fix: enforce layered trust boundaries for forge and message automation - #6260
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Separate the four GitHub schedules into external intake and trusted maintenance, with live repository authority checks instead of self-only author comparisons. External issue bodies, edits and comments now pass complete-input screening, tool-free API analysis and validated server actions; trusted maintenance independently screens outside discussions and retains withheld activity for retry.
Reuse the same configurable boundary for email, iMessage and Signal: local-only private text providers, no tools/redirects/fallback or autofixer escalation, strict output contracts, and no private identity context. PR review defaults to tool-free static analysis; unsupported execution profiles and legacy queued tasks fail closed.
Make Abuse Guard setup actionable with required screening by default, passive status, explicit install/repair, current pinned classifier dependencies, verified complete token-window coverage, and per-source provider/model/limit controls. Preserve recognized prompt upgrades and custom prompts across installs.
Closes #6255
Closes #6256
Closes #6257
Closes #6258
Test plan