Perform an authorized, report-only defensive security posture review of a local repository, configuration set, or desktop host using read-only inspection. Use when the user wants a sanitized hardening report with prioritized findings, validation, rollback, compatibility risks, and coverage gaps, but no remediation. Do not use for penetration testing, exploit development, active incident response, secret recovery, or implementing fixes.