Files
msd-core/docs/features/security-hardening.md
Jakub Zych a9a7a328e6 refactor: hard-fork GSD -> MSD (Make Software Done)
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00

1.9 KiB

id, title, group
id title group
46 Security Hardening v1.27 Features

Purpose: Defense-in-depth security for MSD's planning artifacts. Because MSD generates markdown files that become LLM system prompts, user-controlled text flowing into these files is a potential indirect prompt injection vector.

Components:

1. Centralized Security Module (security.cjs)

  • Path traversal prevention — validates file paths resolve within the project directory
  • Prompt injection detection — scans for known injection patterns in user-supplied text
  • Safe JSON parsing — catches malformed input before state corruption
  • Field name validation — prevents injection through config field names
  • Shell argument validation — sanitizes user text before shell interpolation

2. Prompt Injection Guard Hook (msd-prompt-guard.js) PreToolUse hook that scans Write/Edit calls targeting .planning/ for injection patterns. Advisory-only — logs detection for awareness without blocking legitimate operations.

3. Workflow Guard Hook (msd-workflow-guard.js) PreToolUse hook that detects when Claude attempts file edits outside a MSD workflow context. Advises using /msd-quick or /msd-fast instead of direct edits. Configurable via hooks.workflow_guard (default: false).

4. CI-Ready Injection Scanner (prompt-injection-scan.security.test.cjs) Test suite that scans all agent, workflow, and command files for embedded injection vectors.

Requirements:

  • REQ-SEC-01: All user-supplied file paths MUST be validated against the project directory
  • REQ-SEC-02: Prompt injection patterns MUST be detected before text enters planning artifacts
  • REQ-SEC-03: Security hooks MUST be advisory-only (never block legitimate operations)
  • REQ-SEC-04: JSON parsing of user input MUST catch malformed data gracefully
  • REQ-SEC-05: macOS /var → /private/var symlink resolution MUST be handled in path validation