bc41b2ed3e
- Extracted `_pat_safe_remote` and rejected HTTP(S) origins with embedded credentials or mismatched host/repo. - Guarded `clone` via `_assert_clone_url_safe` on the caller-supplied `clone_url` (pool has no `origin` yet). - Asserted origin safety before `fetch`, `fetch_ref`, and `fetch_pr_head` inject the PAT header. - Appended POSIX `--` separator in `omp_local` so prompts starting with `-` aren't parsed as flags. - Added proxy tests covering attacker-origin fetch rejection and unsafe `clone_url` refusal. Co-authored-by: can1357 <me@can.ac>