Threat model
Adversaries, assumptions and controls.
Adversaries ForkReason assumes
- A repository crafted to look like a copy of another, without being one.
- A repository crafted to look unrelated while sharing implementation.
- A repository crafted to instruct the model.
- A user crafting input to reach the filesystem, the shell, or the database.
Controls
ThreatControl
Command injectionSubprocess argument arrays only, shell=false, fixed binary, validated identifiers.
Path traversalArchive members validated before and after path resolution.
Symlink escapeLinks rejected; os.walk with followlinks=false plus an explicit guard.
Repository executiongit archive of tracked blobs; no working tree, no hooks, no submodule content.
Resource exhaustionExplicit limits on size, file count, depth, evidence count and wall clock.
SSRFNo fetch-arbitrary-URL capability; redirects are not followed.
Prompt injectionDeterministic preprocessing, delimiters, strict parsing, independent validators, fail closed.
Custodial signingNo server key can act for a user.
Forged revisionsChain state is authoritative; the database only indexes it.
Out of scope for V1
- Private repositories.
- Non-GitHub hosts.
- Authenticated repository access of any kind.
- Legal determination of any kind.