Skip to content

docs: clarify PR-controlled project instructions#101

Open
caseysilver-oai wants to merge 1 commit into
openai:mainfrom
caseysilver-oai:caseysilver/harden-codex-action-pr-review-guidance
Open

docs: clarify PR-controlled project instructions#101
caseysilver-oai wants to merge 1 commit into
openai:mainfrom
caseysilver-oai:caseysilver/harden-codex-action-pr-review-guidance

Conversation

@caseysilver-oai
Copy link
Copy Markdown

Summary

  • clarify that PR-controlled project instruction files such as AGENTS.md and AGENTS.override.md are untrusted input
  • add safer pull request review guidance to docs/security.md
  • harden the README example with persist-credentials: false and a note about instruction files present in the active workspace

Why

The existing security guidance already covers prompt injection and risky workflow configurations. This update makes the project-instruction-file case explicit so users can reason about pull request review workflows more clearly.

Validation

  • git diff --check

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 11, 2026

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@caseysilver-oai caseysilver-oai force-pushed the caseysilver/harden-codex-action-pr-review-guidance branch from d12a525 to 654f13c Compare May 11, 2026 20:06
@caseysilver-oai
Copy link
Copy Markdown
Author

I have read the CLA Document and I hereby sign the CLA

github-actions Bot added a commit that referenced this pull request May 11, 2026
@caseysilver-oai caseysilver-oai marked this pull request as ready for review May 11, 2026 20:14
@caseysilver-oai caseysilver-oai force-pushed the caseysilver/harden-codex-action-pr-review-guidance branch from 654f13c to 5fd91ff Compare May 11, 2026 20:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant