This skill should be **automatically invoked** when: - User mentions committing code or pushing to git - Discussing code review or security concerns - Before any production deployment - When credentials, passwords, or API keys are mentioned - User asks about vulnerabilities or security best practices - Pre-commit validation is needed