Observed
Found in review of #786 (#780) on 2026-09-14. The composite GitHub Action ran python -m pip install "agents-shipgate==${SHIPGATE_VERSION}" with the PR checkout as the working directory; python -m puts the current directory first on sys.path, so a pip/__main__.py added by the change executed before the engine was installed (reproduced with the published 1.0.0 venv). #786 fixes the Action with python -P; this issue covers the same pattern in the other recipes, which #786 deliberately does not change.
On main (45d6ca7a) the same command runs from the repository checkout in:
examples/gitlab-ci/01-advisory.yml, 02-strict-with-baseline.yml, 03-sarif-or-artifact.yml, 04-multi-config-workspace.yml (python -m pip install "agents-shipgate==1.0.0")
examples/circleci/01-advisory.yml … 04-multi-config-workspace.yml (same)
docs/integrations.md GitLab, CircleCI and Jenkins snippets (python -m pip install --pre "agents-shipgate==1.0.0", sh 'python -m pip install agents-shipgate')
Not reproduced on those CI systems; the mechanism is the Python start-up behaviour already reproduced for the Action.
Why it matters — and its limit
A change can replace pip (or later shadow agents_shipgate in any python -m/python - step run from the checkout) and forge the review output. The practical reach is narrower than the Action's: on GitLab and CircleCI the pipeline definition itself usually comes from the proposed change, so an untrusted contributor can often edit the job directly. The exposure matters where the configuration is trusted but the checkout is not (protected/parent pipelines, pipeline-from-default-branch setups, Jenkins shared libraries). The recipes should not add a code-execution path the maintainer did not choose.
Proposed
Use python -P -m pip install … (Python ≥ 3.11; the CLI requires 3.12) or pipx/uv tool from a neutral working directory in every non-GitHub recipe and integration snippet, and say in docs/integrations.md which file must come from a trusted source. Keep the pinned versions and the existing pin-sweep tests.
Acceptance
Sequencing
P2 under #778's reliability reserve; not a prerequisite for the advisory pilot, which uses the local CLI or the GitHub Action. Related #780, #786.
Observed
Found in review of #786 (#780) on 2026-09-14. The composite GitHub Action ran
python -m pip install "agents-shipgate==${SHIPGATE_VERSION}"with the PR checkout as the working directory;python -mputs the current directory first onsys.path, so apip/__main__.pyadded by the change executed before the engine was installed (reproduced with the published1.0.0venv). #786 fixes the Action withpython -P; this issue covers the same pattern in the other recipes, which #786 deliberately does not change.On
main(45d6ca7a) the same command runs from the repository checkout in:examples/gitlab-ci/01-advisory.yml,02-strict-with-baseline.yml,03-sarif-or-artifact.yml,04-multi-config-workspace.yml(python -m pip install "agents-shipgate==1.0.0")examples/circleci/01-advisory.yml…04-multi-config-workspace.yml(same)docs/integrations.mdGitLab, CircleCI and Jenkins snippets (python -m pip install --pre "agents-shipgate==1.0.0",sh 'python -m pip install agents-shipgate')Not reproduced on those CI systems; the mechanism is the Python start-up behaviour already reproduced for the Action.
Why it matters — and its limit
A change can replace
pip(or later shadowagents_shipgatein anypython -m/python -step run from the checkout) and forge the review output. The practical reach is narrower than the Action's: on GitLab and CircleCI the pipeline definition itself usually comes from the proposed change, so an untrusted contributor can often edit the job directly. The exposure matters where the configuration is trusted but the checkout is not (protected/parent pipelines, pipeline-from-default-branch setups, Jenkins shared libraries). The recipes should not add a code-execution path the maintainer did not choose.Proposed
Use
python -P -m pip install …(Python ≥ 3.11; the CLI requires 3.12) orpipx/uv toolfrom a neutral working directory in every non-GitHub recipe and integration snippet, and say indocs/integrations.mdwhich file must come from a trusted source. Keep the pinned versions and the existing pin-sweep tests.Acceptance
-Por an equivalent neutral cwd).python -m pip/python -without-Pin a checkout directory (mirroring the static rule Add a host-only advisory PR recipe with no manifest or baseline (#780) #786 adds foraction.yml).Sequencing
P2 under #778's reliability reserve; not a prerequisite for the advisory pilot, which uses the local CLI or the GitHub Action. Related #780, #786.