sickn33
bc49ceec90
fix(security): harden skill apply and activation flows
...
Restrict auto-apply to trusted review comments so spoofed issue comments
cannot write optimized SKILL.md content into pull request branches.
Reject activation symlinks that escape the source root and add
regression coverage for both security checks.
2026-03-26 13:24:04 +01:00
..
2026-03-26 13:24:04 +01:00
2026-03-06 15:01:38 +01:00
2026-03-21 11:50:16 +01:00
2026-03-06 15:01:38 +01:00
2026-03-26 13:24:04 +01:00
2026-03-21 10:48:00 +01:00
2026-03-20 09:06:45 +01:00
2026-03-06 15:01:38 +01:00
2026-03-19 18:39:12 +01:00
2026-03-06 15:01:38 +01:00
2026-03-21 10:48:00 +01:00
2026-03-21 11:08:57 +01:00
2026-03-21 11:50:16 +01:00
2026-03-18 18:15:49 +01:00
2026-03-06 15:01:38 +01:00
2026-03-06 15:01:38 +01:00
2026-03-21 11:50:16 +01:00
2026-03-21 11:50:16 +01:00
2026-03-15 08:39:22 +01:00
2026-03-21 11:50:16 +01:00
2026-03-06 15:01:38 +01:00
2026-03-06 15:01:38 +01:00
2026-03-20 10:23:34 +01:00
2026-03-06 15:01:38 +01:00
2026-03-13 14:20:49 +01:00
2026-03-19 16:43:55 +01:00
2026-03-06 15:01:38 +01:00
2026-03-21 11:08:57 +01:00
2026-03-06 15:01:38 +01:00
2026-03-06 15:01:38 +01:00
2026-03-20 18:05:56 +01:00
2026-03-13 14:20:49 +01:00
2026-03-23 19:13:30 +01:00
2026-03-20 17:56:13 +01:00
2026-03-06 15:01:38 +01:00
2026-03-20 09:44:34 +01:00
2026-03-15 08:39:22 +01:00
2026-03-21 10:48:00 +01:00
2026-03-18 18:49:15 +01:00
2026-03-18 18:49:15 +01:00
2026-03-21 11:50:16 +01:00
2026-03-21 10:25:34 +01:00
2026-03-06 15:01:38 +01:00
2026-03-21 11:08:57 +01:00
2026-03-06 15:01:38 +01:00
2026-03-06 15:01:38 +01:00