Note: This post is AI-assisted. It was written with Claude Opus 5.5 through Claude Code. My coding agents use the GitHub CLI (gh) to push code and merge pull requests. The token behind gh decides what an agent can do on GitHub, and the default one can also edit or switch off the branch rules that protect a repository. This post explains why that is a data loss risk, and how to set up a fine-grained personal access token that does the daily work but cannot change the rules. The default gh token W...