The third-party mingw setup action fails on current windows-latest
images, which already ship MinGW gcc. Verify gcc is present and fall
back to Chocolatey only if it is missing.
Fix drift found in review: workspace creation, web_fetch timeout, exec.cwd
is not confined, starter prompt location, config loading is not a pure
function, Go version wording, go install produces an unstamped version,
releases are bare binaries. Security doc: deny runs before any parsing,
quoted command words are matched, sh -c wrappers remain an accepted
bypass, child env scrubbing. CI adds a CGO-free test leg and a tidy check.
Continuous integration workflow runs Go tests, lint, and build checks on pull requests and pushes. Release workflow creates versioned binaries for Linux, macOS, and Windows on tagged commits.