Skip to content

Fix Onakke Oathkeeper - #6850

Merged
matthewevans merged 3 commits into
phase-rs:mainfrom
invalidCards:card/onakke-oathkeeper
Aug 1, 2026
Merged

Fix Onakke Oathkeeper#6850
matthewevans merged 3 commits into
phase-rs:mainfrom
invalidCards:card/onakke-oathkeeper

fix: address Onakke Oathkeeper review feedback

c86a76d
Select commit
Loading
Failed to load commit list.
Superagent Security / Contributor trust completed Aug 1, 2026 in 1s

Contributor trust inconclusive

Investigator 2 reviewed 33 assigned PRs (5 with full patches, 5 with preview patches, and 23 metadata-only). All hydrated patches show benign changes: README documentation updates, single-character typo fixes, optional Discord API query parameters, shell path quoting for Windows decompression, cosmetic mascot additions in a browser extension, MTG card frame image assets, snippet formatting changes, and MTG engine parser logic with extensive tests and CI verification. No evidence of credential exfiltration, hidden network calls, obfuscated code, CI tampering, permission broadening, or installation lifecycle abuse was found in any visible patch. However, 23 PRs in this shard lack hydrated patches, and 70 candidate PRs were omitted globally. High-risk browser extension repositories (new-xkit/XKit, AprilSylph/XKit-Rewritten) that execute with broad page permissions are predominantly unreviewed at the patch level. Because patch-level evidence is missing for the majority of contributions, including highest-risk repos, a confident safety verdict cannot be rendered. Five fully-hydrated PRs were reviewed at patch level and found clean: a Dutch game translation (pure JSON strings), a dice-bot formatting tweak (no eval/network), a CORS proxy swap in a card-art renderer (benign endpoint change with rationale), MTG deck data files (plain text card lists), and documentation markdown. The remaining 28 assigned PRs were either metadata-only or had truncated preview patches that prevented adversarial review of hunks. Notably, a large GPU plugin refactoring PR in region-locker (#20, +789/-986 across 9 files including build.gradle, Java GPU code, and GLSL shaders) was truncated and left unmerged. No concrete malicious patch evidence was found in visible content, but the shard cannot support a confident safe verdict because most candidate PRs were not reviewable at the required patch level and the highest-risk repository changes were truncated.