docs(#2775): align package-legitimacy docs to the ADR-0656 registry-API gate (#3010)

* docs(#2775): align package-legitimacy docs to the ADR-0656 registry-API gate

security-model.md, USER-GUIDE.md, ARCHITECTURE.md, COMMANDS.md,
FEATURES.md, and gsd-planner.md's STRIDE template (+ ja-JP mirrors)
described the pre-ADR-0656 design: slopcheck as the install-or-degrade
gate, with unavailability degrading every package to [ASSUMED].
ADR-0656 inverted this months ago — registry-API verdicts (npm/PyPI/
crates.io) are the gate; slopcheck is an optional escalate-only adapter
that no shipped configuration wires. Verified every replacement claim
against src/package-legitimacy.cts (checkPackages, classifyPackage,
lookupNpm/lookupPypi/lookupCrates) via Memtrace before writing it, so
the corrected prose matches the live implementation rather than
restating the ADR from memory.

Restored docs/explanation/security-model.md:79-84 (and its ja-JP
mirror) to original wording after an orthogonal spec review caught
that an earlier draft had edited the "Why WebSearch packages are
always [ASSUMED]" paragraph — inside the range issue #2775 explicitly
named as correct and to leave alone.

The ja-JP mirror was missing the closing clause present in the
corrected English original ("its absence leaves registry-API verdicts
intact rather than downgrading everything to [ASSUMED]") — added for
parity. This completes the ja-JP mirror the issue's acceptance
criteria named explicitly.

zh-CN/ko-KR/pt-BR (not named by #2775, but carrying the same stale
design) get the mechanical portion of the same fix: command-string
swaps, table headers, ARCHITECTURE.md diagram labels, and technical-
term swaps that reuse a word already attested elsewhere in the same
file (合法性/적법성/legitimidade for "legitimacy") — surrounding prose
untouched. The remainder in those three locales — full-paragraph
rewrites of the corrected degrade-path mechanism, deleted "External
dependency" bullets, and "manually install slopcheck" code blocks —
needs prose composed by a fluent speaker of each language and is filed
as open-gsd/gsd-core#3002 with an exact file:line inventory.

* test(#2775): acknowledge gsd-planner.md byte growth from the STRIDE-row fix

agents/gsd-planner.md grew 14 bytes (49309 -> 49323) from the STRIDE
supply-chain row correction (slopcheck -> package-legitimacy gate).
Emitted agent/workflow files are byte-tracked; this fragment
acknowledges the growth per tests/emitted-attribution.test.cjs's
"differential attribution over the real tree" check.

* docs(#2775): close ja-JP FEATURES.md gap; fix a ko-KR transliterated heading

docs/ja-JP/FEATURES.md:2808 still read the katakana transliteration
"スロップチェック verdict" in REQ-PKG-GATE-01 — invisible to a literal
"slopcheck" grep, so it was missed when ja-JP parity was checked and
declared complete. Corrected to "正当性判定" (legitimacy verdict),
matching the term already established in ja-JP/explanation/
security-model.md and ja-JP/USER-GUIDE.md. This was the only
remaining ja-JP gap; a full sweep for the transliterated form across
docs/ja-JP/ now returns zero hits, and the ja-JP mirror is genuinely
at parity.

docs/ko-KR/USER-GUIDE.md:398's heading "슬롭체크 판정:" had the same
transliteration problem. Fixed inline to "적법성 판정:", reusing the
적법성/legitimacy word already attested two lines below in the same
table. A parallel sweep of zh-CN and pt-BR found no transliterated
forms of "slopcheck" in either locale. The remaining transliterated
occurrence in ko-KR (USER-GUIDE.md:406, the lead-in to the
pip-install code block) needs prose composition like the rest of that
block and is added to open-gsd/gsd-core#3002's inventory.

* chore(#2775): backfill changeset PR number to 3010

---------

Co-authored-by: sim <sim@local>
This commit is contained in:
Tom Boucher
2026-08-02 20:24:42 -04:00
committed by GitHub
parent 97f2af29da
commit de78f2eef2
26 changed files with 96 additions and 88 deletions

View File

@@ -0,0 +1,5 @@
---
type: Fixed
pr: 3010
---
**Package-legitimacy docs now match the registry-API gate** — `security-model.md`, `USER-GUIDE.md`, `ARCHITECTURE.md`, `COMMANDS.md`, `FEATURES.md`, and the planner's STRIDE template described the pre-ADR-0656 design (slopcheck as the install-or-degrade gate, unavailability degrading every package to [ASSUMED]). Docs now describe the actual registry-API verdict gate (npm/PyPI/crates.io), with slopcheck as an optional escalate-only adapter. The `ja-JP` mirror is fully aligned, and the mechanical portion of the same drift (command strings, table headers, and already-attested-term swaps) is corrected in the `zh-CN`, `ko-KR`, and `pt-BR` mirrors as well; the prose-composition remainder in those three locales is tracked separately in #3002. (#2775)

View File

@@ -374,7 +374,7 @@ Output: [Artifacts created]
|-----------|----------|-----------|----------|-------------|-----------------|
| T-{phase}-01 | {S/T/R/I/D/E} | {function/endpoint/file} | {critical\|high\|medium\|low} | mitigate | {specific mitigation action} |
| T-{phase}-02 | {category} | {component} | low | accept | {rationale for acceptance} |
| T-{phase}-SC | Tampering | npm/pip/cargo installs | high | mitigate | slopcheck + blocking human checkpoint for [ASSUMED]/[SUS] |
| T-{phase}-SC | Tampering | npm/pip/cargo installs | high | mitigate | package-legitimacy gate + blocking human checkpoint for [ASSUMED]/[SUS] |
</threat_model>
<verification>

