AI Chatbot Account Recovery: Security Audit Checklist for Developers
A developer's guide to designing safe AI chatbot account recovery flows, using the Meta/Instagram breach as a live case study.
- ▸Guide (guide.md) — ~2,800-word narrative covering the four-phase flow model, a technical breakdown of the Meta breach root cause, OWASP LLM Top 10 mapping, and 8 concrete mitigations with pass signals
- ▸Checklist (checklist.md) — Standalone 32-item pass/fail checklist organized by flow phase, with escalation criteria and OWASP reference — designed to run against your codebase in under two hours
- ▸README.md — Product overview, usage guide, and scope boundaries
## goes-well-with
From the same shelf
Agentic AI Security Policy Template Pack
Downloadable Markdown + YAML policy templates giving IT teams the acceptable-use, blast-radius, approval-gate, and logging scaffolding to safely deploy agentic AI coding tools like Claude Code, Codex, and Grok Build.
IT Vendor AI Contract Review Checklist
A structured checklist and scoring rubric for IT managers evaluating vendor AI clauses — data retention, model training rights, liability, and exit terms — before signing SaaS contracts that now bundle AI features by default.
CI/CD Governance Bottleneck Playbook for AI-Augmented Teams
A practical guide and checklist bundle for engineering teams whose human release-approval processes have become the rate-limiting step after AI floods their repos with code.
## not-ready-to-buy
Take the field notes instead
One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.