Generated file maps are untrusted input. Every path is normalized, rejects absolute/drive/parent traversal, resolves beneath the selected job root, and must contain text before materialization. Job IDs are restricted to a short safe character set.
The bundled stages are deterministic simulations. Replacing them with model, Docker, or external tool adapters would require a separate trust boundary: review generated code, avoid credential inheritance, keep execution isolated, and never treat an LLM verdict as a security sandbox.