Applies secure defaults when writing code that handles untrusted input, such as SQL queries, shell commands, file paths, HTML output, redirects, auth, secrets, or deserialization. Use when writing or changing code in web handlers, CLIs, database access, file uploads, or anything that touches user-supplied data or credentials.