security-diff-scan
vmain
Use when the user asks for a security review of a pull request, commit, branch diff, working-tree patch, or other Git-backed change set.
vmain
Use for a standard, single-pass security audit of an entire repository or a scoped path, package folder, or submodule with no diff to review. This is the default repository scan. Do not use for PR/commit/branch/working-tree diffs, or for deep, multi-pass, or variance-reducing scans.
vmain
Kubernetes security: RBAC, PodSecurity, network policies.