Outcome
Authorized task text reaches the selected model without semantic changes introduced by diagnostic redaction, while public/logging surfaces continue to protect sensitive data. This advances Model Router's Objective by making delegated instructions reliable across harnesses.
Evidence and Elon decision
Source audit of main7e64edf found that core._durable_run redacts prompt and direction-block metadata before persistence, then the OpenCode supervisor sends that stored prompt as execution input. Patterns resembling password assignments or authorization examples can therefore change the model's instructions. Codex command arguments follow a different storage path. This is a source-confirmed behavior, not a demonstrated secret exposure or a measured production incident.
Question the coupling between execution input and sanitized diagnostics. Separate their purposes at the smallest existing boundary. Do not remove secret protection globally, create another transcript store, or rewrite the harness seam.
Acceptance criteria
Non-goals
Broad security redesign, credential migration, new logging/storage systems, changing subscriptions, or deployment/install. No live credentials or raw private transcripts in tests or GitHub artifacts.
Blocked by
None for a synthetic reproduction and bounded design. Not dispatched as part of the current two implementation jobs; prioritize after the demonstrated recovery failures.
Required proof
Use synthetic strings through the actual prompt-to-supervisor seam and public serialization path. Assert exact model input and independently sanitized output, unchanged private permissions, supported harness compatibility and full project proof. Independent exact-candidate review required.
Related architecture audit and recovery work: #87.
Outcome
Authorized task text reaches the selected model without semantic changes introduced by diagnostic redaction, while public/logging surfaces continue to protect sensitive data. This advances Model Router's Objective by making delegated instructions reliable across harnesses.
Evidence and Elon decision
Source audit of main7e64edf found that core._durable_run redacts prompt and direction-block metadata before persistence, then the OpenCode supervisor sends that stored prompt as execution input. Patterns resembling password assignments or authorization examples can therefore change the model's instructions. Codex command arguments follow a different storage path. This is a source-confirmed behavior, not a demonstrated secret exposure or a measured production incident.
Question the coupling between execution input and sanitized diagnostics. Separate their purposes at the smallest existing boundary. Do not remove secret protection globally, create another transcript store, or rewrite the harness seam.
Acceptance criteria
Non-goals
Broad security redesign, credential migration, new logging/storage systems, changing subscriptions, or deployment/install. No live credentials or raw private transcripts in tests or GitHub artifacts.
Blocked by
None for a synthetic reproduction and bounded design. Not dispatched as part of the current two implementation jobs; prioritize after the demonstrated recovery failures.
Required proof
Use synthetic strings through the actual prompt-to-supervisor seam and public serialization path. Assert exact model input and independently sanitized output, unchanged private permissions, supported harness compatibility and full project proof. Independent exact-candidate review required.
Related architecture audit and recovery work: #87.