fix(tests): allowlist execute-phase.md in prompt-injection scan (#1835)

execute-phase.md grew to ~51K chars after the code-review gate step
was added in #1630, tripping the 50K size heuristic in the injection
scanner. The limit is calibrated for user-supplied input — trusted
workflow source files that legitimately exceed it are allowlisted
individually, following the same pattern as discuss-phase.md.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-04-05 20:03:47 -04:00
committed by GitHub
parent 99c089bfbf
commit 95eda5845e

View File

@@ -52,6 +52,7 @@ const SCAN_EXTS = new Set(['.md', '.cjs', '.js', '.json']);
const ALLOWLIST = new Set([
'get-shit-done/bin/lib/security.cjs', // The security module itself
'get-shit-done/workflows/discuss-phase.md', // Large workflow (~50K) with power mode + i18n
'get-shit-done/workflows/execute-phase.md', // Large orchestration workflow (~51K) with wave execution + code-review gate
'hooks/gsd-prompt-guard.js', // The prompt guard hook
'tests/security.test.cjs', // Security tests
'tests/prompt-injection-scan.test.cjs', // This file