Use GitHub's private vulnerability reporting on this repository: Report a vulnerability (enabled 2026-09-18). Never open a public issue or pull request for a security problem: this repository is public, and its workflows run on every Meridian repository the moment a fix merges, so a public report is a public exploit window.
Include what you can of: the workflow, composite action or script involved;
the event or trigger that reaches it; what an attacker controls (a PR head,
a comment, test output, a manifest field); the write or credential it
reaches; and a run link if you have one. Do not include a live token. A
maintainer acknowledges the report in the advisory thread, confirms or
disputes it against main, and fixes it through a pull request from a
maintainer's machine, since agents running in CI cannot change workflow
files here. Disclosure is coordinated with you in the same thread.
Reusable GitHub Actions workflows that run coding agents (Claude Code, or
OpenAI Codex on request) as a dev agent, a reviewer and two autonomous loops,
plus the composite actions and scripts they share. Meridian repositories and
the public meridianlabs-ai/inspect_ai fork run them through thin stubs
pinned to this repository's main; the meridianlabs-ai/actions repository
builds two more agent workflows on the same composites.
The Claude GitHub App is installed only on the repositories Claude Security
scans, and an org owner keeps it suspended outside scan windows. Nothing in
these workflows acts as claude[bot]: they land as the machine account, and
the scanner only reads. A push, comment, label, review or pull request by
claude[bot] is unexpected; report it as above. What the App could do
during a scan window is in THREAT_MODEL.md.
The trust boundaries, the guarantees and what is by design, not a finding, are in THREAT_MODEL.md.