Run a repository-grounded security review of a diff or codebase. Discover the project's assets, trust boundaries, authentication and authorization rules, sensitive data, persistence, external integrations, deployment controls, and documented exceptions before reviewing. Use as a security lens during code review, for security-sensitive changes, or for a repository security sweep. Report verified findings and explicitly identify checks that could not be completed.