v2.0.2 - security hardening v2
Raw git lockdown (blocks --output/--no-index/--ext-diff/--git-dir/--work-tree/-c/-C and remote/exec flags that could write files, run programs, or escape the repo), recursive audit redaction (nested apply_patch content/edits never hit data/audit.log), and a new security regression suite (npm run test:security) wired into CI. 6/6 security checks + 23/23 functional pass. No breaking changes.