Delivery and remote operationsCommand contributionv1.0.0Built-in coverage

GitHub capability protection

Reviews distinct GitHub maintenance, content, merge, publication, workflow, and control effects.

Evidence at a glance

Source
Merged native coverage · f440ae1a9f
Activation
This coverage is built into the native Guard runtime.
Maintainer
Project maintained
Coverage
15 rules · 19 permissions

Coverage and limits

Reviews distinct GitHub maintenance, content, merge, publication, workflow, and control effects.

  • Coverage is limited to the reviewed operations and the surrounding Guard policy.
  • A maintainer profile is not a security certification or an official upstream endorsement.

Command mapping and enforcement

How Guard maps this extension onto your workspace policy: which commands it recognizes, which tools it touches, and how each tool state resolves.

15
Reviewed rules
19
Permission checks
0
Per-tool overrides
v1.0.0
Listing version

Runtime identity

Catalog ID
command.github
Guard enforcement ID
command.github
Source path
src/codex_plugin_scanner/guard/runtime/command_builtin_extension_registry.py

Tool state mapping

No per-tool overrides are declared. Every tool this extension touches resolves through the workspace Guard policy as-is.

Action classes

GitHub routine pull-request merge commandGitHub workflow rerunGitHub local configuration writeGitHub bounded maintenance commandGitHub content mutation commandGitHub merge commandGitHub administrator pull-request merge commandGitHub release publication commandGitHub workflow mutation commandGitHub force mutation commandGitHub delete commandGitHub secret mutation command+3 more

Frequently asked questions

What does GitHub capability protection cover?

Reviews distinct GitHub maintenance, content, merge, publication, workflow, and control effects. The listing declares 15 rules and 19 permission checks. Coverage is limited to these reviewed operations and the surrounding Guard policy.

Is GitHub capability protection active by default?

Built-in coverage: This coverage is built into the native Guard runtime. Enabling state is always controlled through Guard policy, never from this directory.

Who maintains GitHub capability protection?

This listing is maintained by the HOL Guard project itself as part of the native runtime catalog.

Is a listing of GitHub capability protection a security guarantee?

No. Every listing documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. Review the stated limitations and the exact source tree before relying on any single control.