Team Ai
Datasetpublic

paulibo/vcore-workflow-envelopes

Authority envelopes of public workflows using claude-code-action (de-identified) Links Blog post: https://paulinebourigault.github.io/blog/2026/what-the-agent-may-do/ Code (vcore): https://github.com/certior/vcore Companion dataset (benchmark): https://huggingface.co/datasets/paulibo/vcore-actions-benchmark Derived analysis of 16,346 distinct public GitHub workflow files that invoke anthropics/claude-code-action, collected through GitHub code search on… See the full description on the dataset page: https://huggingface.co/datasets/paulibo/vcore-workflow-envelopes.

sourceHugging Facecc-by-4.0updated 11d agoView on Hugging Face
0likes121downloads
Dataset Card

Authority envelopes of public workflows using claude-code-action (de-identified)

Links

  • —Blog post: https://paulinebourigault.github.io/blog/2026/what-the-agent-may-do/
  • —Code (vcore): https://github.com/certior/vcore
  • —Companion dataset (benchmark): https://huggingface.co/datasets/paulibo/vcore-actions-benchmark

Derived analysis of 16,346 distinct public GitHub workflow files that invoke anthropics/claude-code-action, collected through GitHub code search on 2026-09-15 and analysed with a model of the action at v1.0.225 and the Lean-verified vcore checker.

What is in a record

  • —id: an opaque identifier (a keyed hash; the key is not published)
  • —copies: identical copies in the collection; stars_bucket
  • —per agent step: reference class, resolved version and family (only v1 steps are analysed)
  • —per configuration (event, activity type, mode): whether the agent can run and why not, whether the triggering account can lack write access, which prompt sources an outsider can write, whether the workspace can hold pull request content, whether the token is in .git/config, subprocess scrubbing, permission mode, tool categories, the verdicts of P1 (exfiltration) and P2 (untrusted write) with abstract counterexample shapes, and the single workflow edits verified to restore each property

claude-code-action.manifest.json has the collection funnel, the search query, the model commit and the aggregates reported in the write-up.

What is not in a record

Repository names, owners, paths, commit or blob ids, content hashes, dates, licences, languages and workflow contents. Records cannot be joined to repositories through the data.

Interpretation

A violated property means the configuration permits a sequence of tool calls, under named assumptions; it is not evidence that any repository was or can be attacked. Unrestricted shell access and unknown text provenance are treated conservatively; the manifest includes a sensitivity run that trusts text of unknown authorship.