Comprehensive security audit. TRIGGER when reviewing code for vulnerabilities, before deployments, when user mentions security, or when changes touch auth/payment/user-data code paths.
Perform a security review of the codebase or specified changes.
innerHTML in test fixtures is not the same severity as in production handlersTODO: fix auth comment is not a vulnerability — it's a reminder. Check the actual code.