8ac1d8223b
Creates /tmp/venv inside the ephemeral container, installs bandit there, and runs the security check via the venv's Python. No --user installs, no script-location warnings, no writes outside the container's /tmp. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>