- Remove pull_request_review trigger - Add trust-check job to validate PR authors before running CI - Create run-ci.yml workflow for maintainer approval via label - Use workflow run timestamp to prevent backdating attacks - Add per_page and in-progress checks for robustness