Documents the three-incident history, the enforcement layers (inline comments + grep guard + ADR), how to spot the symptom, and the explicit upgrade trigger (act_runner v4 protocol support OR v3 CVE). Cross-references ADR-011 (single-tenant Gitea runner) and #557. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>