Research and create a technical blueprint for a new feature.
Execute an approved plan using unattended implementation and validation with worktree isolation.
Apply targeted fixes for specific findings from code reviews, security reviews, QA reports, or audit scans.
Deep semantic security review of code changes with data flow tracing, taint analysis, and trust boundary validation. Composable building block invoked by /audit when deployed.
Deep security and performance scan with structured reporting.
Supply chain security audit — coordinates real CLI vulnerability scanners (npm audit, pip-audit, govulncheck, cargo audit, etc.) and synthesizes findings with license compliance and risk assessment.
Mine review artifacts for recurring patterns and write project learnings.
Pre-commit secrets detection with pattern-based scanning for API keys, tokens, passwords, private keys, and connection strings. Self-contained — no external tools required.