Skip to content

docs: clarify PR-controlled project instructions#101

Merged
viyatb-oai merged 1 commit into
openai:mainfrom
caseysilver-oai:caseysilver/harden-codex-action-pr-review-guidance
May 14, 2026
Merged

docs: clarify PR-controlled project instructions#101
viyatb-oai merged 1 commit into
openai:mainfrom
caseysilver-oai:caseysilver/harden-codex-action-pr-review-guidance

Conversation

@caseysilver-oai
Copy link
Copy Markdown
Contributor

Summary

  • clarify that PR-controlled project instruction files such as AGENTS.md and AGENTS.override.md are untrusted input
  • add safer pull request review guidance to docs/security.md
  • harden the README example with persist-credentials: false and a note about instruction files present in the active workspace

Why

The existing security guidance already covers prompt injection and risky workflow configurations. This update makes the project-instruction-file case explicit so users can reason about pull request review workflows more clearly.

Validation

  • git diff --check

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 11, 2026

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@caseysilver-oai caseysilver-oai force-pushed the caseysilver/harden-codex-action-pr-review-guidance branch from d12a525 to 654f13c Compare May 11, 2026 20:06
@caseysilver-oai
Copy link
Copy Markdown
Contributor Author

I have read the CLA Document and I hereby sign the CLA

github-actions Bot added a commit that referenced this pull request May 11, 2026
@caseysilver-oai caseysilver-oai marked this pull request as ready for review May 11, 2026 20:14
@caseysilver-oai caseysilver-oai force-pushed the caseysilver/harden-codex-action-pr-review-guidance branch from 654f13c to 5fd91ff Compare May 11, 2026 20:27
@viyatb-oai viyatb-oai self-requested a review May 14, 2026 21:50
@viyatb-oai viyatb-oai merged commit 9cdb6f3 into openai:main May 14, 2026
2 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators May 14, 2026
@caseysilver-oai caseysilver-oai deleted the caseysilver/harden-codex-action-pr-review-guidance branch May 14, 2026 21:53
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants