ScreenshotNeo

BlogHow-to

Reverse Engineering Code With ChatGPT

Learn how to use ChatGPT to understand authorized code, trace behavior across files, and verify what the model explains—with practical prompts and runnable examples.

By the ScreenshotNeo team29 September 202610 min read

Reverse Engineering Code With ChatGPT

ChatGPT can help you understand code you own or are authorized to inspect. Give it a focused file, function, or repository context; ask about inputs, outputs, side effects, and dependencies; then verify each explanation against the source and, when behavior matters, with tests or runtime evidence. It can help locate feature logic, map module relationships, trace data flow, and spot documentation gaps. It does not turn a plausible explanation into proof that code ran as described.

“Reverse engineering” here means reasoning from authorized source code to understand how it works. This is different from attempting to discover the source code or internal components of a service whose implementation you cannot inspect. OpenAI’s Services Agreement defines reverse engineering in relation to OpenAI services, algorithms, and systems; that clause should not be generalized into a rule about analyzing unrelated code. Check applicable agreements and laws for your situation.

1. What ChatGPT can help you find

A useful code investigation has a bounded question and evidence you can inspect. For example, ask where a feature is implemented, which modules call it, how data changes on the way through, or what happens when a particular condition is met. OpenAI’s guide on [how OpenAI uses Codex](https://openai.com/index/how-openai-uses-codex/) describes similar code-understanding tasks: locating feature logic, mapping relationships between services or modules, tracing data flow, and identifying architecture patterns or documentation gaps. That guide describes internal use cases; it is not an independent performance study.

Question Useful evidence to provide What to verify
Where is this feature implemented? Search results, likely entry points, relevant files That the cited symbol is actually on the execution path
What does this function do? Function and directly called helpers Inputs, return values, exceptions, mutation, I/O
How does data move between modules? Callers, callees, types, API handlers, storage adapters Every edge in the proposed path and each transformation
Why does behavior differ by configuration? Config declarations, defaults, parsing and use sites Precedence, fallback rules, environment-specific values
Where should I investigate next? Current findings and repository search results That each suggested file or symbol exists and is relevant

ChatGPT’s answer is a working map, not an authority on the repository. Context may be incomplete, a symbol may be renamed or generated, and a behavior may depend on runtime state or an external service not shown in the excerpt.

2. Prepare a useful, authorized code sample

  1. Confirm scope. Work with source you own or have permission to inspect. For a work repository, follow its access, confidentiality, and data-handling rules before sharing code with any external service.
  2. State the goal narrowly. “Trace how a submitted invoice becomes a database record” is more useful than “explain this application.”
  3. Find likely files locally. Use your IDE, language server, or command-line search to locate symbols and their references. Share file paths and focused excerpts, not an unfiltered repository dump.
  4. Include relevant context. Add types, callers, direct callees, configuration defaults, and tests if they affect the question. Note the language/runtime and any version constraints.
  5. Remove secrets and sensitive data. Do not paste credentials, tokens, private keys, production records, or information your organization does not permit you to share. Replace values with clearly labeled placeholders while retaining the shape that matters.

For a concrete function explanation, include the complete function and any helper whose behavior controls its result. A fragment without the import, type, caller, or error handling may invite assumptions. If the relevant code is too large, ask for a search plan first, then provide the specific files discovered through that plan.

3. A repeatable investigation workflow

Step 1: Ask for a bounded explanation

Give the model the question, source excerpt, and constraints. Ask it to separate what the code directly shows from assumptions, and request file paths and line references where the interface or supplied material supports them.

Trace each connection from a concrete symbol or file, then verify every hop in the repository.
Trace each connection from a concrete symbol or file, then verify every hop in the repository.
You are helping me understand code I am authorized to inspect.

Goal: Explain how the application handles POST /invoices.
Repository context: TypeScript service; relevant files follow.

For each conclusion:
- Cite the supplied file path and line number if available.
- Describe inputs, outputs, side effects, errors, and dependencies.
- Separate directly supported facts from assumptions.
- If context is missing, ask for the next file or symbol to inspect.
- Do not claim runtime behavior that cannot be established from this code.

[Paste focused route handler, called service, relevant types, and tests]

If you need to discover the entry point first, ask for a search strategy rather than asking the model to guess from a project description:

Starting from this route name and repository tree, identify likely entry points.
Return search terms and candidate paths only. Explain what evidence would confirm
or rule out each candidate. Do not infer that a file implements the feature
until its contents support that conclusion.

