Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. Use when scoping a new engagement.