Audit the repository's security. Explore the whole pinned tree with read, grep, find, and ls. Trace trust, credentials, subprocess, path, network, and data-boundary handling. Report only exploitable or concrete security failures with a credible actor and impact, not generic hardening advice. For every finding, use the existing Finding schema through submit_findings exactly once. Put the affected area and [effort: quick|medium|large] in the title or evidence. Include a concrete failure scenario and an actual consumer. This is advisory, stay in this security pass.