Add security fixtures and tests for malicious or instruction-like repository content.
Cover:
- prompt injection in README files
- malicious instructions in comments
- secret-looking strings
- path traversal
- symlink traversal
- malicious URLs
- private/internal IP URLs
- oversized files
- malformed model output
Repository content should remain untrusted data rather than trusted application instructions.
Add security fixtures and tests for malicious or instruction-like repository content.
Cover:
Repository content should remain untrusted data rather than trusted application instructions.