What we review
- Prompt injection and untrusted-input boundaries.
- Secrets, permissions, least authority, and approval gates.
- Tool calls and external actions that must fail closed.
- Money, publishing, infrastructure, and other high-authority paths.
- Receipts, auditability, stale truth, rollback, and kill switches.
- AI-generated changes that look correct but are operationally wrong.