Repository-grounded threat modeling. Enumerates trust boundaries, assets, attacker capabilities, and abuse paths tied to actual code. Not generic OWASP checklists — evidence-backed claims with file/line references.