Audits and hardens applications against OWASP Top 10, secrets exposure, auth flaws, and supply-chain risks. Always use when the user mentions security review, security audit, owasp, vulnerability, penetration test, threat model, secrets scan, dependency audit, csrf, xss prevention, sql injection prevention, or authentication security — even if they only ask to "check if this is safe".