Review the public core before inviting external operators. Acceptance: auth/session behavior, webhook SSRF protection, secret handling, OAuth scopes, inbound spoofing/forgery behavior, rate limits, attachment handling, and security docs are reviewed with explicit follow-ups.
Review the public core before inviting external operators. Acceptance: auth/session behavior, webhook SSRF protection, secret handling, OAuth scopes, inbound spoofing/forgery behavior, rate limits, attachment handling, and security docs are reviewed with explicit follow-ups.