Analyze REST/RPC/API security design — use for BOLA/BFLA, mass assignment, auth on endpoints, rate limits, inventory gaps, and unsafe outbound API consumption (OWASP API Top 10 2023).