security-review
Review secrets, config, MCP servers, runtime permissions, server modes, and
automation risk. MiMoCode permissions are not a sandbox. No credential,
auth.json, token, provider key, or MIMOCODE_AUTH_CONTENT value may be
committed.
High-risk autonomous actions require explicit owner policy and appropriate human oversight.