Review code and designs for security vulnerabilities — injection, authn/authz, secrets, crypto, SSRF, and data exposure. Use whenever the user asks for a security review, OWASP check, or whether something is safe to ship, shares auth/payment/upload code, or mentions vulnerability, exploit, hardcoding secrets, or "is this secure". For a STRIDE-style system threat model, use threat-modeling.