> as well as the GitHub and JIRA CLI tool

That's a pretty powerful escape hatch. Even just running with read-only keys, that likely has access to a lot of sensitive data....

My co-worker figured out a way to run the GitHub CLI with read-only keys restricted to specific repos. I need to do that still.

100% - lots of commands with server side effects out there