Analyze path traversal and unsafe file access — use when user input influences file paths, downloads, includes, zip extraction, or static file send APIs (CWE-22 / A01:2021).