[Paste a limited directory tree and route or feature name]

For behavior that crosses modules, request a path with each hop tied to a symbol or file. Then inspect each reference. Do not accept a diagram that jumps from an HTTP handler to a database result without showing the service, validation, transaction, and persistence code that connect them.

Trace the data flow for an invoice created by this handler.
For each hop, give: source symbol, destination symbol, value passed, and evidence.
Mark uncertain links and tell me which caller/callee or type definition would resolve them.
Also identify mutations, validation, persistence, network calls, and error paths.
Do not fill gaps with a typical framework pattern.

[Paste handler and known references]

A useful map may look like: HTTP route → request validator → invoice service → repository interface → SQL adapter. Treat each arrow as a hypothesis until you confirm the caller, arguments, and implementation in the repository. Interfaces, dependency injection, event queues, callbacks, generated code, and reflection can make a simple text search incomplete.

Step 3: Ask for edge cases and alternative explanations

Once the happy path is mapped, ask what happens for missing fields, malformed input, retries, duplicate requests, timeouts, partial failures, and configuration overrides. Request specific code evidence for each behavior. If an answer says “the operation is atomic,” find the transaction boundary and the storage semantics that establish that claim.

Step 4: Verify in the repository

  • Open every cited path and confirm the symbol and line reference. Line numbers can shift or be hallucinated.
  • Use “Find References,” language-server navigation, or repository search to confirm callers and implementations.
  • Read tests for intended cases, but distinguish test coverage from all possible runtime behavior.
  • Run relevant tests or reproduce behavior in a safe environment when the conclusion matters.
  • Update your map when new evidence contradicts the model’s first explanation.

For screenshots of an authorized web application, a rendered page can help compare what source suggests with what the browser displays. A capture is visual evidence of one browser state, viewport, URL, and moment; it does not establish the full server-side data flow. [ScreenshotNeo](https://screenshotneo.com) is a website screenshot API and MCP server that can capture a URL as an image or PDF. Its capture options include viewport/device selection, full-page capture, element capture, waiting for a selector or network idle, custom cookies and headers, and custom JavaScript. See the [API documentation](https://screenshotneo.com/docs/) for parameter details.

4. Using ChatGPT for defensive security analysis

Keep security work authorized and focused on identifying, preventing, or remediating a security issue. OpenAI says additional automated checks may apply to some cybersecurity requests; a check may delay an answer, and a notice alone does not mean a policy violation was determined. The [OpenAI Help Center guidance](https://help.openai.com/en/articles/12635275-additional-safety-checks-for-biological-and-cybersecurity-requests-in-chatgpt-codex-and-the-api) recommends framing cybersecurity work around a defensive outcome.

For ordinary code review, ask about a defined risk and a specific code path: “Does this handler validate the tenant identifier before loading a record? Show the path and propose a minimal remediation if validation is missing.” Ask for the applicable trust boundary, evidence, assumptions, impact, and a defensive fix. Review any suggested patch yourself, and run appropriate tests and security checks.

OpenAI’s separate [Codex Security](https://help.openai.com/en/articles/20001107-codex-security) workflow is oriented to repository security analysis. Its Help Center description says it builds a codebase-specific threat model, explores vulnerabilities, attempts validation in a sandbox, and proposes fixes for human review. The page describes the feature as a research preview and lists ChatGPT Enterprise, Edu, Business, and Pro users; availability and access terms can change, so check the current page. A sandbox reproduction attempt is evidence to review, not a guarantee that every finding is correct or every vulnerability has been found.

Workflow Best fit Validation Review
Ad hoc code understanding with a coding assistant Locate logic, understand relationships, trace data flow Verify paths and run tests or inspect runtime behavior as needed You confirm conclusions against the repository
Codex Security Repository-focused vulnerability analysis and remediation proposals May attempt isolated sandbox validation Human review of findings and proposed changes

