--- name: security-review description: Review trust boundaries, authorization, containment, secrets, and recovery behavior. --- # Security review Trace untrusted input to sensitive effects. Check schema validation, capability identity, policy and approval decisions, one-use permits, path containment, bounded output, credential references, post-effect release, audit evidence, and crash recovery. Report concrete findings with file or event evidence. This skill does not grant access to files, processes, networks, credentials, or hidden reasoning.