fix(#260): enforce worktree absolute-path safety via PreToolUse hook

Closes #260

Moves the step-0b absolute-path guard from prose instructions to a harness-enforced PreToolUse hook (gsd-worktree-path-guard.js). Hard-blocks Edit/Write/MultiEdit calls whose absolute path resolves outside the active worktree root.
This commit is contained in:
Tom Boucher
2026-06-01 10:56:06 -04:00
committed by GitHub
parent 4332e1a5dd
commit faf329ecb9
10 changed files with 632 additions and 2 deletions

View File

@@ -33,6 +33,7 @@ const HOOKS_TO_COPY = [
'gsd-statusline.js',
'gsd-update-banner.js',
'gsd-workflow-guard.js',
'gsd-worktree-path-guard.js',
// Community hooks (bash, opt-in via .planning/config.json hooks.community)
'gsd-session-state.sh',
'gsd-validate-commit.sh',