Audit JS package.json for sketchy dependencies
Audit a JS/TS project for supply-chain attack indicators (typosquatting, post-install hooks, sketchy deps)
How to review React Server Components (RSC) for correctness, perf, and the use server/use client boundary