# Production Review — Remaining Items Output of the multi-agent production review (security / Python / TypeScript / performance / architecture / code-quality). Each entry below is something the original audit flagged and the autonomous hardening pass deliberately did **not** address — either because it needs design input, profiling validation, or a multi-day refactor that should land in its own session. The hardening pass landed everything else: see git log between `master` and the head of the review branch for the applied changes (URL-scheme + malicious-input rejection, IconSelect XSS escape, MiniSelect for forbidden plain `