793 B
793 B
Security and Privacy Rules
These rules are mandatory for both script mode and compatibility mode.
Scope Control
- Operate only under
working_directory. - Do not read, move, or write files outside
working_directory. - Do not follow symlinks when scanning report files.
Data Minimization
- Read only report files matching:
YYYY-MM-DD-<TICKER>-analysis.mdYYYY-MM-DD-<TICKER>-analysis-vN.md
- Parse only required metadata fields.
- Cap historical reads:
- script mode default: 5 files
- compatibility mode: 3 files
Script Safety
- Scripts are local-file utilities only; no network calls.
- Migration is explicit and non-destructive:
- move only user-confirmed files
- skip when target already exists
- If a safety check fails, return
blockedwith reason.