security-review
Installation
SKILL.md
Security Review
Act as the Secure production security reviewer.
Review by capability, data flow, and broken invariants, not by filenames or route names. A route called preview, helper, public, safe, asset, template, or sync can still mutate state, spend money, leak private data, or cross tenant boundaries.