security: session summary_embedding is computed from the unscrubbed summary
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 82/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- python
- Domain
- machine-learning, security
Research direction
Start in src/brainlayer/pipeline/session_enrichment.py at enrich_session Step 5 and trace the call to upsert_session_enrichment and scrub_llm_output. Add a regression test showing that embed_fn receives the redacted session summary, then run the relevant session-enrichment tests. Done means the stored vector is derived from the scrubbed text.
Written by the indexing model from the issue text.
Description
Gap
enrich_session (src/brainlayer/pipeline/session_enrichment.py, Step 5) computes summary_embedding = embed_fn(enrichment["session_summary"]) before upsert_session_enrichment scrubs session_summary. The stored text is redacted; the stored vector was computed from the unredacted text.
Why it matters
Different class from the text-at-rest gap fixed in the tool_usage_stats scrub PR: a vector is not the token, but it is derived from it, and semantic search over summary_embedding can match on content that the persisted text no longer carries.
Fix shape
Scrub the summary before embedding (embed_fn(scrub_llm_output(summary))), or embed after the upsert from the stored value. Add a test that the embed_fn receives the redacted text.
At rest
Canonical session_enrichments has 0 rows (read-only count, 2026-09-28), so nothing to backfill today.
Found during the audit for the tool_usage_stats scrub lane (security).
— brainlayerClaude (worker) · claude-code/claude-opus-5-5
- Dominant language
- Python
- Stars
- 9
- Forks
- 7
- Avg merge
- 2h 8m
- Merged PRs (30d)
- 225
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from EtanHey/brainlayer
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
EtanHey/brainlayer#999 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
EtanHey/brainlayer#986 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
EtanHey/brainlayer#676 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
EtanHey/brainlayer#612 ·
Maintainers usually reply within 1 day
-
good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
EtanHey/brainlayer#59 ·
Maintainers usually reply within 1 day
All issues in EtanHey/brainlayer
Similar issues
-
namespace operations
Difficulty 1/5 Under an hour Newbie friendliness 82/100
EclipseFdn/open-vsx.org#13573 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
collective/icalendar#1854 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
rancher/rancher-ai-agent#412 ·
Maintainers usually reply within 6 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
TUDelftGeodesy/DePSI#134 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
HenriquesLab/rxiv-maker#335 ·