Run independent adversarial security and external-effects review
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 0
- Forks
- 0
- Avg merge
- 8h 21m
- Merged PRs (30d)
- 2
Description
Outcome
An independent model attempts to bypass authority, expose sensitive data, or duplicate money/supplier effects before the deployed demo is trusted.
Scope
- Attack OAuth audience/tenancy, RBAC, local/broker revocation, non-authorizing handoffs, browser sessions, CSRF, and approval/review TOCTOU.
- Attack Stripe and supplier idempotency, webhook/browser ordering, crash reconciliation, refund-target overcommitment, service refunds, and inactive-run callbacks.
- Inspect vault, redaction, erasure, logs, URLs, receipts, effects/attempts/jobs, errors, and console/MCP projections.
- Attack fixture materialization privilege and active-run switching with unresolved work.
Acceptance
- Reviewer did not author the reviewed code or its fixes.
- Severity-ranked findings include reproducible evidence or concrete arguments.
- Locator-only browser use, wrong user, replay, stale reprice, revoked authority, callback inversion, overlapping refund obligations, and racing effect observations are attempted.
- All blocking findings are fixed and re-reviewed or explicitly accepted by the product owner.
- The review states which deeper production-hardening items remain post-demo.
Dependencies
- #19, #20, #21, #14, and #15.
Review
This issue is the mandatory stage 4 security/effects gate artifact.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the implementations and review artifacts from dependencies #19, #20, #21, #14, and #15, then map the listed OAuth, authorization, browser, payment, callback, logging, and fixture scenarios to the deployed demo. Attempt each acceptance-case attack with reproducible evidence, rank findings by severity, and document fixes, explicit product-owner acceptance, and remaining post-demo hardening work.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, authorization, payments, security, testing
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100