Adds a capability baseline file and a GitHub Actions workflow that
uses Google's capslock tool to detect if any new capabilities (file
access, network, syscalls, etc.) are introduced by code changes.
https://claude.ai/code/session_01HwDXpKevFLhE5EfrR6JrBn