Testing a generator
You don't need the PDM to try a generator. From the PDM's repository, with a ClassCAD at CC_URL:
yarn workspace @classcad/pdm-worker generator:run ../generators/flange '{"outerDiameter": 160}' ./out
It runs the folder as it is on disk, committed or not, with the manifest's defaults for every parameter you leave out. What it saves lands in the output directory (<folder>/.out by default). Nothing is checked against the manifest: the PDM does that.
Against a repository on your disk
For development, a code document can point at a git repository on the worker's disk instead of GitHub: file:///home/me/generators. The API has to allow it with CODE_ALLOW_LOCAL_REPOS=true. What runs is what's committed. Leave the setting off wherever people aren't trusted.
Trust
Generators run without a sandbox for now: the code can do what Node can do on the worker. Run only code you trust.