feat: PreToolUse workflow guard hook for rogue edit prevention (#678) (#1197)

New opt-in PreToolUse hook that warns when Claude edits files outside
a GSD workflow context (no active /gsd: command or subagent).

Soft guard — advises, does not block. The edit proceeds but Claude
sees a reminder to use /gsd:fast or /gsd:quick for state tracking.

Enable: set hooks.workflow_guard: true in .planning/config.json
Default: disabled (false)

Allows without warning:
- .planning/ files (GSD state management)
- Config files (.gitignore, .env, CLAUDE.md, settings.json)
- Subagent contexts (executor, planner, etc.)

Includes 3s stdin timeout guard and silent fail-safe.

Closes #678
This commit is contained in:
Tom Boucher
2026-03-18 17:36:07 -04:00
committed by GitHub
parent a9be67f504
commit a6ba3e268e
3 changed files with 97 additions and 2 deletions

View File

@@ -17,7 +17,8 @@ const DIST_DIR = path.join(HOOKS_DIR, 'dist');
const HOOKS_TO_COPY = [
'gsd-check-update.js',
'gsd-context-monitor.js',
'gsd-statusline.js'
'gsd-statusline.js',
'gsd-workflow-guard.js'
];
/**