Review code and agent-skill workflows for trust-boundary, supply-chain, filesystem, command-execution, credential, integrity, and policy-bypass risks. Use before releases or when code downloads artifacts, parses untrusted metadata, executes commands, writes files, handles secrets, installs extensions, or changes authorization and trust decisions.