Analyzes codebases for security design flaws, threat modeling gaps: attack surface, auth boundaries, and data flow risks.