Security Review (Implementation)
Review what actually changed, as changed — not the design's intent. A passing backend or frontend implementation does not substitute for this action's own evidence.
Dispatch
One synchronous Agent-tool call, subagent_type: security-reviewer.
Required inputs
- The changed files or documentation of the slice.
Required outputs (all mandatory)
- Applicable security evidence for the changed surface (application-security standards, supply-chain/SBOM evidence where dependencies changed).
- A security residual-risk statement — explicit, even when the list is empty.
Result
Report each required output produced (with its location), the result (pass / pass_with_risks / blocked / failure), and blocking questions as an explicit list (empty list stated explicitly).