Conduct a read-only security inspection of this repository and its local configuration. Do not modify files, install packages, display secret values, or search outside the authorized workspace. Look for accidentally tracked credentials, sensitive local files, unsafe defaults, overly broad permissions, insecure authentication or session settings, missing input validation, vulnerable dependency declarations, public-cloud exposure, and configuration that differs between development and production. Separate confirmed findings from possible concerns. For every finding, identify the supporting file and location, plausible impact, existing control, recommended correction, and a safe verification test. If a value appears secret, report only its type and location—never its contents. Finish with a prioritized preflight checklist. Wait for Pilot in Command approval before changing anything.