Consequence-first scan of your AI-built project: 25 checks that catch the scariest things AI coding tools ship wrong — broken access control (IDOR), unenforced validation, missing security headers, no account deletion, no payment-amount validation. Enough signal to know which Pro audits to run next.