This commit introduces a comprehensive threat model, and security
triage guide, and operator guidelines based on the code, documentation
and a review of the published GitHub Security Advisories (GHSAs)
Assisted-by: gemini-cli
Assisted-by: Antigravity
Assisted-by: Claude Code (Opus 4.8)
Co-authored-by: Vinayak Goyal <vinayakankugoyal@gmail.com>
Signed-off-by: Samuel Karp <samuelkarp@google.com>