enhance(#3085): add Grep to allowed-tools for 21 skills (#4397)

* enhance(#3085): add Grep to allowed-tools for 21 skills

29 of 71 skills omit Grep from allowed-tools, forcing Bash grep for
structured search instead of the dedicated tool. Adds Grep to the
21-skill subset confirmed safe in prior review (excludes the 6
gsd-ns-* dispatchers, gsd-help, and gsd-surface, which have no
plausible structured-search need).

Hand-edits commands/gsd/*.md only; skills/*/SKILL.md is regenerated
via `npm run gen:plugin-skills` from that source. Updates the one
hardcoded copilot-install test assertion affected by gsd-health's
new tool order.

* chore(#3085): backfill changeset PR number

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test(#2618): assert the Needs clause on the structured field, not the path-length-dependent bullet

The bullet embeds the todo file's ABSOLUTE path, so its total length
varies by runner tmpdir: on macOS CI, /private/var/folders/… plus the
test harness's gsd-test-run-* wrapper pushed the full bullet to 244
chars — past renderPendingTodoBullet's intended 240-char cap, whose
documented first degradation step drops the Needs clause. The product
behavior is correct (#2618 design); the assertion was runner-dependent.
The extraction is now pinned on json.todos[0].needs; the rendered-bullet
shape stays covered by the path-independent title assertion and the
renderer's own unit rows.

Found blocking #4186's CI on the macOS shard (test landed 30 minutes
earlier in b7406b293f / PR #4384).

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-09-06 13:37:47 -04:00
committed by GitHub
parent b7917882bb
commit ed133cc116
45 changed files with 61 additions and 3 deletions

View File

@@ -0,0 +1,6 @@
---
type: Changed
pr: 4397
---
<!-- docs-exempt: internal tool-grant correction to skill frontmatter; no file under docs/ enumerates per-skill allowed-tools (verified against docs/ARCHITECTURE.md, docs/AGENTS.md, and docs/adr/) so there is nothing to update -->
**21 GSD skills now declare `Grep` in `allowed-tools`** — cleanup, complete-milestone, config, debug, graphify, health, mempalace-capture, mempalace-recall, new-milestone, new-project, next, pause-work, phase, pr-branch, resume-work, review-backlog, settings, stats, thread, workspace, and workstreams can now use the dedicated structured-search tool instead of shelling out through Bash grep.

View File

@@ -5,6 +5,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
requires: [phase]
---

View File

@@ -7,6 +7,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
requires: [audit-milestone, discuss-phase, execute-phase, new-milestone, phase, plan-phase, stats, update]
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
requires: [code-review, review, settings]
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- Agent
- AskUserQuestion
---

View File

@@ -5,6 +5,7 @@ argument-hint: "[build|query <term>|status|diff]"
allowed-tools:
- Read
- Bash
- Grep
requires: [config, fast, phase, update]
---

View File

@@ -5,6 +5,7 @@ argument-hint: "[--repair] [--context]"
allowed-tools:
- Read
- Bash
- Grep
- Write
- AskUserQuestion
requires: [thread]

View File

@@ -5,6 +5,7 @@ argument-hint: "[CONTEXT.md|PLAN.md|SUMMARY.md]"
allowed-tools:
- Read
- Bash
- Grep
requires: [config]
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
requires: [config]
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- Agent
- AskUserQuestion
requires: [new-project, phase, plan-phase]

View File

@@ -5,6 +5,7 @@ argument-hint: "[--auto]"
allowed-tools:
- Read
- Bash
- Grep
- Write
- Agent
- AskUserQuestion

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Bash
- Glob
- Grep
- SlashCommand
- AskUserQuestion
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
requires: [phase, progress]
---

View File

@@ -7,6 +7,7 @@ allowed-tools:
- Write
- Bash
- Glob
- Grep
---
<objective>

View File

@@ -4,6 +4,7 @@ description: Create a clean PR branch by filtering out .planning/ commits — re
argument-hint: "[target branch, default: main]"
allowed-tools:
- Bash
- Grep
- Read
- AskUserQuestion
requires: [review]

View File

@@ -4,6 +4,7 @@ description: Resume work from previous session with full context restoration
allowed-tools:
- Read
- Bash
- Grep
- Write
- AskUserQuestion
- SlashCommand

View File

@@ -5,6 +5,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
requires: [phase, review]
---

View File

@@ -5,6 +5,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
requires: [quick]
---

View File

@@ -5,6 +5,7 @@ effort: low
allowed-tools:
- Read
- Bash
- Grep
requires: [phase, progress]
---
<objective>