View File

@@ -579,7 +579,7 @@ ui-phase → UI-SPEC.md (design contract, optional)
plan-phase
├── Research gate (blocks if RESEARCH.md has unresolved open questions)
├── Phase Researcher → RESEARCH.md
│ └── Package Legitimacy Gate: slopcheck on every package; [SLOP] removed,
│ └── Package Legitimacy Gate: registry-API verdict on every package; [SLOP] removed,
│ [SUS]/[ASSUMED] flagged; Audit table written to RESEARCH.md
├── Planner (with reachability check) → PLAN.md files
│ └── checkpoint:human-verify injected before [ASSUMED]/[SUS] installs;
@@ -845,17 +845,15 @@ The researcher → planner → executor pipeline includes a supply-chain gate ag
| Layer | Component | Action |
|-------|-----------|--------|
| Research | `gsd-phase-researcher` | Runs `slopcheck install <pkgs> --json`; writes `## Package Legitimacy Audit` table to RESEARCH.md; strips `[SLOP]` packages before RESEARCH.md is written |
| Research | `gsd-phase-researcher` | Runs `gsd-tools query package-legitimacy check --ecosystem <npm\|pypi\|crates> <pkgs>`; writes `## Package Legitimacy Audit` table to RESEARCH.md; strips `[SLOP]` packages before RESEARCH.md is written |
| Planning | `gsd-planner` | Reads Audit table; inserts `checkpoint:human-verify` before any `[ASSUMED]` or `[SUS]` install task; adds `T-{phase}-SC` STRIDE supply-chain row to `<threat_model>` |
| Execution | `gsd-executor` | RULE 3 excludes package installation from auto-fix scope; failed installs surface as checkpoints, never silent substitutions |
**Claim provenance integration:** Package names discovered via WebSearch are tagged `[ASSUMED]` (not `[VERIFIED]`) regardless of `npm view` result. This extends the existing `[ASSUMED]` / `[VERIFIED]` / `[CITED]` provenance system by enforcing the provenance tag as a hard gate at the install boundary — `[ASSUMED]` always generates a `checkpoint:human-verify` in PLAN.md.
**Claim provenance integration:** Package names discovered via WebSearch are tagged `[ASSUMED]` (not `[VERIFIED]`) regardless of the registry-API verdict. This extends the existing `[ASSUMED]` / `[VERIFIED]` / `[CITED]` provenance system by enforcing the provenance tag as a hard gate at the install boundary — `[ASSUMED]` always generates a `checkpoint:human-verify` in PLAN.md.
**Ecosystem coverage:** The researcher uses registry-specific verification commands — `npm view` (Node), `pip index versions` (Python), `cargo search` (Rust) — rather than a single generic check. This catches cross-ecosystem hallucination (~9% rate documented in 2025 USENIX research).
**Ecosystem coverage:** The gate resolves signals directly from each ecosystem's registry API rather than a single generic check — `registry.npmjs.org` + `api.npmjs.org/downloads` (Node), `pypi.org/pypi/<pkg>/json` (Python), the crates.io API (Rust). This catches cross-ecosystem hallucination (~9% rate documented in 2025 USENIX research).
**Graceful degradation:** If `slopcheck` is unavailable, every recommended package is tagged `[ASSUMED]` and gated with a checkpoint. Research and planning proceed; the system never hard-fails on a missing tool dependency.
**External dependency:** `slopcheck` (MIT, pip-installable). If abandoned, the `[ASSUMED]`-gate fallback maintains human-checkpoint coverage.
**Graceful degradation:** Each registry adapter degrades to null signals (never throws) on a failed lookup; missing signals push a package to `[SUS]`, which is gated behind the same `checkpoint:human-verify` checkpoint as `[ASSUMED]`. Research and planning proceed; the system never hard-fails on a network or tool outage. `slopcheck` is an optional escalate-only adapter — it can only raise a verdict, never lower it, and is not the install-or-degrade gate. No shipped configuration wires it.
---

View File

@@ -227,13 +227,13 @@ Research, plan, and verify a phase.
- With `--view`: print existing RESEARCH.md to stdout, no spawn. Errors if RESEARCH.md missing.
**Package Legitimacy Gate (v1.42.1):**
When the researcher recommends external packages, it runs `slopcheck install <pkg> --json` on each one and writes a `## Package Legitimacy Audit` table to RESEARCH.md recording Registry, Age, Downloads, Source Repo, and slopcheck verdict. Verdicts:
When the researcher recommends external packages, it runs `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkg>` on each one and writes a `## Package Legitimacy Audit` table to RESEARCH.md recording Registry, Age, Downloads, Source Repo, and legitimacy verdict. Verdicts are computed from live registry APIs (npm, PyPI, crates.io):
- `[SLOP]` — package removed from RESEARCH.md entirely; never reaches the planner
- `[SUS]` — package flagged; planner inserts `checkpoint:human-verify` before the install task
- `[OK]` — package approved; no checkpoint added
Packages sourced from WebSearch are tagged `[ASSUMED]` (not `[VERIFIED]`) and treated the same as `[SUS]` — they get a human checkpoint before install. If `slopcheck` cannot be installed, every recommended package is tagged `[ASSUMED]` and gated.
Packages sourced from WebSearch are tagged `[ASSUMED]` (not `[VERIFIED]`) and treated the same as `[SUS]` — they get a human checkpoint before install. A failed registry lookup degrades to `[SUS]` rather than throwing, so it is gated, not silently accepted. `slopcheck` is an optional escalate-only adapter that no shipped configuration wires; it is not required for the gate to function.
See [Package Legitimacy Gate in the User Guide](USER-GUIDE.md#package-legitimacy-gate-v1421) for the full checkpoint format, verdict table, and troubleshooting.

View File

@@ -2899,7 +2899,7 @@ Source commit: abc1234 (3 commits behind HEAD)
- Executor install failures stop for human verification instead of auto-trying similarly named packages.
**Requirements:**
- REQ-PKG-GATE-01: Research MUST record package registry, age, download/source signals, slopcheck verdict, and disposition.
- REQ-PKG-GATE-01: Research MUST record package registry, age, download/source signals, legitimacy verdict, and disposition.
- REQ-PKG-GATE-02: Planner MUST gate unverified or suspicious package installs before execution.
- REQ-PKG-GATE-03: Executor MUST NOT auto-substitute package names after failed package-manager installs.

