forked from bchanot/claude
`gitflow_delete` now ends with `_gitflow_delete_remote`: after the local copy is gone, the remote tip is read with `ls-remote --exit-code`, checked against develop/main with the same ancestor test, and only then removed with `push origin --delete`. Same contract as the pushes (BDR-095): best effort, warn never fail. No origin, `GITFLOW_NO_PUSH=1` or `gitflow.autopush false` skip it; an unreachable origin or a remote tip holding commits the bases lack keeps the remote branch, loudly. A base is never targeted, by construction and by an explicit guard. The static deny on hand `git push --delete` stays: it matches the Bash tool's command string, the lib is the sanctioned path. Prose (hard_deny, environment), doctrine, gitflow SKILL (table, op, warning row), SETTINGS.md and CHANGELOG updated. T24: 9 checks (finish removes the copy, bases untouched, unmerged remote tip kept, never pushed silent, unreachable origin loud, autopush opt-out). 161/163, the 2 failures are the pre-existing T16a (gitleaks absent on this host).