T09 · Insecure Skill Coding Practices
- Location
scripts/engine.py:180- Finding
Micro-Initiation Cadence Controls Are Not Persisted
- Content
View full analysis
None: """Log a micro-initiation send.""" now = datetime.now(timezone.utc).isoformat() if "sends" not in self.micro_state: self.micro_state["sends"] = [] self.micro_state["sends"].append(now) if "pool_history" not in self.micro_state: self.micro_state["pool_history"] = {} if pool_name not in self.micro_state["pool_history"]: self.micro_state["pool_history"][pool_name] = [] self.micro_state["pool_history"][pool_name].append(now) ``` ### Technical Analysis The engine calls `should_send_micro_initiation()` to enforce the documented weekly and no-repeat limits, but it never calls `MicroInitiations.log_send()` after creating the scheduled message. Logging the message to `ContextBuffer` does not update `micro_state.json`, whi ...[truncated 1982 chars]- Remediation
View remediation
None: self.micro_initiations.log_send(pool_name, message) self.context_buffer.log_message("micro_initiation", {}, message) ``` 3. If delivery confirmation cannot be implemented, atomically reserve a cadence slot before returning the message and roll it back on delivery failure. 4. Pass the actual daily regular-alert count to `should_send_micro_initiation()`: ```python alert_count = self.context_buffer.context.get("sent_count", 0) allowed = self.micro_initiations.should_send_micro_initiation(alert_count) ``` 5. Make cadence checking and state updates atomic to prevent concurrent polling tasks from passing the check simultaneously. 6. Add tests covering weekly limits, fourteen-day repeat suppression, busy-day suppression, process restarts, concurrent checks, and delivery failures. ]]>
