CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
873 B
873 B
Adversarial Bug Report — harden-enforcement-layers
Attack Vectors
- Hook bypass: Can a user bypass the pre-push hook?
- Symlink attacks: Does
install-hooks.shfollow symlinks unsafely? - Command injection: Does
register-guards.shhave injection vectors in its Python inline script or pi install call?
Findings
- Pre-push hook can be bypassed with
--no-verify(documented), but this is by design — it's a deterrent layer install-hooks.shusescpnotln -sf— no symlink following riskregister-guards.shpasses$OPENCODE_SOURCEand$PI_SOURCEto Python/pi — these are hardcoded framework paths, not user input. Safe.- Python inline script uses
$OPENCODE_CONFIGwhich could theoretically contain special chars, but this is a framework path from a controlled location
Verdict
No exploitable vulnerabilities found.