Skip to content

Security: meridianlabs-ai/agents

SECURITY.md

Security

Reporting a vulnerability

Use GitHub's private vulnerability reporting on this repository: Report a vulnerability (enabled 2026-09-18). Never open a public issue or pull request for a security problem: this repository is public, and its workflows run on every Meridian repository the moment a fix merges, so a public report is a public exploit window.

Include what you can of: the workflow, composite action or script involved; the event or trigger that reaches it; what an attacker controls (a PR head, a comment, test output, a manifest field); the write or credential it reaches; and a run link if you have one. Do not include a live token. A maintainer acknowledges the report in the advisory thread, confirms or disputes it against main, and fixes it through a pull request from a maintainer's machine, since agents running in CI cannot change workflow files here. Disclosure is coordinated with you in the same thread.

What this repository is

Reusable GitHub Actions workflows that run coding agents (Claude Code, or OpenAI Codex on request) as a dev agent, a reviewer and two autonomous loops, plus the composite actions and scripts they share. Meridian repositories and the public meridianlabs-ai/inspect_ai fork run them through thin stubs pinned to this repository's main; the meridianlabs-ai/actions repository builds two more agent workflows on the same composites.

The Claude GitHub App

The Claude GitHub App is installed only on the repositories Claude Security scans, and an org owner keeps it suspended outside scan windows. Nothing in these workflows acts as claude[bot]: they land as the machine account, and the scanner only reads. A push, comment, label, review or pull request by claude[bot] is unexpected; report it as above. What the App could do during a scan window is in THREAT_MODEL.md.

Threat model

The trust boundaries, the guarantees and what is by design, not a finding, are in THREAT_MODEL.md.

There aren't any published security advisories