Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

security: session summary_embedding is computed from the unscrubbed summary

Open Beginner friendly
#985 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
82/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
python

Research direction

Start in src/brainlayer/pipeline/session_enrichment.py at enrich_session Step 5 and trace the call to upsert_session_enrichment and scrub_llm_output. Add a regression test showing that embed_fn receives the redacted session summary, then run the relevant session-enrichment tests. Done means the stored vector is derived from the scrubbed text.

Written by the indexing model from the issue text.

Description

Gap

enrich_session (src/brainlayer/pipeline/session_enrichment.py, Step 5) computes summary_embedding = embed_fn(enrichment["session_summary"]) before upsert_session_enrichment scrubs session_summary. The stored text is redacted; the stored vector was computed from the unredacted text.

Why it matters

Different class from the text-at-rest gap fixed in the tool_usage_stats scrub PR: a vector is not the token, but it is derived from it, and semantic search over summary_embedding can match on content that the persisted text no longer carries.

Fix shape

Scrub the summary before embedding (embed_fn(scrub_llm_output(summary))), or embed after the upsert from the stored value. Add a test that the embed_fn receives the redacted text.

At rest

Canonical session_enrichments has 0 rows (read-only count, 2026-09-28), so nothing to backfill today.

Found during the audit for the tool_usage_stats scrub lane (security).

— brainlayerClaude (worker) · claude-code/claude-opus-5-5

Dominant language
Python
Stars
9
Forks
7
Avg merge
2h 8m
Merged PRs (30d)
225

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from EtanHey/brainlayer

All issues in EtanHey/brainlayer

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.