View File

@@ -412,8 +412,8 @@ AI coding tools hallucinate package names. Attackers pre-register those names on
```markdown
## Package Legitimacy Audit
| Package | Registry | Age | Downloads | Source Repo | slopcheck | Disposition |
|---------|----------|-----|-----------|-------------|-----------|-------------|
| Package | Registry | Age | Downloads | Source Repo | Verdict | Disposition |
|---------|----------|-----|-----------|-------------|---------|-------------|
| express | npm | 13 yrs | 100M+/wk | github.com/expressjs/express | [OK] | Approved |
| some-new-util | npm | 3 days | 47 | none | [SLOP] | REMOVED |
| api-bridge | npm | 6 mo | 1.2k/wk | github.com/user/api-bridge | [SUS] | Flagged |
@@ -425,7 +425,7 @@ AI coding tools hallucinate package names. Attackers pre-register those names on
**During execution** — if an install fails, the executor surfaces a checkpoint and stops rather than silently trying an alternative.
**Slopcheck verdicts:**
**Legitimacy verdicts:**
| Verdict | Meaning | GSD action |
|---------|---------|------------|
@@ -433,12 +433,10 @@ AI coding tools hallucinate package names. Attackers pre-register those names on
| `[SUS]` | Suspicious signals | Flagged; planner adds `checkpoint:human-verify` |
| `[SLOP]` | High-confidence hallucination | Removed from RESEARCH.md; never reaches planner |
To install slopcheck manually:
```bash
pip install slopcheck
# verify: slopcheck install express --json
```
Verdicts are computed from live registry APIs (npm, PyPI, crates.io) — there
is no separate tool to install. `slopcheck` is an optional escalate-only
adapter (it can raise a verdict but never lower one); no shipped
configuration wires it, and its absence does not change the gate's behavior.
---

View File

@@ -54,11 +54,15 @@ researcher → planner → executor pipeline and eventually run as
The gate operates across three pipeline stages:
**Research stage.** When `gsd-phase-researcher` recommends external packages,
it runs `slopcheck install <pkgs> --json` against each one. The results are
written to a `## Package Legitimacy Audit` table in `RESEARCH.md`. Packages
tagged `[SLOP]` (high-confidence hallucination or attacker-registered) are
**stripped from `RESEARCH.md` entirely** before the file is saved. They never
reach the planner.
it runs `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates>
<pkgs>` against each one. Verdicts (`OK|SUS|SLOP`) are computed from live
registry APIs against thresholds `{ minAgeDays: 30, minWeeklyDownloads: 1000,
requireRepo: true }`, plus terminal short-circuits for non-existence and
suspicious `postinstall` scripts. The results are written to a `## Package
Legitimacy Audit` table in `RESEARCH.md`. Packages tagged `[SLOP]`
(high-confidence hallucination or attacker-registered) are **stripped from
`RESEARCH.md` entirely** before the file is saved. They never reach the
planner.
**Planning stage.** `gsd-planner` reads the Audit table. For any package
tagged `[SUS]` (suspicious: newly registered, low download count, no source
@@ -85,12 +89,13 @@ gets a human review before installation.
### Ecosystem coverage
The researcher uses registry-specific verification commands rather than a
single generic check:
The gate resolves signals directly from each ecosystem's registry API rather
than a single generic check:
- Node.js: `npm view`
- Python: `pip index versions`
- Rust: `cargo search`
- Node.js: `registry.npmjs.org` (age, repository URL, `postinstall` script)
plus `api.npmjs.org/downloads` (weekly downloads)
- Python: `pypi.org/pypi/<pkg>/json` (age, repository URL)
- Rust: the crates.io API (age, weekly downloads, repository URL)
This covers cross-ecosystem hallucination, which occurs at roughly 9 %
according to 2025 USENIX research — cases where an AI recommends a package
@@ -98,17 +103,18 @@ that exists in one ecosystem but not the one actually in use.
### Graceful degradation
If `slopcheck` is unavailable (not installed, or the pip install fails at
research time), GSD applies the strictest possible fallback: **every
recommended package is tagged `[ASSUMED]`**, and the planner gates every
install with a `checkpoint:human-verify` task. Research and planning proceed
normally — the system never hard-fails on a missing tool dependency. This
is intentionally stricter than the normal flow: slopcheck unavailability means
every package install gets a human checkpoint.
Each registry adapter has a 5-second timeout and returns degraded (all-null)
signals on a failed lookup rather than throwing. Missing signals surface as
`unknown-age` / `unknown-downloads` reasons, which push a package to `[SUS]`
— and `[SUS]` is gated behind the same `checkpoint:human-verify` task as
`[ASSUMED]`. The gate fails toward human review, not silence, and research
and planning proceed normally: nothing here hard-fails on a network or tool
outage.
The `slopcheck` tool is MIT-licensed and pip-installable. If it is ever
abandoned, the `[ASSUMED]`-gate fallback ensures human-checkpoint coverage is
maintained regardless.
`slopcheck` is an optional adapter that can only escalate a verdict, never
lower it, and is not the install-or-degrade gate. No shipped configuration
