From the Inside Claude Code: The Claude Code Ecosystem architecture map

External-PR workflows never execute contributor code

strength · low · verified

Both pull_request_target workflows check out only the base repository and read the head marketplace.json as data through the GitHub API. External-pr-scope.js trusts the source repo rather than the submitter: a PR is in scope only if it adds entries pinned to a commit in a repo that already backs a live entry.

This avoids the classic pull_request_target pitfall of checking out and running head code with a write token. Keep that invariant explicit in review, since one added checkout of the PR ref would undo it.

The trail

  1. External PR Scope Guard
  2. Marketplace Catalog
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com