T09 · Insecure Skill Coding Practices
- Location
scripts/todo-cleaner.py:72- Finding
Cancelled Todo Records Are Not Deleted After the Documented Retention Period
- Content
View full analysis
- Remediation
View remediation
'), 'terminal_at': terminal_at_str, 'error': str(e), }) to_keep.append(item) ``` Additional hardening should include: 1. Add tests for expired and recent `completed` records. 2. Add tests for expired and recent `cancelled` records. 3. Validate that each terminal status has its corresponding timestamp. 4. Report malformed terminal records clearly without deleting them silently. 5. Restrict permissions on `memory/todo.json` because its descriptions and context may contain sensitive user information. ]]>
