Files
roboco/docs/rag/standards/python-security.md
T
879afc14a4 Board Program LEARN context, ruff 0.16, and verb-rejection observability (#700)
* fix(board): LEARN decisions name the item, not its per-cycle index

A cycle's reject reasons are rendered into the NEXT cycle's exploration
prompt, but the ref recorded alongside each reason was the item's stored
id (item-0/item-1) — a per-cycle index that means something different
every cycle and appears nowhere the explorer can resolve. The reason
survived the loop; what it was about did not.

Record the item's title instead, via a shared learn_ref() helper (falls
back to the id when title-less, and reads target_task_title for Scales,
whose items name the live task they mutate).

* chore(lint): satisfy ruff 0.16 — keyword-only signatures and markdown formatting

The dev toolchain resolved ruff 0.16.0, which stabilises PLR0917 (too many
positional arguments) and formats python code blocks inside markdown. Both
fired repo-wide and neither had anything to do with the code they flagged.

- 36 signatures gain a `*` so their tail arguments are keyword-only, and
  the 104 call sites that passed them positionally are converted. mypy was
  the safety net for the static ones; the full suite caught nine more that
  only bind at runtime (the MCP tool functions, whose real callers already
  pass named JSON arguments).
- 28 markdown files reformatted by 0.16's code-block formatter.
- One RUF036 (`None` mid-union) autofixed in the GitLab provider.

* fix(gateway): log the reason when a verb rejects

A rejected envelope rides an HTTP 200, its body is never logged, and there
is no trace table — so in the access log a verb an agent could not satisfy
looks identical to one that worked. On 2026-07-25 four Board Programs
(Periscope, Sentinel, Scales, Barfly) each POSTed their propose verb three
or four times, persisted nothing, and left their exploration tasks PENDING;
the reason was unrecoverable afterwards, from the logs or from the agents'
own transcripts.

Log error/message/remediate/missing plus the calling agent at
envelope_to_response — the one chokepoint every v1 flow and do route
returns through. Success envelopes stay silent.

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
2026-07-26 15:07:28 +02:00

1.4 KiB

Python Security Standards

No Hardcoded Secrets

NEVER hardcode secrets:

# Bad - NEVER
API_KEY = "sk-abc123xyz789"
DATABASE_URL = "postgresql://user:password@host/db"

# Good - environment variables
from pydantic_settings import BaseSettings


class Settings(BaseSettings):
    api_key: str
    database_url: str
    model_config = {"env_prefix": "ROBOCO_"}

SQL Injection Prevention

NEVER use string concatenation for SQL:

# Bad - SQL injection vulnerability
query = f"SELECT * FROM users WHERE id = '{user_id}'"

# Good - parameterized query
result = await session.execute(select(User).where(User.id == user_id))

Command Injection Prevention

NEVER pass user input directly to shell:

# Bad - command injection
import os

os.system(f"process_file {filename}")

# Good - use subprocess with list
import subprocess

subprocess.run(["process_file", filename], check=True)

No eval() or exec()

NEVER use on untrusted input:

# Bad - code injection
result = eval(user_input)

# Good - safe parsing
import ast

result = ast.literal_eval(user_input)  # Only literals

Non-Security Hashes

When hashing for non-security purposes:

import hashlib

content_hash = hashlib.md5(
    content.encode(),
    usedforsecurity=False,  # Required flag
).hexdigest()[:12]

Security Tools

Run before merge:

# Security scan
uv run bandit -r roboco/ -ll

# Dependency audit
uv run pip-audit