Review and harden a codebase proportionally to a WRITTEN threat model — not to a generic checklist of everything that could ever be insecure. Two failure modes cost equally: under-hardening a real boundary (webhook accepting unsigned payloads) and over-hardening a non-boundary (enterprise auth on a single-user local CLI). The threat model, written first, is what tells them apart.