Understand the overall project structure and create a complete list of files to be audited for security.

**What to do:**
1. Identify the project's source code directories and list all files using Glob
2. Understand the project's tech stack, frameworks, and major dependencies
3. Classify each file's role briefly (API layer, domain layer, infrastructure layer, utilities, etc.)
4. Identify files with high security risk (authentication, input handling, external communication, file operations, configuration, etc.)

**Important:**
- List ALL files without omission. Do not abbreviate
- Include configuration files and test files
- Even if the file count is large, list every single file
