AltimateAI / AltimateAI/altimate-code

workspace: memory content mirrored to cloud is unfiltered — no secret/PII redaction

Offen
#1,141 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
TypeScript
Sterne
811
Forks
134
Ø Merge
3 T. 2 Std.
Gemergte PRs (30 T.)
50

Beschreibung

Found during v0.9.7 release review (Chaos Gremlin/Privacy Auditor persona).

`memory-extract.ts`'s tool description explicitly invites the agent to capture 'warehouse configs found via /discover, query patterns from sql_optimize, naming conventions observed' into memory blocks. Nothing in the write path (`memory-write.ts`, `memory-extract.ts`) or the mirror path (`memory-sync.ts`'s `push()` forwards `block.content` verbatim to `MemoryApi.add/update`) does secret-scanning, PII filtering, or redaction before content leaves the machine (when workspace mirroring is enabled).

Compounds the disclosure gap fixed in v0.9.7 (see bind-time consent line added in workspace.tsx/link.ts): once a user knows memory syncs and accepts that, there's still no guardrail preventing a warehouse connection string or customer-identifying value from being captured into a block and mirrored.

Deferred because this needs a content-scanning/redaction design (not a quick patch), and the feature remains gated behind the off-by-default `ALTIMATE_WORKSPACE` pilot flag.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Trace the memory write and mirror paths in memory-write.ts, memory-extract.ts, and memory-sync.ts, especially push() forwarding block.content to MemoryApi.add/update. Review the consent-related changes in workspace.tsx and link.ts for context. Done requires an agreed content-scanning and redaction design that prevents secrets and PII from leaving the machine when mirroring is enabled.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
typescript
Bereich
cloud, data-engineering, security
Issue-Typ
Feature
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Aktiv
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.