It reads your GitHub, hits an injected instruction, and nominee denies the exfiltration before the tool runs - then waits for your yes to publish, with a token minted at that exact moment.
One real OAuth login. The agent never sees your password or stores a token.