Follow-up hardening from the security re-verification of the prior fix:
- H6: the parser's wrapper skip-loop skipped a wrapper's option flag but not its
space-separated value, so `nice -n 10 git push`, `sudo -u ci git push`,
`timeout 5 git push` (and wrappers outside the set) returned None and ran
unguarded. Rewrite `_parse_git_tokens` to locate the `git` executable and fail
closed on any unrecognized leading token before a git push, instead of a silent
pass-through.
- H1: `git remote get-url --push` returns only the first of multiple pushurl
entries while `git push` writes to ALL of them, and insteadOf/pushInsteadOf can
rewrite the destination. Use `get-url --push --all` and fail closed unless there
is exactly one push URL and no URL rewrite is configured.
Adds tests for valued-wrapper-option pushes, multiple push URLs, and URL rewrites.
Claude-Session: https://claude.ai/code/session_01GxSndB7VoGQyeS196eUr5E