This project may execute commands from untrusted repositories. Treat target repositories as hostile.
Open a private security advisory or contact the repository owner. Do not open a public issue for exploitable sandbox, secret, or command-execution problems.
- command allowlist
- repository allowlist
- Docker and Daytona runner boundaries
- secret redaction in logs and artifacts
- prompt-injection guidance in docs/threat-model.md
The default local runner is not a security boundary.