Overview
The same agent that designed a system may overlook the assumptions it made while building it. A separate security-review conversation with fresh context can inspect the artifact more independently. The audit should search for secrets, missing ignore rules, suspicious dependencies, unsafe scripts, exposed services, database-policy failures, and other relevant findings. A separate implementation pass can then fix the issues, followed by another review.