ProtoLens

ProtoLens security

Security model

ProtoLens reviews static prototypes from GitHub without cloning repositories, installing dependencies, or executing user code.

No repository cloning

Review links read selected static files by repo, ref, and path through GitHub APIs.

No npm install or builds

ProtoLens does not run package managers, build scripts, dev servers, or repository runtime code.

Static rendering only

HTML and SVG are sanitized before review rendering. Dynamic app hosting is out of scope for the MVP.

Bounded files and comments

File size, comment body, discovery, and export limits protect GitHub and Cloudflare quota.

Security contact

Report security issues to support@myagenthubs.com.