DashboardpublishUse strict read-only, evidence-backed s…

Use strict read-only, evidence-backed security audit reports

Category: preference
Confidence: 0.80
ID: 01a09fd2-0d9c-7607-b0b9-4243993fa149
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 1
Source session: 0znBJ2ZDBdIk4MyqO
Created: 2026-09-14 12:08:58
Updated: 2026-09-14 12:08:58

Cross-Project Recalls

ProjectHitsLast recalled
opencode-lore 2 18h ago

Content

When reviewing security or correctness, independently inspect the exact current worktree, relevant workflows, source, and tests without editing, formatting, staging, generating, or otherwise mutating repository files. Return a non-empty report that directly addresses every requested audit question. Order substantive findings from highest to lowest severity and label each MUST-FIX, CONCERN, or PASS, citing current file:line evidence and including compact test/evidence details; state explicit PASS evidence when no defect is found. Preserve any requested scope, especially approval provenance, trust boundaries, immutable pinning, lifecycle cleanup, retries, cancellation, and adversarial paths. If inspection is blocked, begin with BLOCKED, quote the exact tool or artifact error, identify what could not be inspected, and conclude negatively. Always end the report exactly with MERGE or DO-NOT-MERGE.

Move to: