* refactor(#712): replace Codex slash-command denylist lookbehind with positive-boundary match
The hyphen-style /gsd-<cmd> -> $gsd-<cmd> conversion in
convertSlashCommandsToCodexSkillMentions used a negative-lookbehind DENYLIST
enumerating characters that must NOT precede a real mention. #637 -> #704 showed
this is an unbounded treadmill: each new unanticipated preceding char (/, ., word
chars, then }, )) leaked the same path-corruption bug class, and a backtick-wrapped
path (`/gsd-core/workflows/update.md`) still leaked through.
Replace it with a POSITIVE two-boundary definition of a mention:
1. Left: opens at start-of-string, whitespace, or an inline-prose delimiter
(backtick/quote/paren/bracket).
2. Right: the command token is not followed by a path separator `/` (a path
continues, a command does not). The (?![a-z0-9/-]) lookahead also blocks
regex backtracking to a shorter command.
This closes the whole class by construction (no preceding-char denylist to
maintain) and fixes the backtick-wrapped-path corruption the #704 test
documented as a pre-existing gap, while preserving conversion of legitimate
backtick-wrapped mentions (e.g. CONTEXT.md's `/gsd-execute-phase` lists).
The colon-style /gsd: replace is intentionally left unguarded (it never appears
as a filesystem path segment) and is annotated as such.
Tests assert the regex directly (function now exported) across a convert/
don't-convert matrix plus one end-to-end pipeline assertion for the headline
backtick-path case.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore(#712): add changeset fragment for PR #747
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>