wires it; its absence leaves registry-API verdicts intact rather than
downgrading everything to `[ASSUMED]`.
---
@@ -242,9 +248,9 @@ attack.
**What the Package Legitimacy Gate does not eliminate:** A legitimate package
that is later compromised (account takeover, dependency confusion in its own
tree) is not caught by slopcheck, which checks registration signals at
research time. Lock files and `npm audit` at the dependency-integrity layer
are the controls for that class of attack.
tree) is not caught by the registry-API gate, which checks registration
signals at research time. Lock files and `npm audit` at the
dependency-integrity layer are the controls for that class of attack.
**What the prompt injection defences reduce:** The probability that
user-controlled text in planning artifacts successfully overrides agent

View File

@@ -375,7 +375,7 @@ ui-phase → UI-SPEC.md (design contract, optional)
plan-phase
├── Research gate (blocks if RESEARCH.md has unresolved open questions)
├── Phase Researcher → RESEARCH.md
│ └── Package Legitimacy Gate: slopcheck on every package; [SLOP] removed,
│ └── Package Legitimacy Gate: registry-API verdict on every package; [SLOP] removed,
│ [SUS]/[ASSUMED] flagged; Audit table written to RESEARCH.md
├── Planner (with reachability check) → PLAN.md files
│ └── checkpoint:human-verify injected before [ASSUMED]/[SUS] installs;
@@ -598,7 +598,7 @@ Runtime Engine (Claude Code / Gemini CLI)
| レイヤー | コンポーネント | アクション |
|-------|-----------|--------|
| 調査 | `gsd-phase-researcher` | `slopcheck install <pkgs> --json` を実行;`## Package Legitimacy Audit` テーブルを RESEARCH.md に書き込む;RESEARCH.md が書かれる前に `[SLOP]` パッケージを除去 |
| 調査 | `gsd-phase-researcher` | `gsd-tools query package-legitimacy check --ecosystem <npm\|pypi\|crates> <pkgs>` を実行;`## Package Legitimacy Audit` テーブルを RESEARCH.md に書き込む;RESEARCH.md が書かれる前に `[SLOP]` パッケージを除去 |
| 計画 | `gsd-planner` | 監査テーブルを読み取る;任意の `[ASSUMED]` または `[SUS]` インストールタスクの前に `checkpoint:human-verify` を挿入;`<threat_model>` に `T-{phase}-SC` STRIDE サプライチェーン行を追加 |
| 実行 | `gsd-executor` | RULE 3 はパッケージインストールを自動修正スコープから除外;失敗したインストールはチェックポイントとして表面化し、サイレントな代替なし |

View File

@@ -185,13 +185,13 @@ GSD ワークスペースを管理 — リポジトリコピーと独立した `
- `--view` 付き: 既存の RESEARCH.md を標準出力に表示し、起動なし。RESEARCH.md がない場合はエラー。
**パッケージ正当性ゲート(v1.42.1):**
リサーチャーが外部パッケージを推奨する場合、各パッケージに対して `slopcheck install <pkg> --json` を実行し、Registry、Age、Downloads、Source Repo、および slopcheck の評決を記録した `## Package Legitimacy Audit` テーブルを RESEARCH.md に書き込みます。評決:
リサーチャーが外部パッケージを推奨する場合、各パッケージに対して `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkg>` を実行し、Registry、Age、Downloads、Source Repo、および正当性評決を記録した `## Package Legitimacy Audit` テーブルを RESEARCH.md に書き込みます。評決はライブのレジストリ API(npm、PyPI、crates.io)から計算されます:
- `[SLOP]` — パッケージは RESEARCH.md から完全に削除され、プランナーには届かない
- `[SUS]` — パッケージにフラグが付けられ、プランナーはインストールタスクの前に `checkpoint:human-verify` を挿入
- `[OK]` — パッケージが承認され、チェックポイントは追加されない
WebSearch から取得したパッケージは `[ASSUMED]`(`[VERIFIED]` ではない)とタグ付けされ、`[SUS]` と同様に扱われます — インストール前に人間によるチェックポイントが設けられます。`slopcheck` がインストールできない場合、すべての推奨パッケージは `[ASSUMED]` とタグ付けされ、ゲートが設けられます。
WebSearch から取得したパッケージは `[ASSUMED]`(`[VERIFIED]` ではない)とタグ付けされ、`[SUS]` と同様に扱われます — インストール前に人間によるチェックポイントが設けられます。レジストリルックアップが失敗した場合はスローせず `[SUS]` にデグレードされるため、サイレントに承認されることはありません。`slopcheck` はオプションのエスカレート専用アダプターであり、出荷される設定では配線されていません。ゲートの動作に必須ではありません。
詳細については、[ユーザーガイドのパッケージ正当性ゲート](../USER-GUIDE.md#package-legitimacy-gate-v1421)(チェックポイント形式、評決テーブル、トラブルシューティングを含む)を参照してください。

View File

@@ -2805,7 +2805,7 @@ Source commit: abc1234 (3 commits behind HEAD)
- Executor のインストール失敗は、同様の名前のパッケージを自動的に試みる代わりに人間の確認のために停止する。
**要件:**
- REQ-PKG-GATE-01: リサーチはパッケージレジストリ、年齢、ダウンロード/ソースシグナル、スロップチェック verdict、および処分を記録しなければならない。
- REQ-PKG-GATE-01: リサーチはパッケージレジストリ、年齢、ダウンロード/ソースシグナル、正当性判定、および処分を記録しなければならない。
- REQ-PKG-GATE-02: プランナーは実行前に未検証または疑わしいパッケージのインストールをゲートしなければならない。
- REQ-PKG-GATE-03: Executor はパッケージマネージャーのインストール失敗後にパッケージ名を自動置換してはならない。

View File

@@ -382,8 +382,8 @@ AI コーディングツールはパッケージ名を幻覚することがあ
```markdown
## Package Legitimacy Audit
| Package | Registry | Age | Downloads | Source Repo | slopcheck | Disposition |
|---------|----------|-----|-----------|-------------|-----------|-------------|
| Package | Registry | Age | Downloads | Source Repo | Verdict | Disposition |
|---------|----------|-----|-----------|-------------|---------|-------------|
| express | npm | 13 yrs | 100M+/wk | github.com/expressjs/express | [OK] | Approved |
| some-new-util | npm | 3 days | 47 | none | [SLOP] | REMOVED |
| api-bridge | npm | 6 mo | 1.2k/wk | github.com/user/api-bridge | [SUS] | Flagged |
@@ -395,7 +395,7 @@ AI コーディングツールはパッケージ名を幻覚することがあ
**実行中** — インストールが失敗した場合、エグゼキューターはチェックポイントを提示して停止し、代替案をサイレントに試みません。
**スロップチェックの判定:**
**正当性の判定:**
| 判定 | 意味 | GSD のアクション |
|---------|---------|------------|
@@ -403,12 +403,7 @@ AI コーディングツールはパッケージ名を幻覚することがあ
| `[SUS]` | 疑わしいシグナル | フラグ付き; プランナーが `checkpoint:human-verify` を追加 |
| `[SLOP]` | 高確信度の幻覚 | RESEARCH.md から削除; プランナーに到達しない |
slopcheck を手動でインストールするには:
```bash
pip install slopcheck
# verify: slopcheck install express --json
```
判定はライブのレジストリ API(npm、PyPI、crates.io)から計算されます — 個別にインストールするツールはありません。`slopcheck` はオプションのエスカレート専用アダプター(判定を引き上げることはできますが、引き下げることはできません)です。出荷される設定はこれを配線しておらず、その不在によってゲートの動作が変わることはありません。
---

