Skip to content

fix integrity filtering for working tasks #66

Description

@cgwalters

See bootc-dev/bcvk#333

I think for generic "issue to PR" we need to drop integrity filtering by default.

That said...what could be interesting here is having an explicit "triage/plan" step that does only filter to inputs from trusted contributors, and maybe we have the contributor need to repeat the plan?

OTOH honestly, while I like the idea of integrity filtering, the core problem is there's so many other ways to implicitly poison LLM inputs (web searches e.g.) and I think ultimately the best security gate here is a "reviewer" agent.

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/codeTriggers the drafter agentagent/workflow-edits-allowedPre-authorizes agent runs to edit protected files without the request_review gate

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions