# Security Hygiene Audit Review authentication, authorization, secrets, input validation, dependency risk and unsafe defaults within a defined application scope. ## Purpose This is a publishable P0 built-in DevRunbook package. It is designed for the `inspect` work mode with default autonomy `diagnose` and risk tier `high`. ## Required context - Scope: Describe the repository, application and deployment boundaries to assess. - Deployment context: Describe trust boundaries, exposure, users, data and runtime environment. ## Completion - Findings include evidence, exploitability context and remediation priority. - The report states that it is not a formal penetration test. - Validation evidence and unresolved limitations are reported honestly. ## Quality status Editorially reviewed and covered by static structure and determinism fixtures. It is not represented as execution-validated or battle-tested until the platform stores corresponding evidence.