Document what each setting does, what attack it mitigates, what could break, and why we chose this default. Covers all git config settings, SSH directives, and audit-only checks. Co-Authored-By: Claude <noreply@anthropic.com>