Skip to content

Security Review

security-review owns:

Did this change create an unsafe trust, authority, or sensitive-data path?

  • authentication or authorization changes
  • new trust boundaries appear
  • sensitive data is stored, transmitted, or exposed differently
  • user-controlled input reaches a privileged capability
  • a security property or abuse path needs independent review

A security-sensitive subsystem did not change and there is no concrete security question.

asset / authority
↓
trust boundary
↓
attacker-controlled input or capability
↓
possible violation
↓
required security property
↓
evidence / mitigation
Use $security-review on the new admin booking endpoint,
focusing on authorization and cross-tenant data access.

Read the complete security-review instructions.