Review APIs, configuration, CLI options, schemas, or developer-facing interfaces for unsafe defaults, ambiguous choices, and misuse-prone design.