CI / build (push) Has been cancelled
- Archive 79 completed framework-dev tasks from tasks/ -> tasks/complete/ - status.py: add --cleanup-done and --install-cleanup-schedule commands - Add scripts/automaton-cleanup.sh for periodic task archiving - Dashboard: rename 'Background' tab -> 'Agent', 'Cleanup' agent -> 'Completed Task Archiver', remove redundant group headers and pill badges, dim inactive agent placeholders - .rules.md: add Self-Documenting UI Names rule - New tests: test_cleanup_done.py, expanded test_app.py and test_task.py
10 lines
413 B
Markdown
10 lines
413 B
Markdown
# Adversarial Bug Report: Inline Comment Textarea for Review
|
|
|
|
## Deep Review
|
|
Textarea value is read with `.value`, sent as JSON, and stored directly in REVIEW.md.
|
|
|
|
## Potential Issues
|
|
1. **No input sanitization**: Comment text is stored raw. If REVIEW.md is later parsed by markdown renderer, injection possible. Acceptable risk — REVIEW.md is a structured data file, not a rendered document.
|
|
|
|
## Verdict: PASS
|