The apply pipeline's draft PRs were titled `agent-apply: <task_id> (diff <hash>)` with a flat body — neither within Sea Haven PR conventions. That format was deliberate injection-hardening (only sanitized tokens, never model free-text; §4.6). Thread the approved plan's title through dispatch as an optional `pr_title` input, sanitized box-side (single line, no control chars, 70-char cap, capitalized) and RE-VALIDATED in the workflow as defense- in-depth, with the hardened `agent-apply: <task_id>` title as the fallback when empty/unsafe. Provenance (task id, diff hash, head) moves to the PR body. gh consumes both as argv data, never shell-interpolated. |
||
|---|---|---|
| .. | ||
| db | ||
| nodes | ||
| transport | ||
| __init__.py | ||
| api.py | ||
| billing.py | ||
| ci_fetcher.py | ||
| ci_gate.py | ||
| ci_watcher.py | ||
| coordinator.py | ||
| dashboard.py | ||
| deadline_timer.py | ||
| decisions.py | ||
| dispatcher.py | ||
| draft_pr_monitor.py | ||
| github_app.py | ||
| graph.py | ||
| invoker.py | ||
| invoker_multi.py | ||
| ledger.py | ||
| operator_cli.py | ||
| recovery.py | ||
| responder.py | ||
| resume_worker.py | ||
| state_store.py | ||
| status_page.py | ||
| task_model.py | ||
| topology.py | ||