Review security-sensitive code changes before they ship — injection, broken auth, access control, secrets, data exposure — for diffs touching auth, user input, APIs, databases, or credentials. Use before a PR or merge when the change touches security-relevant paths, when adding an endpoint or auth flow, or when handling user input or credentials. Skip for diffs with no security surface (UI-only, docs, refactors with no input or trust-boundary change).