Replace overly broad `permissions: read-all` with minimal `contents: read` at workflow level in pr-lint.yml and sync-labels.yml. Job-level permissions already declare specific needs.