Skip to content

handoff re-scan should report what it masked, so pre-rule leaks become visible #91

Description

@agentdynamic

PR for issue 81 closed two capture-time redaction misses (a MySQL-family
-p<password> and several vendor token prefixes). The issue also floated a
third, optional item, deliberately left out of that PR:

Optionally: have handoff's existing re-scan report what it masked, so a
leak that predates a rule gets noticed rather than silently persisting.

Why it is still worth doing, and why it is a separate change:

  • Every rule added to hooks/_lib.sh only protects captures made after it
    ships. Buffers, HANDOFF.md drafts and archived buffer files written before
    the rule still contain whatever leaked then. Nothing today tells an operator
    that a buffer they are about to consolidate contains masked-vs-plaintext
    credentials.
  • The handoff skill already re-scans before writing HANDOFF.md/logs, so the
    hook exists; it just discards the count. Surfacing "N patterns masked in
    buffer/session-X.md, of which M are bare-flag shapes" turns a silent
    historical leak into a visible one.
  • It is a skill-file change (skills/throughline-handoff/SKILL.md, and the
    equivalent re-scan step in the OpenCode/OMP ports), not a hooks/_lib.sh
    change, so it has a different test surface: the hook suite tests scripts, and
    this is agent-instruction text with no harness.

Suggested shape: have the re-scan emit a machine-checkable summary line (counts
by pattern class, never the secret itself) into the handoff run output, and add
a hook-test case asserting the summary is produced by whatever script does the
scan, so the reporting cannot silently vanish.

Do not print matched values or even truncated prefixes of them in the report -
that would move the credential from the buffer into the summary that is meant to
describe it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions