@@ -166,7 +166,16 @@ Output mapping requirement: Populate these fields in current_task_metadata for d
166166
167167** ⚠️ Risk Analysis:**
168168- Validate that potential risks are properly identified and addressed
169- - Required risk categories to consider: OAuth/authentication misconfiguration, insecure cookie/session settings, CSRF vulnerabilities, open redirect attacks, session fixation, secret leakage, database migration failures, XSS from external data, dependency vulnerabilities, rate limiting absence, environment mismatches
169+ - Required risk categories to consider:
170+ - ** Security risks** : Authentication/authorization vulnerabilities, data exposure, input validation gaps, session management issues, dependency vulnerabilities, configuration security
171+ - ** Performance degradation** : Memory leaks, inefficient algorithms, database query performance, resource exhaustion
172+ - ** Breaking changes** : API compatibility issues, backward compatibility problems, migration path failures
173+ - ** Code maintainability** : Technical debt accumulation, tight coupling, SOLID principle violations, architectural degradation
174+ - ** System reliability** : Error handling gaps, race conditions, concurrent access issues, failure recovery problems
175+ - ** Data integrity** : Inconsistent state management, validation gaps, data corruption risks
176+ - ** User experience** : Response time degradation, accessibility regressions, usability issues
177+ - ** Testing coverage** : Reduced test coverage, flaky tests, missing edge cases, test maintenance issues
178+ - ** Documentation drift** : Outdated documentation, missing API docs, unclear error messages
170179- Are identified risks realistic and comprehensive?
171180- Do mitigation strategies adequately address the risks (one-to-one mapping)?
172181- Does the plan include appropriate safeguards and rollback mechanisms?
0 commit comments