View File

@@ -24,7 +24,7 @@ AI モデルはパッケージ名を幻覚します。これはまれな失敗
ゲートは 3 つのパイプラインステージにわたって動作します:
**調査ステージ。** `gsd-phase-researcher` が外部パッケージを推奨するとき、それぞれに対して `slopcheck install <pkgs> --json` を実行します。結果は `RESEARCH.md` の `## Package Legitimacy Audit` テーブルに書き込まれます。`[SLOP]`(高信頼度の幻覚または攻撃者登録済み)とタグ付けされたパッケージは、ファイルが保存される前に **`RESEARCH.md` から完全に除去されます**。それらはプランナーに届きません。
**調査ステージ。** `gsd-phase-researcher` が外部パッケージを推奨するとき、それぞれに対して `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkgs>` を実行します。評決(`OK|SUS|SLOP`)はライブのレジストリ API から、しきい値 `{ minAgeDays: 30, minWeeklyDownloads: 1000, requireRepo: true }` に基づいて計算され、非存在および疑わしい `postinstall` スクリプトに対する終端ショートサーキットも含まれます。結果は `RESEARCH.md` の `## Package Legitimacy Audit` テーブルに書き込まれます。`[SLOP]`(高信頼度の幻覚または攻撃者登録済み)とタグ付けされたパッケージは、ファイルが保存される前に **`RESEARCH.md` から完全に除去されます**。それらはプランナーに届きません。
**計画ステージ。** `gsd-planner` は監査テーブルを読み取ります。`[SUS]`(疑わしい:新規登録、低ダウンロード数、ソースリポジトリなし、または人気パッケージに近い命名パターン)または `[ASSUMED]`(直接レジストリ検証ではなく WebSearch から取得)とタグ付けされたパッケージについて、プランナーはインストールステップの前に **`checkpoint:human-verify` タスクを挿入します**。チェックポイントにはレジストリページへの直接リンクと、確認すべき具体的な事項が含まれます:メンテナー履歴、イシュートラッカーの活動、疑わしいインストールスクリプトがないこと。
@@ -36,19 +36,19 @@ WebSearch を通じて発見されたパッケージ名は、`npm view` が成
### エコシステムカバレッジ
調査者は単一の汎用チェックではなく、レジストリ固有の検証コマンドを使います:
ゲートは単一の汎用チェックではなく、各エコシステムのレジストリ API から直接シグナルを解決します:
- Node.js:`npm view`
- Python:`pip index versions`
- Rust:`cargo search`
- Node.js:`registry.npmjs.org`(登録日、リポジトリ URL、`postinstall` スクリプト)と `api.npmjs.org/downloads`(週間ダウンロード数)
- Python:`pypi.org/pypi/<pkg>/json`(登録日、リポジトリ URL)
- Rust:crates.io API(登録日、週間ダウンロード数、リポジトリ URL)
これは 2025 年の USENIX 研究によると約 9% の割合で発生するクロスエコシステム幻覚をカバーします——AI が実際に使用しているエコシステムには存在しない別のエコシステムのパッケージを推奨するケース。
### グレースフルデグレデーション
`slopcheck` が利用できない場合(インストールされていない、または調査時に pip インストールが失敗した)、GSD は可能な限り厳格なフォールバックを適用します:**すべての推奨パッケージが `[ASSUMED]` とタグ付けされ**、プランナーはすべてのインストールを `checkpoint:human-verify` タスクでゲートします。調査と計画は通常どおり進行します——システムはツールの依存関係の欠落でハードフェイルすることはありません。これは通常フローより意図的に厳格です:slopcheck の利用不可は、すべてのパッケージインストールに人間のチェックポイントを付与することを意味します。
各レジストリアダプターには 5 秒のタイムアウトがあり、失敗したルックアップに対しては例外をスローせずデグレードされた(すべて null の)シグナルを返します。欠落したシグナルは `unknown-age` / `unknown-downloads` の理由として現れ、パッケージを `[SUS]` に押し上げます——そして `[SUS]` は `[ASSUMED]` と同じ `checkpoint:human-verify` タスクでゲートされます。ゲートはサイレントにではなく人間のレビューに向かって失敗し、調査と計画は通常どおり進行します:ネットワークやツールの障害でハードフェイルすることはありません。
`slopcheck` ツールは MIT ライセンスで pip インストール可能です。廃止された場合でも、`[ASSUMED]` ゲートフォールバックにより、人間チェックポイントカバレッジが維持されます。
`slopcheck` はオプションのアダプターであり、評決をエスカレートすることしかできず(引き下げることはできません)、インストールまたはデグレードのゲートではありません。出荷される設定はこれを配線しません。その不在は、すべてを `[ASSUMED]` に格下げするのではなく、レジストリ API の評決をそのまま維持します。
---
@@ -99,7 +99,7 @@ GSD のランタイム動作の上流で、`open-gsd` 組織はリポジトリ
**パッケージ正当性ゲートが低減するもの:** 幻覚されたまたは攻撃者登録済みのパッケージが人間のチェックポイントなしに `npm install` に届く確率。`[SLOP]` ゲートは高信頼度の悪質なパッケージを完全に除去します;`[SUS]`/`[ASSUMED]` ゲートは実行前に人間のレビューを要求します。これによりスロップスクワッティング攻撃の成功コストが実質的に引き上げられます。
**パッケージ正当性ゲートが排除しないもの:** 後で侵害された正規パッケージ(アカウント乗っ取り、そのパッケージ自体のツリーでの依存関係混同)は、調査時に登録シグナルを確認する slopcheck ではキャッチされません。その種の攻撃に対するコントロールは、依存関係整合性レイヤーのロックファイルと `npm audit` です。
**パッケージ正当性ゲートが排除しないもの:** 後で侵害された正規パッケージ(アカウント乗っ取り、そのパッケージ自体のツリーでの依存関係混同)は、調査時に登録シグナルを確認するレジストリ API ゲートではキャッチされません。その種の攻撃に対するコントロールは、依存関係整合性レイヤーのロックファイルと `npm audit` です。
**プロンプトインジェクション防御が低減するもの:** 計画アーティファクト内のユーザー制御テキストがエージェントの指示を正常に上書きする確率。既知のインジェクション形式のパターンマッチングは一般的なケースをキャッチします;新しいジェイルブレイクや低シグナルのインジェクションは検出されない可能性があります。アドバイザリーのみの姿勢は、検出がログに記録されるがブロックされないことを意味します——検出でハード停止するコストではなく、ワークフロー継続性を保持する意図的な選択。

