CybersecuritySoftware EngineeringReleased 6 Oct 2026
Audit how a project handles authentication and file storage, then recommend proven alternatives where what's there is incomplete. Determines whether login is hand-rolled or built on an established library, checks it against what an auth system must actually do — password hashing, session expiry and revocation, login rate limiting, password reset, email verification, 2FA — and checks whether uploads go to the server filesystem or to object storage with signed URLs. Use this whenever the user asks about their login system, whether to build auth themselves or use a library, which auth provider to pick, where to store user uploads, or asks for a review of their architecture a…