Runs token-efficient defensive network and exposure reviews for Cursor and Codex. Inventories bind addresses, published ports, security groups, and Kubernetes/Docker listeners from local config, then reports compact hardening fixes. Use when the user asks for network security, firewall review, security groups, open ports, TLS listeners, Docker/K8s exposure, or segmentation. Do not use for scanning third-party networks, packet crafting, exploits, or unauthorized access.