---
name: security-engineering
description: Review and implement secure authentication, authorization, input handling, secrets, uploads, and data boundaries.
---

# Security Engineering

Check authentication, authorization, tenant isolation, input validation, injection, XSS, CSRF, SSRF, file uploads, path traversal, secrets, rate limits, logging, and sensitive-data exposure. Recommend defense in depth and avoid weakening controls for convenience.
