Highlights
- Scan public GitHub repositories from a structured issue form.
- Get a deterministic security report plus an optional, visibly labeled GitHub Models explanation.
- No separately stored AI API key: the workflow uses its short-lived GITHUB_TOKEN and free rate-limited GitHub Models access.
- Target repositories are read at an immutable commit and never cloned or executed.
- AI input is limited to rule-catalog aggregates; raw issue and workflow content is excluded.
See CHANGELOG.md and docs/issue-bot.md for the complete security model and operational limits.