Use when the user needs a security-focused review of system architecture — identifying attack surfaces, trust boundaries, auth gaps, data exposure risks, and injection vectors using STRIDE before implementation begins