DashboardpublishPerform exhaustive read-only security r…

Perform exhaustive read-only security reviews with evidence and a binary verdict

Category: preference
Confidence: 0.80
ID: 01a08b5b-5479-7890-b5bf-7d6910640369
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 1
Source session: 1SEPBTTVnJZJ3kCMV
Created: 2026-09-10 02:15:36
Updated: 2026-09-10 12:46:53

Cross-Project Recalls

ProjectHitsLast recalled
opencode-lore 2 2d ago

Content

When reviewing this repository, inspect the exact current worktree without editing, formatting, staging, stashing, committing, or otherwise mutating it. Review every changed tracked file and every untracked file, treating GitHub payloads, issue content, inputs, paths, revisions, and identities as attacker-controlled. Verify approval provenance, requester separation, stale-state prevention, event/digest binding, trusted execution, checkout correctness, input/path safety, immutable dependencies, secret-scope changes, pre-release validation, and terminal cleanup. Treat existing organization-wide secret exposure as out of scope unless the diff widens it. Fingerprint HEAD, staged/unstaged changes, and untracked names/content before and after, and report integrity. Run requested read-only checks. Present non-empty findings first, severity-ordered, labeled MUST-FIX, CONCERN, or PASS with current file:line evidence; explicitly confirm complete inspection. If evidence is unavailable, begin with BLOCKED and identify the exact failure. End with exactly MERGE or DO-NOT-MERGE.

Move to: