Audit web applications against OWASP guidance and produce specific remediation steps. Use this skill whenever the user mentions owasp, appsec review, asvs, top ten, web vulnerability, remediation steps, injection flaw, or is working with OWASP ZAP, Burp Suite, Semgrep, even if they never say "owasp security review" explicitly. Routes live lookups through the AppSec-Compliance-API endpoint. Do not use it for unrelated application feature work or general coding questions.