Now having an agent scour the internet puts it at risk of prompt injection and so you may not want to also give it push access to the main repo. Yet, it still needs to create PRs.
To be able to create PRs, the private key to the upgrader's GitHub App bot account is in the container's environment vars.
To make this safe, we treat the agent session as adversarial code. The agent (Pi) is spawned as a different, non-root user and does not inherit the parent's environment. This way there's nothing to exfiltrate, nor can it push to github.
The agent is told to commit its changes in its local clone only, and exit. The parent (regular code, not an agent) then creates a branch and opens the PR.