Static board · Read-only. Open an entry ID to inspect its Markdown source. Regenerate with /board-view after the board changes.
Search and filters apply to entry cards. Ranked investigations and their evidence remain visible.
eb-self
0 open · 90 totalPattern intelligence
rule v1 · score is not confidenceRanked systemic investigations
useful resurfacing confirmed systemic fixes hypotheses with outcomes
No multi-entry clusters are present.
To do 0
—
Review 0
—
Validate 0
—
Done 82
B001P1
SessionStart O(n^2) blocked_by loop exceeds 10s timeout on large boards
hooks/scripts/board-session-start.sh
B002P1
Injection reject-blocklist is trivially bypassable; payloads promote to live board
hooks/scripts/board-consolidate.sh
B003P1
Adversarial/benign fixtures are dead code; ARCHITECTURE claims a reject-rate guarantee
tests/smoke/automated.sh
B004P1
Permission allowlist does not cover the scripts the hooks actually invoke
references/required-permissions.json
B005P2
First captured finding is invisible — buried in _sessions/, only a count shown
hooks/stop-hook-procedure.md
B006P2
Advancing one entry through tdd->review->validate requires two session restarts
commands/worker-start.md
B008P2
Corrupt/truncated session-mode.json silently un-pauses a paused session
hooks/scripts/board-stop-gate.sh
B009P2
Consolidator silently no-ops (findings lost) when python3 is broken/absent
hooks/scripts/board-consolidate.sh
+ 72 more resolved
ARCHITECTURE.md is stale for 1.2.0 (version header, MCP server absent, wrong script/suite counts)
ARCHITECTURE.md
B014P2
Two implementations of scratch->live promotion with no stated canonical engine
agents/consolidator.md
Internal milestone jargon (M2.2.c) leaks into user-facing command output
commands/board-install-permissions.md
Version sprawl across surfaces; no authoritative version signal
references/required-permissions.json
pattern recurrence threshold is inconsistent (2+ vs >=3) across three surfaces
skills/board-intake/SKILL.md
code-reviewer name collides with /code-review and its tools contradict its read-only contract
agents/code-reviewer.md
B023P2
board-index-check invariant is defeated by the resolve-in-place convention
hooks/scripts/board-index-check.sh
B024P0
MCP path traversal via project name writes files outside the repo root
mcp-server/engineering_board_mcp.py
B025P1
Reject filter bypassed by a polite/adverb lead-in before the imperative verb
hooks/scripts/board_reject_check.py
B026P1
MCP-captured scratch findings are silently destroyed on consolidate
mcp-server/engineering_board_mcp.py
B027P1
README Quickstart dead-ends at board-init; capture-promote-fix path is undiscoverable
README.md
B028P2
MCP serialize_frontmatter does not escape newlines; field values can inject keys
mcp-server/engineering_board_mcp.py
B029P2
claim-acquire self-deletes its lock on a session_id containing whitespace
hooks/scripts/board-claim-acquire.sh
B030P2
Permission-install delivery is a 6-step copy-paste loop, undiscoverable from onboarding
commands/board-install-permissions.md
worker-start unsupported-discipline error leaks a version number to the user
commands/worker-start.md
B034P0
MCP entry_id path traversal in board_claim/board_release (arbitrary create + rm -rf)
mcp-server/engineering_board_mcp.py
B035P1
MCP bulk tools bypass router-row containment (arbitrary BOARD.md overwrite + cross-root read)
mcp-server/engineering_board_mcp.py
B037P1
Reject filter bypassed by markdown list/blockquote markers before the verb
hooks/scripts/board_reject_check.py
B038P1
MCP affects_prefix injects a BOARD-ROUTER row (control-file corruption + bulk DoS + project spoof)
mcp-server/engineering_board_mcp.py
B039P2
MCP board_init follows symlinks to write scaffold outside root
mcp-server/engineering_board_mcp.py
MCP board_capture_finding title/kind not flattened (scratch header injection + count spoof)
mcp-server/engineering_board_mcp.py
RFC 0002 stale command count + missing /board-view verdict
docs/rfcs/0002-surface-product-review.md
Landing page did not surface /board-view and still conceded the visualization gap it closed
docs/index.html
B043P1
Reject filter bypassed by Unicode bullets, markdown headings, line separators
hooks/scripts/board_reject_check.py
MCP board_capture_finding evidence field injects scratch headers (count spoof)
mcp-server/engineering_board_mcp.py
B046P1
Permission rules emitted without Tool(...) wrapper; self-check reports a false green
commands/board-install-permissions.md
worker->pm refusal hint points to a dead-end (/board-resume no-ops from worker mode)
hooks/scripts/board-mode-guard.sh
B051P1
Reject filter line-separator folding incomplete (CR/VT/FF/FS/GS/RS)
hooks/scripts/board_reject_check.py
consolidate promotion writer flattens only evidence_quote, not title/affects/tags
hooks/scripts/board-consolidate.sh
B053P1
Reject filter misses non-ASCII sentence terminators as clause boundaries
hooks/scripts/board_reject_check.py
B054P2
MCP board_capture_finding evidence blockquote splits on \n only (CR/FF/NEL forge a header)
mcp-server/engineering_board_mcp.py
README "rendered live by /board-view" link points at a raw .html blob (GitHub shows source)
README.md
B056P2
Reject terminator fold incomplete (Arabic comma/semicolon, Armenian, Tibetan, Khmer, Mongolian, ...)
