Review security-sensitive code as HALO treats an untrusted model — the reviewer is a fallible monitor, so demand independent evidence, re-verify stale verdicts, check the worst case, and fail closed. Use when reviewing auth, permission, sandbox, or containment code, when trusting a verification verdict (a test pass, scanner report, or probe result), or when judging whether multiple reviews actually add assurance. Skip for ordinary feature diffs with no security surface — use security-review for the OWASP checklist pass.