So the CodeRabbit application with access to application secrets still runs in the same virtual machine as untrusted code from the outside?