Archive completed tasks, add cleanup commands, self-documenting dashboard UI
CI / build (push) Has been cancelled

- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/
- status.py: add --cleanup-done and --install-cleanup-schedule commands
- Add scripts/automaton-cleanup.sh for periodic task archiving
- Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders
- .rules.md: add Self-Documenting UI Names rule
- New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
This commit is contained in:
Lap Tran
2026-06-24 22:43:33 -04:00
parent e13513faaa
commit 4a2301b077
572 changed files with 856 additions and 101 deletions
@@ -0,0 +1,15 @@
# Adversarial Bug Report — harden-enforcement-layers
## Attack Vectors
1. **Hook bypass**: Can a user bypass the pre-push hook?
2. **Symlink attacks**: Does `install-hooks.sh` follow symlinks unsafely?
3. **Command injection**: Does `register-guards.sh` have injection vectors in its Python inline script or pi install call?
## Findings
- Pre-push hook can be bypassed with `--no-verify` (documented), but this is by design — it's a deterrent layer
- `install-hooks.sh` uses `cp` not `ln -sf` — no symlink following risk
- `register-guards.sh` passes `$OPENCODE_SOURCE` and `$PI_SOURCE` to Python/pi — these are hardcoded framework paths, not user input. Safe.
- Python inline script uses `$OPENCODE_CONFIG` which could theoretically contain special chars, but this is a framework path from a controlled location
## Verdict
No exploitable vulnerabilities found.