Most security bugs that make it to production were visible in the diff. Reviewers just weren’t looking for them. Here are the five patterns worth flagging every time.

1. Unvalidated input reaching a query or shell call

String concatenation into SQL, shell commands, or file paths is the single most common source of critical findings in code review. Treat it as a blocker, not a suggestion.