DashboardpublishPerform read-only, evidence-based audit…

Perform read-only, evidence-based audits with an explicit merge verdict

Category: preference
Confidence: 0.80
ID: 01a08c56-2be3-7536-8324-5866130c6591
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 1
Source session: 0zagU7llErLsZ8oKO
Created: 2026-09-10 17:20:52
Updated: 2026-09-10 17:20:52

Cross-Project Recalls

ProjectHitsLast recalled
opencode-lore 2 1h ago

Content

Always audit the exact current worktree against the stated base without editing, formatting, staging, stashing, committing, generating, or otherwise mutating repository state. Inspect every changed and untracked file and trace security-critical approval, event/request binding, CI transitions, trusted-code execution, immutable dependencies, pre-release validation, and terminal cleanup paths. Treat event and issue data as attacker-controlled while respecting explicitly accepted pre-existing risks. Run requested read-only checks and, when requested, verify the worktree fingerprint is unchanged. Produce a non-empty report with findings ordered by severity, each labeled PASS, CONCERN, or MUST-FIX and supported by current file:line evidence. If tooling blocks review, begin with BLOCKED and quote the exact error. End exactly with MERGE or DO-NOT-MERGE.

Move to: