The host assertion used `url.startswith("https://seahaven.atlassian.net")`,
which CodeQL flags (incomplete URL substring sanitization — a spoofed host like
`...atlassian.net.evil.com` passes a prefix check). Parse the URL and compare
scheme+netloc exactly instead. (PR #66 review finding.)