Threat model

Adversaries, assumptions and controls.

Adversaries ForkReason assumes

  • A repository crafted to look like a copy of another, without being one.
  • A repository crafted to look unrelated while sharing implementation.
  • A repository crafted to instruct the model.
  • A user crafting input to reach the filesystem, the shell, or the database.

Controls

ThreatControl
Command injectionSubprocess argument arrays only, shell=false, fixed binary, validated identifiers.
Path traversalArchive members validated before and after path resolution.
Symlink escapeLinks rejected; os.walk with followlinks=false plus an explicit guard.
Repository executiongit archive of tracked blobs; no working tree, no hooks, no submodule content.
Resource exhaustionExplicit limits on size, file count, depth, evidence count and wall clock.
SSRFNo fetch-arbitrary-URL capability; redirects are not followed.
Prompt injectionDeterministic preprocessing, delimiters, strict parsing, independent validators, fail closed.
Custodial signingNo server key can act for a user.
Forged revisionsChain state is authoritative; the database only indexes it.

Out of scope for V1

  • Private repositories.
  • Non-GitHub hosts.
  • Authenticated repository access of any kind.
  • Legal determination of any kind.
Threat model · ForkReason