- Prefer GitHub App for bot identity and granular org/repo permissions.
- Lock remote extends with
--allowed-remote-patterns
; default is off. - No external network calls unless configured (providers, HTTP checks, etc.).
- Document where tokens are used; rotate provider keys regularly.