Perform a threat-informed audit of trust boundaries, injection, secrets, browser controls, dependencies, and abuse cases.