Give the model a narrow review contract
Ask for concrete trust boundaries, data flows, dangerous APIs, and missing authorization checks rather than a generic find all vulnerabilities prompt. Supply only the files and dependencies needed, and remove secrets, customer data, and proprietary context that the chosen service is not approved to process.
Require the response to state file, line, precondition, data flow, CWE where applicable, confidence, and evidence still needed. This makes weak guesses visible.