View File

@@ -413,7 +413,7 @@ ui-phase → UI-SPEC.md (디자인 계약, 선택적)
plan-phase
├── 리서치 게이트 (RESEARCH.md에 미해결 공개 질문이 있으면 차단)
├── 단계 리서처 → RESEARCH.md
│ └── 패키지 적법성 게이트: 모든 패키지에 slopcheck; [SLOP] 제거,
│ └── 패키지 적법성 게이트: 모든 패키지에 대한 레지스트리 API 판정; [SLOP] 제거,
│ [SUS]/[ASSUMED] 플래그; 감사 테이블을 RESEARCH.md에 작성
├── 플래너 (도달 가능성 검사 포함) → PLAN.md 파일
│ └── [ASSUMED]/[SUS] 설치 전에 checkpoint:human-verify 삽입;
@@ -656,7 +656,7 @@ UI-SPEC.md (단계별) ───────────────────
| 계층 | 컴포넌트 | 동작 |
|-------|-----------|--------|
| 리서치 | `gsd-phase-researcher` | `slopcheck install <pkgs> --json` 실행; `## Package Legitimacy Audit` 테이블을 RESEARCH.md에 작성; RESEARCH.md가 작성되기 전에 `[SLOP]` 패키지 제거 |
| 리서치 | `gsd-phase-researcher` | `gsd-tools query package-legitimacy check --ecosystem <npm\|pypi\|crates> <pkgs>` 실행; `## Package Legitimacy Audit` 테이블을 RESEARCH.md에 작성; RESEARCH.md가 작성되기 전에 `[SLOP]` 패키지 제거 |
| 계획 | `gsd-planner` | 감사 테이블 읽기; `[ASSUMED]` 또는 `[SUS]` 설치 작업 전에 `checkpoint:human-verify` 삽입; `<threat_model>`에 `T-{phase}-SC` STRIDE 공급망 행 추가 |
| 실행 | `gsd-executor` | RULE 3은 패키지 설치를 자동 수정 범위에서 제외; 실패한 설치는 체크포인트로 표시되며 절대 자동 대체하지 않음 |

View File

@@ -185,7 +185,7 @@ GSD 워크스페이스 관리 — 리포지토리 복사본과 독립적인 `.pl
- `--view` 사용: 기존 RESEARCH.md를 stdout으로 출력, 생성 없음. RESEARCH.md가 없으면 오류 발생.
**패키지 적법성 게이트 (v1.42.1):**
리서처가 외부 패키지를 추천하면 각 패키지에 대해 `slopcheck install <pkg> --json`을 실행하고 레지스트리, 출시일, 다운로드 수, 소스 리포지토리, slopcheck 판정이 담긴 `## Package Legitimacy Audit` 테이블을 RESEARCH.md에 작성합니다. 판정:
리서처가 외부 패키지를 추천하면 각 패키지에 대해 `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkg>`을 실행하고 레지스트리, 출시일, 다운로드 수, 소스 리포지토리, 적법성 판정이 담긴 `## Package Legitimacy Audit` 테이블을 RESEARCH.md에 작성합니다. 판정:
- `[SLOP]` — 패키지가 RESEARCH.md에서 완전히 제거; 계획자에게 전달되지 않음
- `[SUS]` — 패키지 플래그 지정; 계획자가 설치 작업 전에 `checkpoint:human-verify` 삽입

