Security Review
- Never hardcode credentials, tokens, passwords, or private keys.
- Apply least privilege.
- Validate untrusted input at boundaries.
- Review authentication and authorization separately.
- Check secret handling, logging exposure, injection, and dependency risks.