v0.14.0 — recipe reads GITHUB_TOKEN from PAT file
Recipe-only (package == 0.12.0). The web pass reads $GITHUB_TOKEN from ~/.config/github_token_ro (override DARNLINK_GATE_TOKEN_FILE) when unset, so 'web' works on repos with private cross-repo destinations from a git hook. PR #26.