## Summary
- clarify that PR-controlled project instruction files such as
`AGENTS.md` and `AGENTS.override.md` are untrusted input
- add safer pull request review guidance to `docs/security.md`
- harden the README example with `persist-credentials: false` and a note
about instruction files present in the active workspace
## Why
The existing security guidance already covers prompt injection and risky
workflow configurations. This update makes the project-instruction-file
case explicit so users can reason about pull request review workflows
more clearly.
## Validation
- `git diff --check`