From the Inside Claude Code: The Claude Code Ecosystem architecture map

Claude jobs reach GitHub only through a read-only wrapper and event-bound writes

strength · medium · verified

scripts/gh.sh allows only issue view, issue list, search issues and label list, rejects repo:, org: and user: qualifiers, and requires numeric issue numbers. Writes go through edit-issue-labels.sh and comment-on-duplicates.sh, which read the issue number from GITHUB_EVENT_PATH, drop unknown labels and cap duplicates at three existing issues. Write, Edit, WebFetch and WebSearch are disallowed and the runner egress is allow-listed.

Impact: A prompt-injected agent cannot touch other issues, other repositories, code, or arbitrary hosts.

CLAUDE_CODE_SCRIPT_CAPS further limits triage to two label edits and dedupe to one duplicate comment per run.

The trail

  1. GitHub Actions Workflows
  2. Issue Automation Scripts
  3. GitHub
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com