nhi.sgit.ai / documents / serialised-pr

The Serialised Pull Request Is The Headline: The Workflow That Gives An Agent No Access At All

TypeStrategy brief Versionv0.33.58 Date14 August 2026 AuthorDinis Cruz (project lead) and collaborators LicenceCC BY 4.0 Sourceraw markdown · view on GitHub

Summary

The evidence backbone of this site's thesis, and the workflow that answers it for a whole class of work. The external evidence is severe: one agent held a token scoped to every repository its developer had authorised; a Black Hat disclosure showed an unprivileged issue reaching CI secrets in three vendors' own repositories; the platform capability to mint short-lived scoped tokens is an open feature request. Against that, the serialised pull request: an agent clones a public source with no credential at all, works, and emits a diff a human imports, reviews and merges elsewhere — nothing to steal, nothing to revoke, provenance per commit. Independent security guidance recommends exactly this shape.

Key concepts

Key ideas

On this site

The evidence backbone of the thesis page; rung 5 of the Hope ladder; curated in the collection under compromise and attribution.

Infographic

Slot reserved. The matching LinkedIn infographic has not yet been linked — the request list is on the infographics page (N1 on comms). Once identified it will appear here, pointing back to this document.

Read the document

📄 Original document · v0.33.58 · 14 August 2026 · rendered from the raw markdown (the source of truth)