Run a fast secrets and dangerous-code pre-flight scan before committing or pushing code. Trigger when the user says "scan before commit", "check for secrets", "is this safe to push", or whenever you are about to stage, commit, or open a PR with new code.