Defensive security review of a diff or feature — injection, authz, secrets, input trust, dependency risk — with concrete attack scenarios for each finding. Use before merging anything touching auth, user input, files, network, or money, or when the user says "security check" or "is this safe".