repo_analyze flags no SECURITY.md and no CODEOWNERS. Because this repo deliberately executes untrusted model-generated Python, a SECURITY.md that (a) documents the sandboxing model and its current guarantees/limitations and (b) explains how to report vulnerabilities would be high-value. A CONTRIBUTING.md would also help for an org-level open-source repo.
repo_analyze flags no SECURITY.md and no CODEOWNERS. Because this repo deliberately executes untrusted model-generated Python, a SECURITY.md that (a) documents the sandboxing model and its current guarantees/limitations and (b) explains how to report vulnerabilities would be high-value. A CONTRIBUTING.md would also help for an org-level open-source repo.