GitHub Copilot security scanning arrives in the terminal with /security-review, an experimental pre-commit slash command that uses LLM inference to flag injection flaws, XSS, path traversal, and weak cryptography before code reaches a pull request. High-confidence-only output addresses LLM hallucination risk; air-gapped use supported via BYOK.