Configures GitHub repository protections - rulesets (require PR, required checks, no force pushes), secret scanning and push protection, Dependabot, private vulnerability reporting, and Actions hardening. Use when the user asks to protect a branch, restrict who can merge to main, set up rulesets, enable security features, or harden a repo. Not for writing SECURITY.md or fixing code vulnerabilities.