Hardened CI for untrusted pull requests
For maintainers needing a ready-to-run workflow that limits token and secret exposure.
Works with
- Cursor
- GitHub Copilot
- Codex
- DeepSeek
The prompt152 words · 3 blanks
What you fill in
- Package manager
[package_manager]Examplepnpm - Test command
[test_command]Examplepnpm test -- --runInBand - Pull request trust level
[threat_model]ExamplePublic repository with forked pull requests
How to use it
- 1Open it in PromptVault. Find it in Coding, or search for “Hardened CI for untrusted pull requests”.
- 2Fill in the 3 blanks. package manager, test command and pull request trust level — the only things the prompt cannot know.
- 3Copy and paste it into Cursor. It also works with GitHub Copilot, Codex and DeepSeek.
About this prompt
“Hardened CI for untrusted pull requests” is a intermediate coding prompt. For maintainers needing a ready-to-run workflow that limits token and secret exposure. It is 152 words long and written to get a usable answer on the first message, in Cursor, GitHub Copilot and Codex or any other chat assistant. Good for: automation, devops, security, testing and first draft. Like every prompt in PromptVault, it was written and edited in-house, and it works offline once the app is installed.
