Analyze the current project and propose GitHub Actions workflows for CI and releases tailored to its technology and goal — or, when workflows already exist, refresh the pinned versions of every action and library to the latest available. Interviews the human on the judgement calls (which branching model to support, when CI runs, when a release is cut) until there is a shared understanding, pins every action to a specific commit SHA at its most current version, has those target versions security-assessed by the `action-security-auditor` subagent, and asks for explicit confirmation before writing. Never commits. User-invoked only (`/setup-github-workflow`).