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
requires: [phase]
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
---

View File

@@ -4,6 +4,7 @@ description: Manage parallel workstreams — list, create, switch, status, progr
allowed-tools:
- Read
- Bash
- Grep
requires: [new-milestone, phase, progress, resume-work]
---

View File

@@ -5,6 +5,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- Agent
- AskUserQuestion
---

View File

@@ -5,6 +5,7 @@ argument-hint: "[build|query <term>|status|diff]"
allowed-tools:
- Read
- Bash
- Grep
---

View File

@@ -5,6 +5,7 @@ argument-hint: "[--repair] [--context]"
allowed-tools:
- Read
- Bash
- Grep
- Write
- AskUserQuestion
---

View File

@@ -5,6 +5,7 @@ argument-hint: "[CONTEXT.md|PLAN.md|SUMMARY.md]"
allowed-tools:
- Read
- Bash
- Grep
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- Agent
- AskUserQuestion
---

View File

@@ -5,6 +5,7 @@ argument-hint: "[--auto]"
allowed-tools:
- Read
- Bash
- Grep
- Write
- Agent
- AskUserQuestion

View File

@@ -5,6 +5,7 @@ allowed-tools:
- Read
- Bash
- Glob
- Grep
- SlashCommand
- AskUserQuestion
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
---

View File

@@ -7,6 +7,7 @@ allowed-tools:
- Write
- Bash
- Glob
- Grep
---

View File

@@ -4,6 +4,7 @@ description: "Create a clean PR branch by filtering out .planning/ commits — r
argument-hint: "[target branch, default: main]"
allowed-tools:
- Bash
- Grep
- Read
- AskUserQuestion
---

View File

@@ -4,6 +4,7 @@ description: "Resume work from previous session with full context restoration"
allowed-tools:
- Read
- Bash
- Grep
- Write
- AskUserQuestion
- SlashCommand

View File

@@ -5,6 +5,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
---

View File

@@ -5,6 +5,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
---

View File

@@ -4,6 +4,7 @@ description: "Display project statistics — phases, plans, requirements, git me
allowed-tools:
- Read
- Bash
- Grep
---
<objective>

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
---

View File

@@ -6,6 +6,7 @@ allowed-tools:
- Read
- Write
- Bash
- Grep
- AskUserQuestion
---

View File

@@ -4,6 +4,7 @@ description: "Manage parallel workstreams — list, create, switch, status, prog
allowed-tools:
- Read
- Bash
- Grep
---

View File

@@ -743,7 +743,7 @@ describe('installRuntimeArtifacts (copilot integration)', () => {
const skillContent = fs.readFileSync(path.join(skillsDir, 'gsd-health', 'SKILL.md'), 'utf8');
// Frontmatter format checks
assert.ok(skillContent.startsWith('---\nname: gsd-health\n'), 'starts with name: gsd-health');
assert.ok(skillContent.includes('allowed-tools: Read, Bash, Write, AskUserQuestion'),
assert.ok(skillContent.includes('allowed-tools: Read, Bash, Grep, Write, AskUserQuestion'),
'allowed-tools is comma-separated');
assert.ok(!skillContent.includes('allowed-tools:\n -'), 'NOT YAML multiline format');
// CONV-06/07 applied

View File

@@ -319,9 +319,19 @@ test('cmdInitTodos: real todo file produces a rendered bullet via the CLI', (t)
const json = runQueryInitTodos(dir);
assert.equal(json.pending_read_ok, true);
assert.equal(json.todo_count, 1);
assert.match(json.pending_todos_markdown, /Fix retry logic/);
assert.match(json.pending_todos_markdown, /Needs Add a max-attempts cap\.$/m);
// The Needs clause is asserted on the STRUCTURED field, not the rendered
// bullet: the bullet embeds the todo file's ABSOLUTE path, so its total
// length varies by runner tmpdir (macOS CI's /private/var/folders/… plus
// the test harness's gsd-test-run-* wrapper pushed the full bullet past
// renderPendingTodoBullet's intended 240-char cap, whose documented first
// degradation step is to drop the Needs clause — a correct product
// behavior this test must not depend on the runner's path length for).
assert.equal(json.todo_count, 1);
assert.ok(Array.isArray(json.todos) && json.todos.length === 1, 'todos array must carry the one todo');
// (the raw field keeps the trailing period; only the rendered bullet
// strips it — renderPendingTodoBullet's own unit rows pin that.)
assert.equal(json.todos[0].needs, 'Add a max-attempts cap.');
});
test('cmdInitTodos: needs clause survives a deterministically long base path (#4384 macOS shape)', (t) => {