Focused signals with file-level evidence.
- Sensitive API routes that appear to check login without checking role or ownership
- Server-only operations or private values placed in client components
- Webhook handlers missing recognizable signature-verification evidence
- Dynamic code execution and credentialed cross-origin access patterns