ForgeLayer

GitHub Repository Connection v1

Represent repository boundaries before any GitHub access exists.

Workspace-owned repository previews separate GitHub host identity, installation trust, repository ownership, permissions, metadata, contents, and future write authority. No GitHub request occurs.

GitHub host: recognizedInstallations verified: 0GitHub requests: 0Writes / execution: disabled

Authenticated integration boundary

Persist repository metadata without granting GitHub access.

The isolated adapter stores allowlisted labels in the server-resolved workspace. It does not validate an installation, read repository contents, write to GitHub, or execute repository commands.
Integration inactive

Repository connection metadata

Isolated persistence is not active. Deterministic preview data remains separate.

External contact: false

Workspace repository inventory

1 repository host recognized

3 scenario-isolated GitHub repository previews. Installation, ownership, permissions, metadata, and contents remain unverified or unavailable.

Inspect Repository Connections
3Recorded previews
0Verified installations
0Verified repositories
0Metadata read enabled
0Contents read enabled
0Write enabled
0Webhooks configured
0Repository executions
Deterministic previewGitHub requests: 0GitHub writes: 0Provider inventory remains separate

Scenario-isolated inventory

Three Controlled Tasks, three independent repository previews.

Identity, labels, paths, policy snapshots, Review Runs, Work Records, and Ledger references remain scoped to one scenario.

GitHub · repository host

acme-payments/payment-webhook-service

Recorded preview

Secure Payment Webhook · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Inactive
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (2)
  • app/api/payments/webhook.ts
  • tests/payment-webhook.test.ts
Review future setup requirements
  • Authenticated workspace identity
  • Durable RLS-backed authoritative storage
  • Reviewed GitHub App authorization architecture
  • Verified installation ownership
  • Verified repository ownership
  • Least-privilege permission validation
  • Secure installation-token handling
  • Private-key protection
  • Webhook signature verification
  • Webhook replay protection
  • Rate-limit handling
  • Installation revocation and uninstall handling
  • Repository deletion and transfer handling
  • Secret and output redaction
  • Durable audit storage
  • Retention controls
  • Sandboxed provider and repository transports
  • Network containment
  • Filesystem containment
  • Reliable cancellation
  • Timeout enforcement
  • Metering and budget enforcement
  • Provider isolation
  • Independent security review

GitHub · repository host

acme-ai-support/refund-assistant-prompts

Recorded preview

Harden Risky Prompt · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Inactive
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (2)
  • lib/prompts/refund-assistant.ts
  • prompts/refund-assistant-security.md
Review future setup requirements
  • Authenticated workspace identity
  • Durable RLS-backed authoritative storage
  • Reviewed GitHub App authorization architecture
  • Verified installation ownership
  • Verified repository ownership
  • Least-privilege permission validation
  • Secure installation-token handling
  • Private-key protection
  • Webhook signature verification
  • Webhook replay protection
  • Rate-limit handling
  • Installation revocation and uninstall handling
  • Repository deletion and transfer handling
  • Secret and output redaction
  • Durable audit storage
  • Retention controls
  • Sandboxed provider and repository transports
  • Network containment
  • Filesystem containment
  • Reliable cancellation
  • Timeout enforcement
  • Metering and budget enforcement
  • Provider isolation
  • Independent security review

GitHub · repository host

acme-checkout/checkout-ui

Recorded preview

Investigate Failing Tests · paths are deterministic task scope, not fetched repository contents.

Workspace membership
Workspace Recorded
Adapter
github-repository-adapter · github-repository-adapter-v1
Installation
Installation Unverified
Installation ownership
Installation Ownership Unverified
Repository ownership
Repository Ownership Unverified
Permissions
modeled · unrequested · ungranted · unverified
Metadata / contents
not fetched / not fetched
PR / checks
deterministic previews · not fetched
Webhook
Webhook Not Configured
Revocation / kill switch
Not Revoked / Active
Read / write / execution
false / false / false
WorkspaceIdentityTrustWorkspace Recorded
GithubHostTrustHost Recorded
GithubAccountIdentityTrustAccount Unverified
InstallationIdentityTrustInstallation Unverified
InstallationOwnershipTrustInstallation Ownership Unverified
RepositoryIdentityTrustRepository Recorded
RepositoryOwnershipTrustRepository Ownership Unverified
PermissionTrustPermissions Unverified
MetadataTrustMetadata Not Fetched
ContentsTrustContents Not Fetched
WebhookTrustWebhook Not Configured
HealthTrustHealth Not Observed
AdapterVersionTrustAdapter Recorded
PolicyBindingTrustDeterministic Preview
ProductionReadinessProduction Not Ready
Inspect deterministic task paths (3)
  • tests/checkout-confirmation.test.ts
  • app/checkout/confirmation.tsx
  • package.json
Review future setup requirements
  • Authenticated workspace identity
  • Durable RLS-backed authoritative storage
  • Reviewed GitHub App authorization architecture
  • Verified installation ownership
  • Verified repository ownership
  • Least-privilege permission validation
  • Secure installation-token handling
  • Private-key protection
  • Webhook signature verification
  • Webhook replay protection
  • Rate-limit handling
  • Installation revocation and uninstall handling
  • Repository deletion and transfer handling
  • Secret and output redaction
  • Durable audit storage
  • Retention controls
  • Sandboxed provider and repository transports
  • Network containment
  • Filesystem containment
  • Reliable cancellation
  • Timeout enforcement
  • Metering and budget enforcement
  • Provider isolation
  • Independent security review

Least-privilege design

Permissions are modeled, never requested or granted.

Read-oriented permissions describe future needs. Every read and write transport remains disabled, and approval cannot activate a permission.

Read-oriented permissions

PermissionRiskRequestGrantValidationTransport
repository-metadata-readlowunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
repository-contents-readhighunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
pull-request-readmediumunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
issue-readmediumunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
check-status-readmediumunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
workflow-metadata-readmediumunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
branch-protection-readmediumunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
commit-metadata-readmediumunrequestedungrantedunverifiedgithub_repository_read_transport_disabled
webhook-events-receivehighunrequestedungrantedunverifiedgithub_repository_read_transport_disabled

Write-oriented permissions

PermissionRiskRequestGrantValidationTransport
pull-request-writehighunrequestedungrantedunverifiedgithub_repository_write_transport_disabled
check-status-writehighunrequestedungrantedunverifiedgithub_repository_write_transport_disabled
issue-comment-writehighunrequestedungrantedunverifiedgithub_repository_write_transport_disabled
branch-writecriticalunrequestedungrantedunverifiedgithub_repository_write_transport_disabled
contents-writecriticalunrequestedungrantedunverifiedgithub_repository_write_transport_disabled
workflow-dispatch-writecriticalunrequestedungrantedunverifiedgithub_repository_write_transport_disabled
merge-writecriticalunrequestedungrantedunverifiedgithub_repository_write_transport_disabled

Read-only-first boundary

Architecture-first does not mean live read access.

The model distinguishes permission definition, request, grant, verification, transport, and observed repository data.
Modeled read permissions9
Requested / granted / verified0 / 0 / 0
Metadata / contents statenot fetched / not fetched
PRs / checks fetchedfalse / false
Webhooks received0
GitHub writes0

Adapter boundary

Descriptive contract, disabled transports.

No generic GitHub request method or live operation is exposed.

Connection validation

github_connection_validation_transport_disabled

Repository read

github_repository_read_transport_disabled

Repository write

github_repository_write_transport_disabled

Future production requirements

GitHub access stays blocked until every trust boundary exists.

These are review requirements, not live setup controls.