Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

security: session summary_embedding is computed from the unscrubbed summary

Aperta Adatta ai principianti
#985 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
82/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python

Direzione di ricerca

Inizia in src/brainlayer/pipeline/session_enrichment.py al passaggio 5 di enrich_session e segui la chiamata a upsert_session_enrichment e scrub_llm_output. Aggiungi un test di regressione che dimostri che embed_fn riceve il riepilogo della sessione redatto, quindi esegui i test pertinenti di arricchimento della sessione. Il lavoro è completato quando il vettore memorizzato deriva dal testo ripulito.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Gap

enrich_session (src/brainlayer/pipeline/session_enrichment.py, Step 5) computes summary_embedding = embed_fn(enrichment["session_summary"]) before upsert_session_enrichment scrubs session_summary. The stored text is redacted; the stored vector was computed from the unredacted text.

Why it matters

Different class from the text-at-rest gap fixed in the tool_usage_stats scrub PR: a vector is not the token, but it is derived from it, and semantic search over summary_embedding can match on content that the persisted text no longer carries.

Fix shape

Scrub the summary before embedding (embed_fn(scrub_llm_output(summary))), or embed after the upsert from the stored value. Add a test that the embed_fn receives the redacted text.

At rest

Canonical session_enrichments has 0 rows (read-only count, 2026-09-28), so nothing to backfill today.

Found during the audit for the tool_usage_stats scrub lane (security).

— brainlayerClaude (worker) · claude-code/claude-opus-5-5

Lingua principale
Python
Stelle
9
Fork
7
Merge medio
2h 8m
PR unite (30g)
225

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di EtanHey/brainlayer

Tutte le issue di EtanHey/brainlayer

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.