The page covers tokens, hashes, HMAC and the no-server-key rule, and says nothing about what executes repository content, as what, and where. Same gap as the runner issue.
Threat-Model wiki page omits the runner #138
Discussion
Threat-Model now has a section on the CI runner (what the runner holds, what a build sees, where it runs, and the accepted residual risk of uncontained steps), and Admin's runner section covers the runner key scope, the bootstrap flow, the sandboxing drop-in, untrusted fork builds, and trusted_proxies. Wiki commit e977337.