Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD across contents and paths, upstream package/repo coordinates -> @golem15/msd-core and golem15com/msd-core. Deep links into upstream history, sibling upstream packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is. Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line, package/plugin identity, regenerated lockfile, install-tree fixtures, derived registries and benchmark baseline; migration checksum baseline re-locked (MSD keeps its own install state, so no install had applied the old sums); sort-order and regex-escaped expectations in tests adjusted.
1.9 KiB
id, title, group
| id | title | group |
|---|---|---|
| 46 | Security Hardening | v1.27 Features |
Purpose: Defense-in-depth security for MSD's planning artifacts. Because MSD generates markdown files that become LLM system prompts, user-controlled text flowing into these files is a potential indirect prompt injection vector.
Components:
1. Centralized Security Module (security.cjs)
- Path traversal prevention — validates file paths resolve within the project directory
- Prompt injection detection — scans for known injection patterns in user-supplied text
- Safe JSON parsing — catches malformed input before state corruption
- Field name validation — prevents injection through config field names
- Shell argument validation — sanitizes user text before shell interpolation
2. Prompt Injection Guard Hook (msd-prompt-guard.js)
PreToolUse hook that scans Write/Edit calls targeting .planning/ for injection patterns. Advisory-only — logs detection for awareness without blocking legitimate operations.
3. Workflow Guard Hook (msd-workflow-guard.js)
PreToolUse hook that detects when Claude attempts file edits outside a MSD workflow context. Advises using /msd-quick or /msd-fast instead of direct edits. Configurable via hooks.workflow_guard (default: false).
4. CI-Ready Injection Scanner (prompt-injection-scan.security.test.cjs)
Test suite that scans all agent, workflow, and command files for embedded injection vectors.
Requirements:
- REQ-SEC-01: All user-supplied file paths MUST be validated against the project directory
- REQ-SEC-02: Prompt injection patterns MUST be detected before text enters planning artifacts
- REQ-SEC-03: Security hooks MUST be advisory-only (never block legitimate operations)
- REQ-SEC-04: JSON parsing of user input MUST catch malformed data gracefully
- REQ-SEC-05: macOS
/var→/private/varsymlink resolution MUST be handled in path validation