Dashboardinstitutional-transition-labPerform read-only adversarial security …

Perform read-only adversarial security reviews with reproducible evidence

Category: preference
Confidence: 0.80
ID: 01a086e8-5571-73c1-99fc-7711c7f12c12
Project ID: 1fa3712f-997f-4884-b7ec-8abb79f9e342
Cross-project: No
Recalled in other projects: 2
Source session: 0seXxhTpLwXa3dhZk
Created: 2026-09-09 03:20:27
Updated: 2026-09-09 16:02:48

Cross-Project Recalls

ProjectHitsLast recalled
opencode-lore 4 14h ago
cli 1 7d ago

Content

When reviewing archive handling, do not edit files or drift into unrelated governance logic. Inspect the exact current ZIP-validation code, relevant tests, and CPython decompression behavior where necessary. Verify actual—not merely declared—member and aggregate decompressed-byte limits, malformed or truncated streams, CRC/integrity behavior, duplicate or ambiguous names, unsupported metadata/codecs, partial reads, cleanup, and compression-bomb termination. Support conclusions with exact file:line references, small deterministic read-only probes, and focused fail-first regression tests. Distinguish proven protections from residual risks, report substantive findings in severity order using clear PASS/CONCERN/MUST-FIX classifications, and provide an explicit merge disposition when requested.

Move to: