VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
Your VS Code workflow is probably slower than it needs to be, but if you use the Command Palette you'll be faster.