# Tasks: single-react-mysql-readonly-tool ## 1. Security prerequisite and dependency - [x] 1.1 Add JSqlParser 4.6 and record the locked parser version. - [x] 1.2 Make `scripts/query_mysql.py` environment-only and read-only; remove commit and unsafe interactive paths. ## 2. SQL policy and allowlist model - [x] 2.1 Implement immutable data-source/allowlist/limit models and validated query plan. - [x] 2.2 Implement JSqlParser single-SELECT validator, identifier resolution, function/wildcard/join policy and placeholder count checks. - [x] 2.3 Add parser and allowlist security fixtures for accepted/rejected SQL. ## 3. JDBC executor and projection - [x] 3.1 Implement read-only PreparedStatement executor with timeout, max rows, Run cancellation and safe error mapping. - [x] 3.2 Implement `MysqlResultProjector` with row/cell/byte bounds, redaction, JSON-safe values and `NO_EVIDENCE`. - [x] 3.3 Add isolated executor/projector tests for valid rows, empty rows, truncation, sensitive columns and timeout/cancel behavior. ## 4. ToolBoundary adapter and verification - [x] 4.1 Implement typed MySQL adapter through the existing ToolBoundary and canonical invocation store. - [x] 4.2 Add adapter tests proving exact framework ID, raw isolation, validation-before-execution and safe errors. - [x] 4.3 Run focused compile/tests, validate OpenSpec, update devflow evidence, archive and commit before stage 4.