Ship Security
- Apply
references/security-checklist.mdto the changed files (the checklist IS the gate). - If available, also invoke
/security-reviewfor an Anthropic-maintained diff pass and merge findings. - Go deeper on files matching the project's security scoping globs (auth, payments, rules, migrations, env, deps).
- Emit Block (any CRITICAL/HIGH) / Warning / Approve + findings. Do not push.