Implement, modify, or review application code that crosses trust boundaries or handles sensitive data using threat modeling, safe input/output handling, least privilege, secret protection, and fail-safe behavior. Apply broadly to security-relevant code; use specialized auth or API skills for deeper domain policy.