Perform a repository-wide security scan (codebase scan, not PR diff) and report only medium/high/critical vulnerabilities with concrete exploit paths and code evidence. Use when the user asks for a security review, security audit, threat review, SAST-style scan, or types the /security-scan command.