• This feels like a nonissue. There are dozens of ways an untrustworthy repo can cause code execution, from this to build.rs.

    Expecting Claude to list every possible risk is a bit silly.