Skip to content

Fix: Committed .grok/settings.json bypasses workspace trust and controls sandbox security posture - #340

Open
superagent-security-dev[bot] wants to merge 1 commit into
mainfrom
superagent/patch-185953b6-8d7d-498d-b302-72b3213c8f6c
Open

Fix: Committed .grok/settings.json bypasses workspace trust and controls sandbox security posture#340
superagent-security-dev[bot] wants to merge 1 commit into
mainfrom
superagent/patch-185953b6-8d7d-498d-b302-72b3213c8f6c

Apply Superagent patch: Fix: Committed .grok/settings.json bypasses w…

f1e0b44
Select commit
Loading
Failed to load commit list.
Superagent Security / Contributor trust completed Jun 26, 2026 in 16s

Contributor trust inconclusive

The contributor 'superagent-security-dev[bot]' is a bot account with zero retrievable pull-request history. GitHub PR search returned no authored pull requests (warning: 'GitHub PR search returned no authored pull requests or was unavailable.'). With candidate_pr_count=0, hydrated_pr_count=0, and no patch-level evidence to inspect, there is no basis for a patch-level adversarial review. Per the detection guidance, when evidence is insufficient or the packet is too truncated to judge, the verdict must be inconclusive. The account's naming suggests it is an organizational security bot for the superagent organization, but this cannot be treated as a safety signal per instructions prohibiting reputation-based safe verdicts.