i'm missing something basic here .... what does it actually do? It executes a prompt against a git repository. Fine - but then what? Where does the output go? How does it actually persist whatever the outcome of this prompt is?
Is this assuming you give it git commit permission and it just does that? Or it acts through MCP tools you enable?
We use to do do automated sec audits weekly on the code base and post the result on slack
MCP tools. We're doing some MCP bundling and giving it here, pretty cool stuff.