Trust-boundary note
I understand that IdeaHub is maintained internally, so the CLI-content concern depends on the project’s trust model. However, the current command accepts any URL beginning with http, and service ownership does not necessarily guarantee that every idea’s content is maintainer-authored. I would treat this as a documented trust-boundary concern rather than a confirmed blocker if the project can guarantee that all accepted content is intentionally trusted. Otherwise, defense-in-depth safeguards may be warranted to reduce the risk of prompt injection.
Originally posted by @Frankbest18 in #147 (review)
Trust-boundary note
I understand that IdeaHub is maintained internally, so the CLI-content concern depends on the project’s trust model. However, the current command accepts any URL beginning with
http, and service ownership does not necessarily guarantee that every idea’s content is maintainer-authored. I would treat this as a documented trust-boundary concern rather than a confirmed blocker if the project can guarantee that all accepted content is intentionally trusted. Otherwise, defense-in-depth safeguards may be warranted to reduce the risk of prompt injection.Originally posted by @Frankbest18 in #147 (review)