Integration & Security Audit Report (2025-12-27)
Executive Summary
This audit reviewed the current repo state for correctness, integration completeness, and production safety. The highest-severity finding was the presence of real API keys and credentials committed directly in the repository (runtime config defaults, Cloud Build configs, VS Code settings, and an archived env file). This is a critical security issue requiring immediate secret rotation.
We also found integration drift around the REWOO endpoint (stale boss-agent-adk references) and a TypeScript interface mismatch in the frontend Cloud Run registry client that would cause type errors.
This patchset removes leaked secrets, fixes REWOO routing defaults, and repairs the TS orchestrator registry types.
Critical Findings (Fixed)
1) Secrets committed to repo (CRITICAL)
Impact - If this repository is accessible to anyone beyond a tightly controlled internal group, the exposed keys should be treated as compromised. - Even in private repos, secrets in git history are high-risk (forks, logs, CI artifacts).
Where it was found
- Runtime config defaults in:
- src/cells/cell03/v2/config.py
- src/shared/model_config.py
- src/agents/adk/config.py
- miz-oki-adk-agents/moa/config.py
- miz-oki-adk-agents/moe/config.py
- Cloud Build config with inline keys:
- mcp/cloudbuild-custom.yaml
- VS Code client settings:
- mcp/clients/vscode.settings.json
- Archived env file containing live keys:
- archive/legacy_archive/_archive_2025-11-19/archived/MOA-Of-coding-agents-ARCHIVED-20251003/local-config.env
- Legacy docs mentioning credential values:
- docs/legacy/claudememory.md
- docs/legacy/README_MD_Documents.md
Fix applied
- Removed all hardcoded key defaults (defaults are now empty strings).
- Deleted the archived env file containing secrets.
- Converted mcp/cloudbuild-custom.yaml to use Secret Manager (--set-secrets) rather than embedding keys.
- Updated mcp/clients/vscode.settings.json to pull keys from the environment.
- Redacted sensitive credential values in legacy docs.
Required follow-up (NOT optional)
- Rotate/revoke all keys that were committed:
- Anthropic / OpenAI / Gemini / xAI keys
- Neo4j passwords (and any other DB creds)
- If this repo is public or ever leaked, strongly consider purging git history:
- Use git filter-repo (or equivalent) to remove secret blobs from history
- Force-push and invalidate all old references
2) Insecure placeholder Neo4j password defaults (HIGH)
Issue
- Several services defaulted NEO4J_PASSWORD to "password", which can lead to accidental insecure deployments or confusing failures.
Fix applied
- Updated these defaults to "" in:
- services/predictions_api/app/main.py
- services/graph_writer/app/main.py
- jobs/kg_heartbeat/main.py
- services/mizoki-journey-kg/predictions-api/neo4j_client.py
- services/mizoki-journey-kg/graph-writer/writer.py
- (plus two archived legacy files)
3) REWOO URL drift (MEDIUM)
Issue
- Multiple places referenced boss-agent-adk for REWOO (/api/v1/rewoo) while the current architecture centers boss-agent-adk.
Fix applied
- Standardized REWOO URL references to:
- https://boss-agent-adk-698171499447.us-central1.run.app/api/v1/rewoo
- Updated in:
- env.production.yaml
- miz-oki-command-center-ui/env.production.yaml
- miz-oki-command-center-ui/env.production.example
- miz-oki-command-center-ui/cloudbuild.yaml
- miz-oki-command-center-ui/lib/api/config.ts
- miz-oki-command-center-ui/config/boss_agent_capabilities.json
- miz-oki-adk-agents/config/cell_registry.json
- verification + ops scripts under scripts/
4) Frontend TypeScript orchestrator registry mismatch (MEDIUM)
Issue
- miz-oki-command-center-ui/lib/cloud-run-client.ts declared orchestrator keys (bossAgentAdk, bossAgentUnified) that didn’t match the actual config object (bossAgentV5), causing type-level breakage.
Fix applied
- Updated types and the public API to use consistent keys:
- bossAgentV5 | bossRewoo | moaController | moeRouter
Known Shortcomings (Not fully addressed)
Next.js runtime env vs build-time NEXT_PUBLIC_*
Cloud Run deploy-time environment variables do not automatically propagate into already-built client bundles. If the UI requires dynamic per-deploy values in the browser, you need one of:
- Build-time injection (Docker build args) for NEXT_PUBLIC_* values
- A runtime config endpoint pattern (server reads env; client fetches /api/config)
This repo currently mixes both patterns in different places.
How to Publish These Fixes to GitHub main
This environment cannot push to GitHub directly. Recommended workflow:
- Create a branch:
-
git checkout -b fix/security-scrub-and-rewoo - Commit changes:
-
git add -A-git commit -m "security: remove committed secrets; fix REWOO URL drift; repair TS registry" - Push and open PR:
-
git push origin fix/security-scrub-and-rewoo - After merge, rotate all secrets and confirm services are still healthy.