Harden APP-LAYER code — mobile, web, and third-party/payment integrations — against attack. Covers input validation, auth and sessions, secret handling, untrusted data (including LLM output), and SSRF. Trigger when building anything that takes untrusted input, manages sessions, or talks to external services. For database-layer concerns (RLS, views, triggers, SQL), use [[supabase-security-review]] instead.