Dashboard › institutional-transition-lab › Perform read-only adversarial security …
01a086e8-5571-73c1-99fc-7711c7f12c12| Project | Hits | Last recalled |
|---|---|---|
| opencode-lore | 4 | 14h ago |
| cli | 1 | 7d ago |
When reviewing archive handling, do not edit files or drift into unrelated governance logic. Inspect the exact current ZIP-validation code, relevant tests, and CPython decompression behavior where necessary. Verify actual—not merely declared—member and aggregate decompressed-byte limits, malformed or truncated streams, CRC/integrity behavior, duplicate or ambiguous names, unsupported metadata/codecs, partial reads, cleanup, and compression-bomb termination. Support conclusions with exact file:line references, small deterministic read-only probes, and focused fail-first regression tests. Distinguish proven protections from residual risks, report substantive findings in severity order using clear PASS/CONCERN/MUST-FIX classifications, and provide an explicit merge disposition when requested.