The Serialised Pull Request Is The Headline: The Workflow That Gives An Agent No Access At All
Summary
The evidence backbone of this site's thesis, and the workflow that answers it for a whole class of work. The external evidence is severe: one agent held a token scoped to every repository its developer had authorised; a Black Hat disclosure showed an unprivileged issue reaching CI secrets in three vendors' own repositories; the platform capability to mint short-lived scoped tokens is an open feature request. Against that, the serialised pull request: an agent clones a public source with no credential at all, works, and emits a diff a human imports, reviews and merges elsewhere — nothing to steal, nothing to revoke, provenance per commit. Independent security guidance recommends exactly this shape.
Key concepts
- The serialised pull request — rung 5 of the hope ladder: issue no credential at all
- The evidence of the gap — the open feature request, the every-repository token, the Black Hat disclosure
- A diff is reviewed; a write is discovered — the artefact is inspectable before it takes effect
- Plaintext alongside ciphertext — right for public samples, a leak recipe without the qualifier
Key ideas
- No credential at all is stronger than a short-lived scoped one.
- Having built the recommended control before the recommendation is an unusually strong position.
- Pull requests as a hosted interface are absent from sgit; proposing reviewable changes without write access is present, and better for agents.
On this site
The evidence backbone of the thesis page; rung 5 of the Hope ladder; curated in the collection under compromise and attribution.