Skip to content

Work System: issue-creation pipeline has zero PII redaction — prompts and TELOS goal text land in issues verbatim #1825

Description

@PaulWaldo

What I found

The Work System's issue-creation pipeline pushes personal content into issue titles/bodies with no redaction anywhere:

  • hooks/ReminderRouter.hook.ts — pastes the original user prompt verbatim into the issue body on every reminder/research/queue capture.
  • LIFEOS/TOOLS/WorkSweep.ts::sweepSessions — embeds principal_stated_goal from session frontmatter verbatim.
  • LIFEOS/TOOLS/WorkSweep.ts::sweepGoals — reads TELOS ## Active Goals and creates one issue per goal with the full goal text verbatim (financial, health, or otherwise sensitive goal content included).

Grepped WorkSweep.ts, ReminderRouter.hook.ts, and hooks/lib/work-config.ts for redact|scrub|denylist|pii — no matches. There's no boundary-level filter anywhere before content reaches the configured issue repo.

Why it matters

Whatever host WORK.REPO points at (GitHub, or per #1816 any future backend), once an issue is created its content is effectively permanent — closing an issue doesn't delete its title/body; removing content requires a separate deliberate admin action on both GitHub and Forgejo/Gitea. So this isn't a "fix it later" risk — anything sensitive that lands in an issue before the gap closes stays there.

Proposal

Two different content problems, two different fixes:

  • Unpredictable free text (ReminderRouter's prompt capture, sweepSessions's principal_stated_goal) needs a boundary-level redaction filter — one chokepoint right before any issue-creating call, pattern-matching for PII (dollar amounts, account-like numbers, health/financial terms) — analogous to LifeOS's own Daemon skill SecurityFilter used for its public-profile export.
  • Deliberate TELOS exports (sweepGoals) need a source-level opt-out, not redaction — scrubbing a goal like "retire in 2-3 years with financial security" would destroy the reason it's useful. A per-goal sync: false-style flag in TELOS, or simply not exporting goals by default, fits better.

Happy to put up a PR for the redaction-filter half if that's a direction you'd take a contribution on.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions