From the Inside Claude Code: The Claude Code Ecosystem architecture map

The triage and dedupe agents are boxed in identity, tools and network

strength · medium · verified

Both Claude jobs authenticate with a short-lived token from workload identity federation instead of a stored key, hold only issues: write, run in auto permission mode with Write, Edit, WebFetch and WebSearch disallowed, call GitHub only through the wrapper scripts, and run on a runner whose egress is limited to an explicit host list.

Impact: A compromised run can at most mislabel or comment on the one issue that triggered it.

This is a strong template for any further agent in this repo: per-job token, script-mediated writes, explicit egress list and per-script call caps.

The trail

  1. GitHub Actions Workflows
  2. Anthropic API
  3. Issue Automation Scripts
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com