5. Common failure modes and fixes

Symptom Likely cause What to do
It names a file or function that is not present Incomplete context, stale knowledge, or an invented reference Search locally; ask it to use only the supplied tree and excerpts; verify every path
The explanation skips a module Only the entry point was provided, or indirection hides the call Inspect references, interfaces, dependency injection bindings, callbacks, and event handlers; provide the missing link
It describes intended behavior as actual behavior Comments or tests were treated as implementation evidence Inspect executable code and runtime configuration; label comments and tests as intent or coverage
It misses a failure path The excerpt omits exceptions, retries, cleanup, or timeout handling Include those branches and ask specifically about partial failure and side effects
It proposes an invalid fix The patch assumes framework APIs, types, or invariants not shown Ask for a minimal diff tied to existing APIs, then compile, test, and review it
It cannot explain repository-wide behavior The active ChatGPT interface may not have the full repository context Provide a limited tree and relevant files incrementally, or use an appropriate repository-aware workflow; do not assume every interface can ingest an entire codebase
A security question receives extra checks or a delay Some cybersecurity requests can trigger additional automated safeguards State the authorized defensive goal, the code scope, and the remediation intent; follow the applicable product guidance

6. Or skip the browser setup

If your code investigation needs a rendered screenshot, one GET request can capture a URL. This cURL example saves a WebP image:

A screenshot records a rendered browser state; removing overlays can make the page content easier to inspect.
A screenshot records a rendered browser state; removing overlays can make the page content easier to inspect.
curl -G "https://api.screenshotneo.com/v1/shot" \
  -d access_key=YOUR_API_KEY \
  --data-urlencode url=https://stripe.com \
  -o shot.webp

Python:

import requests

r = requests.get(
    "https://api.screenshotneo.com/v1/shot",
    params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"},
    timeout=90,
)
open("shot.webp", "wb").write(r.content)

Node.js:

const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`Screenshot request failed: ${res.status}`);
await Bun.write('shot.webp', res);

Cookie banners, newsletter popups, and chat widgets are removed before the shot. Bot checks, blank pages, and failed loads are never billed; response headers report the page verdict and billing status, and cache hits cost nothing. An MCP server gives AI agents tools to take screenshots, get page information, and capture PDFs. The free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000. Every feature is on every plan. See the [ScreenshotNeo docs](https://screenshotneo.com/docs/) for options and sign up for [1,000 free screenshots a month, with no card](https://screenshotneo.com/account/sign-up/).

7. Performance, reliability, and cost

For code understanding, keep prompts focused: send the entry point and only the dependencies needed to answer the current question. This reduces irrelevant context and makes it easier to audit claims. Split a broad investigation into stages: locate, trace, examine edge cases, verify. Save a compact map of confirmed symbols and unresolved questions so follow-up prompts do not need the entire discussion repeated.

For conclusions that affect a release, security posture, or incident response, use repeatable checks: inspect the cited implementation, run the relevant test suite, and capture runtime behavior in a controlled environment. A model explanation can help choose where to look, but it is not a substitute for execution or an independent security review. Avoid asking for confident answers when the evidence is missing; explicitly request uncertainty and the next evidence needed.

ScreenshotNeo offers a free tier of 1,000 shots per month and paid tiers of $5 for 3,000, $15 for 15,000, $39 for 60,000, $99 for 250,000, and $249 for 1,000,000. Yearly billing gives two months free. Clean screenshots are billed; bot checks/CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing. Choose capture options such as viewport, wait condition, cache TTL, and output format to fit the comparison you need. Check the response’s X-Page-Verdict and X-Billed headers when tracking an individual result. Avoid inferring reliability or speed from a single capture.

8. FAQ

Can ChatGPT explain an unfamiliar codebase?

It can help explain code you provide and context available in the interface. Give it focused files and verify the answer. Do not assume every ChatGPT interface can access or reason over an entire repository automatically.

Can ChatGPT trace what a function does?

Yes, if you supply the function and enough surrounding code to follow its inputs, calls, and side effects. Ask for evidence at each step and check the cited symbols locally.

Does a plausible explanation prove the code behaves that way?

No. Source inspection supports claims about visible code; runtime behavior may depend on configuration, environment, external services, or state. Run tests or reproduce the behavior when it matters.

Is Codex Security the same as asking ChatGPT about code?

No. Codex Security is a distinct repository security workflow with threat modeling, vulnerability exploration, sandboxed validation attempts, and reviewable fix proposals. Check its current availability details in the Help Center.

Practical checklist

  • Confirm you are authorized to inspect and share the code.
  • Ask one bounded question at a time.
  • Provide paths, focused source, relevant types, callers, and tests.
  • Require evidence and a separate list of assumptions.
  • Verify references, trace every link, and run tests or inspect runtime behavior when needed.
  • For security questions, state the defensive goal and review every proposed fix.

Used this way, ChatGPT is a guide through the source: it can suggest where the behavior lives and what to inspect next. You retain the decisive step—checking those suggestions against code and execution.