Fix CodeQL alerts and harden CORS proxy SSRF policy
Takeaway: I'd start by asking it to triage the alerts by severity and propose fix options up front, since going back and forth on 'what would option A entail' for the SSRF fix cost time I could have saved by asking for a menu of mitigations in the first prompt.