security: eval experiment DB persists judge/variant model output unscrubbed
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
Research direction
Start with src/brainlayer/eval/experiment_store.py and read AGENTS.md for the scrub_llm_output rule. Inspect ExperimentStore.add_judgment and upsert_variant, including their INSERT paths, then verify that rationale, scores, and enrichment are scrubbed before persistence and fail closed like the other sites.
Written by the indexing model from the issue text.
Description
Gap
The eval experiment DB (abcde-experiment.db, src/brainlayer/eval/experiment_store.py) persists model output without scrub_llm_output:
enrichment_judge._persist_judgment→ExperimentStore.add_judgmentwrites the judge'srationaleandscores_json.reasonas the model wrote them.ExperimentStore.upsert_variantwritesenrichment_jsonas given (no in-repo caller today, so any future caller inherits the gap).
Scope
Separate eval DB, not the canonical DB and not search-reachable, so a lower priority than session_enrichments. Still model output at rest, and every other LLM-output → DB write goes through scrub_llm_output (AGENTS.md: "every LLM output field passes scrub_llm_output before it is persisted").
Fix shape
Scrub rationale, scores and enrichment in ExperimentStore before the INSERT, so every caller is covered at the chokepoint. Fail closed like the other sites.
Found during the audit for the tool_usage_stats scrub lane (security).
— brainlayerClaude (worker) · claude-code/claude-opus-5-5
- Dominant language
- Python
- Stars
- 9
- Forks
- 7
- Avg merge
- 2h 8m
- Merged PRs (30d)
- 211
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from EtanHey/brainlayer
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
EtanHey/brainlayer#999 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
EtanHey/brainlayer#985 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
EtanHey/brainlayer#982 ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
EtanHey/brainlayer#676 ·
Maintainers usually reply within 1 day
-
enhancement
Difficulty 1/5 1-3 hours Newbie friendliness 88/100
EtanHey/brainlayer#612 ·
Maintainers usually reply within 1 day
All issues in EtanHey/brainlayer
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
PedestrianDynamics/pyFDS-Evac#343 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
theskumar/python-dotenv#708 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 2 days
-
Docs Timedelta
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
pandas-dev/pandas#69919 ·
Maintainers usually reply within 1 day
-
API documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
zephyrproject-rtos/west#1009 · 2 comments ·
Maintainers usually reply within 3 days