hooks/scripts/board_reject_check.py
count_scratch_findings undercounts multi-finding scratch-append blocks
mcp-server/engineering_board_mcp.py
B058P1
Reject filter invisible-char strip is a hand-list; the Cf/default-ignorable class splits verbs
hooks/scripts/board_reject_check.py
B059P1
Reject filter skip-run misses ordered/lettered/checkbox list markers
hooks/scripts/board_reject_check.py
Slash-directive regex misses a slash abutting a marker/quote/paren
hooks/scripts/board_reject_check.py
B061P2
Reject filter strips Unicode tag chars for its scan but promotes them raw (ASCII smuggling)
hooks/scripts/board_reject_check.py
B063P2
board_context silently returns no guidance for task-only requests
mcp-server/engineering_board_core.py
B065P2
Promotion provenance collides when a daily MCP scratch file is recreated
mcp-server/engineering_board_core.py
B066P2
board_context rejects the safe repository-relative cwd '.'
mcp-server/engineering_board_core.py
B067P2
GitHub Actions forces actions/checkout v4 from deprecated Node.js 20 onto Node.js 24
.github/workflows/
B068P2
board-consolidate apply instructions omit the session selector required by session-scoped plans
skills/board-consolidate/SKILL.md
B069P2
Resolved entries append below older archive rows despite newest-first contract
mcp-server/engineering_board_mcp.py
B070P2
Fresh Codex marketplace installs mutable main under a released version label
.agents/plugins/marketplace.json
B071P2
Codex auto-loads Claude hook adapters that require CLAUDE_PROJECT_DIR
.codex-plugin/plugin.json
B072P2
Codex skips the prompt Stop hook and reports failure after every turn
.codex-plugin/plugin.json
B073P2
SessionStart counts BOARD convention examples as open entries
hooks/scripts/board-session-start.sh
B074P2
Self-hosted claim locks dirty the repository because runtime board paths are not ignored
.gitignore
B075P2
Authoritative current-behavior table describes superseded graph context and outcome limitations
docs/PRODUCT_EVOLUTION_SPEC.md
B077P2
Codex exec cancels read-only board tools while MCP schemas omit approval annotations
mcp-server/engineering_board_mcp.py
B078P2
Claude strict plugin validation rejects the ignored marketplace policy field
.claude-plugin/marketplace.json
F002P2
Onboarding wizard (/board-setup) that collapses install->value to one step
commands/board-setup.md
Surface matched Learnings at the moment of need (session summary + viewer panel)
hooks/stop-hook-procedure.md
No entries match the current search and filters.
Learnings · durable memory
A denylist heuristic is never done — assume every pattern has an adjacent bypass
applies to: hooks/scripts/board_reject_check.py, tests/security/
The newest surface carries the most risk — red-team it hardest
applies to: mcp-server/
Fix an input-handling class across every site at once, not one site per cycle
applies to: hooks/scripts/board_reject_check.py, hooks/scripts/board-consolidate.sh, mcp-server/engineering_board_mcp.py
Ship every deterministic guard with a test that drives its real fixtures and call-sites
applies to: hooks/scripts/, tests/, references/
Board health invariants must respect the open-vs-resolved entry lifecycle
applies to: hooks/scripts/board-index-check.sh, hooks/scripts/board-session-start.sh
Questions · Observations
- Q001 question Does driving one board from Claude Code + Claude Desktop simultaneously work, and what breaks?
- Q002 question Does current D.1 version 4 context change cross-incident diagnosis?
- Q003 question Does context presentation prevent cross-incident first causes?
Stats
- bugs 0 open · 78 resolved
- features 0 open · 4 resolved
- questions 0 open · 3 resolved
- learnings 5
Coordination
Claims
- no active claims
Recent reclaims
- no recent reclaims
Active workers
- no active workers