Well, the public key was known anyway for puzzle #130 and other puzzles of multiples of 5. So, those higher bitcount puzzles are apparently of limits for bots.
Yes, that's correct. Otherwise you could just straight up solve #130 as the public key was available from the beginning.
Most bots can steal from puzzle #67 up to the 75-80ish bits, depending on the rig's capabilities.
Any key that takes less than ~10 minutes to crack is not safe. (~10m avg block time, not always the case).
I personally would only feel safe above 110 bits, just to be sure, as we cannot really know what is out there regarding other people's cracking capabilities.
Anything less then 110 bits I would send through MARA's slipstream.