Audit an API's exposure surface — missing rate limits, permissive CORS origins, absent security headers, unenforced HTTPS, unsigned or non-idempotent webhooks, missing pagination caps, and GraphQL depth, complexity, and introspection settings. Use this whenever the user asks about rate limiting, CORS errors or configuration, security headers, API abuse, webhook security, GraphQL hardening, or wants their API or backend reviewed before launch. Also use it when a project exposes REST or GraphQL endpoints and the user asks generally whether the backend is production-ready or safe to expose publicly.