Initial stable release. Audit GitHub Actions workflows locally for permissions, immutable references, injection risks, runner exposure, credential persistence, and secret inheritance. Includes Markdown and JSON reports, file hashes, severity thresholds, and value-free findings.