View File

@@ -382,8 +382,8 @@ AI 코딩 도구는 패키지 이름을 환각합니다. 공격자는 npm, PyPI,
```markdown
## Package Legitimacy Audit
| Package | Registry | Age | Downloads | Source Repo | slopcheck | Disposition |
|---------|----------|-----|-----------|-------------|-----------|-------------|
| Package | Registry | Age | Downloads | Source Repo | Verdict | Disposition |
|---------|----------|-----|-----------|-------------|---------|-------------|
| express | npm | 13 yrs | 100M+/wk | github.com/expressjs/express | [OK] | Approved |
| some-new-util | npm | 3 days | 47 | none | [SLOP] | REMOVED |
| api-bridge | npm | 6 mo | 1.2k/wk | github.com/user/api-bridge | [SUS] | Flagged |
@@ -395,7 +395,7 @@ AI 코딩 도구는 패키지 이름을 환각합니다. 공격자는 npm, PyPI,
**실행 중** — 설치가 실패하면 실행자는 체크포인트를 표시하고 자동으로 대안을 시도하지 않고 중단합니다.
**슬롭체크 판정:**
**적법성 판정:**
| 판정 | 의미 | GSD 조치 |
|---------|---------|------------|

View File

@@ -30,7 +30,7 @@ AI 모델은 패키지 이름을 환각한다. 이것은 변두리 실패 모드
게이트는 세 가지 파이프라인 단계에 걸쳐 작동한다:
**리서치 단계.** `gsd-phase-researcher`가 외부 패키지를 추천할 때 각 패키지에 대해 `slopcheck install <pkgs> --json`을 실행한다. 결과는 `RESEARCH.md`의 `## Package Legitimacy Audit` 테이블에 작성된다. `[SLOP]`로 태그된 패키지들(높은 신뢰도의 환각 또는 공격자가 등록)은 파일이 저장되기 전에 **`RESEARCH.md`에서 완전히 제거된다**. 이런 패키지들은 절대 플래너에게 도달하지 않는다.
**리서치 단계.** `gsd-phase-researcher`가 외부 패키지를 추천할 때 각 패키지에 대해 `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkgs>`을 실행한다. 결과는 `RESEARCH.md`의 `## Package Legitimacy Audit` 테이블에 작성된다. `[SLOP]`로 태그된 패키지들(높은 신뢰도의 환각 또는 공격자가 등록)은 파일이 저장되기 전에 **`RESEARCH.md`에서 완전히 제거된다**. 이런 패키지들은 절대 플래너에게 도달하지 않는다.
**계획 단계.** `gsd-planner`는 감사 테이블을 읽는다. `[SUS]`(의심스러움: 최근 등록, 낮은 다운로드 수, 소스 저장소 없음, 또는 인기 있는 패키지와 가까운 명명 패턴)나 `[ASSUMED]`(직접 레지스트리 검증이 아닌 WebSearch에서 출처)로 태그된 모든 패키지에 대해, 플래너는 설치 단계 전에 **`checkpoint:human-verify` 작업을 삽입한다**. 체크포인트에는 레지스트리 페이지로의 직접 링크와 살펴봐야 할 구체적인 항목들이 포함된다: 유지관리자 이력, 이슈 트래커 활동, 의심스러운 설치 스크립트의 부재.

View File

@@ -428,7 +428,7 @@ ui-phase → UI-SPEC.md (contrato de design, opcional)
plan-phase
├── Portão de pesquisa (bloqueia se RESEARCH.md tiver perguntas abertas não resolvidas)
├── Pesquisador de Fase → RESEARCH.md
│ └── Portão de Legitimidade de Pacotes: slopcheck em cada pacote; [SLOP] removido,
│ └── Portão de Legitimidade de Pacotes: veredicto da API de registro em cada pacote; [SLOP] removido,
│ [SUS]/[ASSUMED] sinalizados; tabela de Auditoria escrita no RESEARCH.md
├── Planner (com verificação de alcançabilidade) → arquivos PLAN.md
│ └── checkpoint:human-verify injetado antes de instalações [ASSUMED]/[SUS];
@@ -687,7 +687,7 @@ O pipeline pesquisador → planner → executor inclui um portão de cadeia de s
| Camada | Componente | Ação |
|--------|------------|------|
| Pesquisa | `gsd-phase-researcher` | Executa `slopcheck install <pkgs> --json`; escreve tabela `## Package Legitimacy Audit` no RESEARCH.md; remove pacotes `[SLOP]` antes de o RESEARCH.md ser escrito |
| Pesquisa | `gsd-phase-researcher` | Executa `gsd-tools query package-legitimacy check --ecosystem <npm\|pypi\|crates> <pkgs>`; escreve tabela `## Package Legitimacy Audit` no RESEARCH.md; remove pacotes `[SLOP]` antes de o RESEARCH.md ser escrito |
| Planejamento | `gsd-planner` | Lê a tabela de Auditoria; insere `checkpoint:human-verify` antes de qualquer tarefa de instalação `[ASSUMED]` ou `[SUS]`; adiciona linha STRIDE `T-{phase}-SC` supply-chain ao `<threat_model>` |
| Execução | `gsd-executor` | REGRA 3 exclui a instalação de pacotes do escopo de correção automática; instalações com falha surgem como checkpoints, nunca substituições silenciosas |

View File

@@ -185,7 +185,7 @@ Pesquisa, planeja e verifica uma fase.
- Com `--view`: imprime o RESEARCH.md existente no stdout, sem criar agente. Apresenta erro se RESEARCH.md estiver ausente.
**Portão de Legitimidade de Pacotes (v1.42.1):**
Quando o pesquisador recomenda pacotes externos, executa `slopcheck install <pkg> --json` em cada um e escreve uma tabela `## Package Legitimacy Audit` no RESEARCH.md com os campos Registry, Age, Downloads, Source Repo e veredicto do slopcheck. Veredictos:
Quando o pesquisador recomenda pacotes externos, executa `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkg>` em cada um e escreve uma tabela `## Package Legitimacy Audit` no RESEARCH.md com os campos Registry, Age, Downloads, Source Repo e veredicto de legitimidade. Veredictos:
- `[SLOP]` — pacote removido do RESEARCH.md completamente; nunca chega ao planejador
- `[SUS]` — pacote sinalizado; o planejador insere `checkpoint:human-verify` antes da tarefa de instalação

View File

@@ -382,8 +382,8 @@ Ferramentas de codificação com IA alucinam nomes de pacotes. Atacantes pré-re
```markdown
## Package Legitimacy Audit
| Package | Registry | Age | Downloads | Source Repo | slopcheck | Disposition |
|---------|----------|-----|-----------|-------------|-----------|-------------|
| Package | Registry | Age | Downloads | Source Repo | Verdict | Disposition |
|---------|----------|-----|-----------|-------------|---------|-------------|
| express | npm | 13 yrs | 100M+/wk | github.com/expressjs/express | [OK] | Approved |
| some-new-util | npm | 3 days | 47 | none | [SLOP] | REMOVED |
| api-bridge | npm | 6 mo | 1.2k/wk | github.com/user/api-bridge | [SUS] | Flagged |
@@ -395,7 +395,7 @@ Pacotes com `[SLOP]` são removidos do RESEARCH.md inteiramente e nunca chegam a
**Durante a execução** — se uma instalação falhar, o executor apresenta um checkpoint e para em vez de tentar silenciosamente uma alternativa.
**Veredictos do slopcheck:**
**Veredictos de legitimidade:**
| Veredicto | Significado | Ação do GSD |
|---------|---------|------------|

View File

@@ -56,7 +56,7 @@ pesquisador → planejador → executor do GSD e eventualmente seria executado c
A barreira opera em três estágios do pipeline:
**Estágio de pesquisa.** Quando `gsd-phase-researcher` recomenda pacotes
externos, executa `slopcheck install <pkgs> --json` para cada um. Os resultados
externos, executa `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkgs>` para cada um. Os resultados
são gravados em uma tabela `## Package Legitimacy Audit` no `RESEARCH.md`.
Pacotes marcados com `[SLOP]` (alucinação de alta confiança ou registrado por
atacante) são **removidos inteiramente do `RESEARCH.md`** antes de o arquivo
@@ -229,7 +229,7 @@ bem-sucedido.
**O que o Package Legitimacy Gate não elimina:** Um pacote legítimo que é
comprometido posteriormente (tomada de conta, confusão de dependências em sua
própria árvore) não é detectado pelo slopcheck, que verifica sinais de registro
própria árvore) não é detectado pelo portão da API de registro, que verifica sinais de registro
no momento da pesquisa. Lock files e `npm audit` na camada de integridade de
dependências são os controles para essa classe de ataque.

