Apply Security First with a security lens.
- Read ../references/analyst.md.
- Read
_first/FIRST.md. Take the In path forsecurity:. If that station is Out, stop and say so. - Read the instance file at that path.
- Read references/spec.md.
- Compare the spec and overlay to the implementation. Label Fact, inference, assumption, unresolved.
- Propose the smallest overlay (or brief) update. Do not invent product facts. Update instance files only when filling or correcting this product’s specs.