Files
Alem Tuzlak 704cdba704 fix(issue-triage): harden against prompt injection + token exfil
- Wrap untrusted issue title/body/comments in <untrusted_issue_content> +
  system clause instructing the agent to treat them as data, not instructions
  (maintainer gate covers who runs the command, not who authored the issue).
- Sandbox policy flipped to default-deny with a read-only/test allowlist;
  network:deny to cut token exfiltration and direct GitHub-API abuse.
- Token isolation (keep GH_TOKEN out of the agent env) tracked as a pre-merge
  blocker; needs live API validation.
2026-07-02 16:44:28 +02:00
..