Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD across contents and paths, upstream package/repo coordinates -> @golem15/msd-core and golem15com/msd-core. Deep links into upstream history, sibling upstream packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is. Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line, package/plugin identity, regenerated lockfile, install-tree fixtures, derived registries and benchmark baseline; migration checksum baseline re-locked (MSD keeps its own install state, so no install had applied the old sums); sort-order and regex-escaped expectations in tests adjusted.
Adversarial security fixtures (#3596)
Reusable hostile payloads consumed by
tests/security-prompt-injection.security.test.cjs.
The fixtures here are pure data — they are loaded by the test as input to the production code under test (hooks, validators, sanitizers, CLI). They are not executed and contain no real secrets.
| File | Attack class | Consumed by |
|---|---|---|
context-instruction-override.md |
Fake instruction override + role manipulation | msd-read-injection-scanner.js, msd-prompt-guard.js |
plan-fake-system-tags.md |
<system>/<assistant> boundary mimicry |
sanitizeForPrompt, msd-prompt-guard.js |
roadmap-heredoc-breakout.md |
Heredoc-shaped payload inside a planning doc | msd-read-injection-scanner.js |
plan-fake-frontmatter.md |
Frontmatter fields that try to override intent | msd-read-injection-scanner.js |
context-malicious-markdown-link.md |
Markdown links with javascript: and embedded creds |
msd-read-injection-scanner.js |
context-invisible-unicode.md |
Zero-width chars hiding instructions | msd-read-injection-scanner.js, sanitizeForPrompt |
The fake-token values used in CLI redaction probes
(ghp_AAAA…, sk-AAAA…) are constructed inline by the test, not stored
here, so an editor or grep that scans this directory does not surface
plausible-looking credentials.