Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD across contents and paths, upstream package/repo coordinates -> @golem15/msd-core and golem15com/msd-core. Deep links into upstream history, sibling upstream packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is. Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line, package/plugin identity, regenerated lockfile, install-tree fixtures, derived registries and benchmark baseline; migration checksum baseline re-locked (MSD keeps its own install state, so no install had applied the old sums); sort-order and regex-escaped expectations in tests adjusted.
33 lines
1.9 KiB
Markdown
33 lines
1.9 KiB
Markdown
---
|
|
id: 46
|
|
title: Security Hardening
|
|
group: v1.27 Features
|
|
---
|
|
|
|
**Purpose:** Defense-in-depth security for MSD's planning artifacts. Because MSD generates markdown files that become LLM system prompts, user-controlled text flowing into these files is a potential indirect prompt injection vector.
|
|
|
|
**Components:**
|
|
|
|
**1. Centralized Security Module** (`security.cjs`)
|
|
- Path traversal prevention — validates file paths resolve within the project directory
|
|
- Prompt injection detection — scans for known injection patterns in user-supplied text
|
|
- Safe JSON parsing — catches malformed input before state corruption
|
|
- Field name validation — prevents injection through config field names
|
|
- Shell argument validation — sanitizes user text before shell interpolation
|
|
|
|
**2. Prompt Injection Guard Hook** (`msd-prompt-guard.js`)
|
|
PreToolUse hook that scans Write/Edit calls targeting `.planning/` for injection patterns. Advisory-only — logs detection for awareness without blocking legitimate operations.
|
|
|
|
**3. Workflow Guard Hook** (`msd-workflow-guard.js`)
|
|
PreToolUse hook that detects when Claude attempts file edits outside a MSD workflow context. Advises using `/msd-quick` or `/msd-fast` instead of direct edits. Configurable via `hooks.workflow_guard` (default: false).
|
|
|
|
**4. CI-Ready Injection Scanner** (`prompt-injection-scan.security.test.cjs`)
|
|
Test suite that scans all agent, workflow, and command files for embedded injection vectors.
|
|
|
|
**Requirements:**
|
|
- REQ-SEC-01: All user-supplied file paths MUST be validated against the project directory
|
|
- REQ-SEC-02: Prompt injection patterns MUST be detected before text enters planning artifacts
|
|
- REQ-SEC-03: Security hooks MUST be advisory-only (never block legitimate operations)
|
|
- REQ-SEC-04: JSON parsing of user input MUST catch malformed data gracefully
|
|
- REQ-SEC-05: macOS `/var` → `/private/var` symlink resolution MUST be handled in path validation
|