64e70efdf1
The worker "checkpoint" is commit → push → open its own PR. Push is free over SSH (same user, same keys); the only incremental grant is PR-create, so the daemon injects a repo-scoped gitea token into the worker env — opt-in per profile, never mutating bridged's own environment. - BridgedConfig.Worker: gitTokenEnv/gitHostEnv fields (opt-in; gitHostEnv defaults to GITEA_HOST). Backward-compat 12-arg constructor keeps pre-CB-302 call sites + YAML working. hasGitToken() gates injection. - WorkerService.spawn: inject GITEA_TOKEN (and paired GITEA_HOST) only when the profile grants a token AND the host env resolves one. resolveEnv() tolerates unset var names. - WorkerServiceTest: injection present for a granting profile; absent when not (proving the gate is config, not a missing env var). - .claude/skills/implementer/SKILL.md: worktree-aware playbook — confirm the worktree/ branch, implement, commit (never .mcp.json/wiki), push, open PR via gitea REST with GITEA_TOKEN, hand off the PR URL via bridge_reply. Never merge; workers can't run IDE diagnostics so never claim IDE-clean. Whole-project gate: mvn clean install green, 164 tests, 0 failures.