View File

@@ -413,7 +413,7 @@ ui-phase → UI-SPEC.md (design contract, optional)
plan-phase
├── Research gate (blocks if RESEARCH.md has unresolved open questions)
├── Phase Researcher → RESEARCH.md
│ └── Package Legitimacy Gate: slopcheck on every package; [SLOP] removed,
│ └── Package Legitimacy Gate: registry-API verdict on every package; [SLOP] removed,
│ [SUS]/[ASSUMED] flagged; Audit table written to RESEARCH.md
├── Planner (with reachability check) → PLAN.md files
│ └── checkpoint:human-verify injected before [ASSUMED]/[SUS] installs;
@@ -655,7 +655,7 @@ Runtime Engine (Claude Code / Gemini CLI)
| 层次 | 组件 | 操作 |
|-------|-----------|--------|
| 研究 | `gsd-phase-researcher` | 运行 `slopcheck install <pkgs> --json`;向 RESEARCH.md 写入 `## Package Legitimacy Audit` 表格;在写入 RESEARCH.md 之前剥离 `[SLOP]` 软件包 |
| 研究 | `gsd-phase-researcher` | 运行 `gsd-tools query package-legitimacy check --ecosystem <npm\|pypi\|crates> <pkgs>`;向 RESEARCH.md 写入 `## Package Legitimacy Audit` 表格;在写入 RESEARCH.md 之前剥离 `[SLOP]` 软件包 |
| 规划 | `gsd-planner` | 读取审计表;在任何 `[ASSUMED]` 或 `[SUS]` 安装任务之前插入 `checkpoint:human-verify`;向 `<threat_model>` 添加 `T-{phase}-SC` STRIDE 供应链行 |
| 执行 | `gsd-executor` | 规则 3 将软件包安装排除在自动修复范围之外;失败的安装以检查点形式呈现,而非静默替换 |

View File

@@ -185,7 +185,7 @@ v1.40 中,六个命名空间路由器作为第一阶段入口点随附发布
- 加 `--view`:将现有 RESEARCH.md 打印到标准输出,不生成新报告。RESEARCH.md 不存在时报错。
**包合法性检查门(v1.42.1):**
当研究者推荐外部包时,会对每个包运行 `slopcheck install <pkg> --json` 并在 RESEARCH.md 中写入 `## Package Legitimacy Audit` 表格,记录注册表、年龄、下载量、源码仓库和 slopcheck 裁决。裁决结果:
当研究者推荐外部包时,会对每个包运行 `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkg>` 并在 RESEARCH.md 中写入 `## Package Legitimacy Audit` 表格,记录注册表、年龄、下载量、源码仓库和合法性裁决。裁决结果:
- `[SLOP]` — 包从 RESEARCH.md 中完全移除,永远不会进入规划器
- `[SUS]` — 包被标记;规划器在安装任务前插入 `checkpoint:human-verify`

View File

@@ -2821,7 +2821,7 @@ Source commit: abc1234 (3 commits behind HEAD)
- 执行器安装失败会暂停进行人工验证,而不是自动尝试类似命名的包。
**需求:**
- REQ-PKG-GATE-01:研究必须记录包注册表、年龄、下载/来源信号、slopcheck 判决和处置。
- REQ-PKG-GATE-01:研究必须记录包注册表、年龄、下载/来源信号、合法性判决和处置。
- REQ-PKG-GATE-02:规划器必须在执行前门控未验证或可疑的包安装。
- REQ-PKG-GATE-03:执行器在包管理器安装失败后不得自动替换包名。

View File

@@ -381,8 +381,8 @@ AI 编码工具会幻觉出包名。攻击者会在 npm、PyPI 和 crates.io 上
```markdown
## Package Legitimacy Audit
| Package | Registry | Age | Downloads | Source Repo | slopcheck | Disposition |
|---------|----------|-----|-----------|-------------|-----------|-------------|
| Package | Registry | Age | Downloads | Source Repo | Verdict | Disposition |
|---------|----------|-----|-----------|-------------|---------|-------------|
| express | npm | 13 yrs | 100M+/wk | github.com/expressjs/express | [OK] | Approved |
| some-new-util | npm | 3 days | 47 | none | [SLOP] | REMOVED |
| api-bridge | npm | 6 mo | 1.2k/wk | github.com/user/api-bridge | [SUS] | Flagged |
@@ -394,7 +394,7 @@ AI 编码工具会幻觉出包名。攻击者会在 npm、PyPI 和 crates.io 上
**执行期间** — 如果安装失败,执行器会显示检查点并停止,而不是静默尝试替代方案。
**Slopcheck 判定:**
**合法性判定:**
| 判定 | 含义 | GSD 操作 |
|---------|---------|------------|

View File

@@ -24,7 +24,7 @@ Slopsquatting 的隐蔽之处在于,通过 `npm view` 验证的幻觉名称*
门控机制跨三个流水线阶段运行:
**研究阶段。** 当 `gsd-phase-researcher` 推荐外部软件包时,它会对每个软件包运行 `slopcheck install <pkgs> --json`。结果会以 `## Package Legitimacy Audit` 表格的形式写入 `RESEARCH.md`。标记为 `[SLOP]`(高置信度幻觉或攻击者注册)的软件包在保存前会**从 `RESEARCH.md` 中完全删除**,永远不会到达规划员。
**研究阶段。** 当 `gsd-phase-researcher` 推荐外部软件包时,它会对每个软件包运行 `gsd-tools query package-legitimacy check --ecosystem <npm|pypi|crates> <pkgs>`。结果会以 `## Package Legitimacy Audit` 表格的形式写入 `RESEARCH.md`。标记为 `[SLOP]`(高置信度幻觉或攻击者注册)的软件包在保存前会**从 `RESEARCH.md` 中完全删除**,永远不会到达规划员。
**规划阶段。** `gsd-planner` 读取审计表。对于任何标记为 `[SUS]`(可疑:新注册、下载量低、无源代码仓库,或命名模式接近某热门软件包)或 `[ASSUMED]`(来自 WebSearch 而非直接注册表验证)的软件包,规划员会在安装步骤之前**插入一个 `checkpoint:human-verify` 任务**。该检查点包含指向注册表页面的直接链接,以及需要重点核查的内容:维护者历史、问题跟踪器活动、是否存在可疑的安装脚本。

View File

@@ -0,0 +1,6 @@
{
"version": 1,
"paths": {
"gsd-planner.md": "#2775: the STRIDE supply-chain row for npm/pip/cargo installs was rewritten from 'slopcheck + blocking human checkpoint for [ASSUMED]/[SUS]' to 'package-legitimacy gate + blocking human checkpoint for [ASSUMED]/[SUS]', matching ADR-0656 (registry-API verdicts are the gate; slopcheck is an optional escalate-only adapter no shipped configuration wires). The +14 bytes is the corrected mitigation description agents read at plan time, not incidental prose growth."
}
}