated behavior and show a focused diff. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Review the diff for unrelated changes and unintended data access.

Three-step code workflow: brief the work, inspect the result, edit and verify.

Test boundaries prompts

This set focuses on test boundaries. Supply your real code and test command before accepting the answer.

21. An authentication change

Help with an authentication change in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

22. A schema migration

Help with a schema migration in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

23. An API pagination update

Help with an API pagination update in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

24. A background queue worker

Help with a background queue worker in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

25. A file upload route

Help with a file upload route in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

26. A form validation change

Help with a form validation change in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

27. A caching layer

Help with a caching layer in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

28. A payment webhook

Help with a payment webhook in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

29. A dependency upgrade

Help with a dependency upgrade in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

30. A client-side state refactor

Help with a client-side state refactor in my existing codebase. Ask for the relevant file, expected behavior, actual behavior and test command if I have not supplied them. Then add unit or integration cases for empty, invalid and concurrent inputs as appropriate. Preserve public interfaces unless evidence requires a change. Show assumptions, a focused diff and the exact command I should run. Do not invent files, test results or security guarantees.

Review: Run the tests and check that they fail before the fix when feasible.

What to check before you use the result

Never paste credentials, private customer data or entire proprietary repositories into an unapproved assistant. Run suggested commands and tests in your own environment. A plausible patch is not evidence that the change works.

If the output misses the task, shorten the prompt and specify the missing fact or constraint. Keep a record of the version you used so the final asset or code change can be reproduced.

Further reading

Continue with a related guide

Put it into practice

Your next step

Have a question or a correction?

Contact Thrive

Keep reading

More from the journal

All articles