Files
msd-core/tests/fixtures/install-tree/opencode.json
Tom Boucher 241646a43a fix(#4651): classify .env names by final extension, and close the trailing-dot alias bypass — Phase 1 of #4636 (#4659)
* test(#4651): failing-first coverage for final-extension classification

Phase 1 of epic #4636, absorbing #4580. Tests only; no fix. These MUST fail.

The guard classifies a name by comparing everything after `.env.` as one
token against a set whose members are FINAL EXTENSIONS. So `.env.local.example`
yields suffix `local.example`, which is not a member, and a committed
secret-free template is refused. That is a category error, not strictness.

Two arms are covered because the same classification is hand-rolled twice in
one file: `isSecretBasename` for Read/Bash, and `globAltSelectsSecret`
(`lit.startsWith('.env.')`) for Grep globs. Fixing one alone would ship a
guard that allows `cat .env.local.example` while refusing
`Grep --glob '.env.local.example'` — the same file, the same hook, opposite
answers. A cross-arm parity loop over one shared list asserts the two cannot
drift.

Rows that exist because they are the ones nobody enumerates:

- `.env.example.local` must stay BLOCKED. Final extension is `local`; this is
  dotenv's documented local-override convention and a real secret. Any fix
  shaped as "contains example" admits it.
- `.env.local.` must stay BLOCKED — empty final extension is not a member.
- `.env.` must stay ALLOWED. Note #4580's proposed patch adds
  `if (suffix === '') return true;`, which flips it to blocked; that breaks the
  existing `allows` assertion in this suite and broadens the protected set,
  which epic #4636's non-goals forbid. Not applied.
- `.env.local.exam*` (partial glob literal) must stay BLOCKED — it can select
  `.env.local`, and a partial literal cannot be classified.
- `*.example` and `*` must stay ALLOWED — regression protection on the arm
  that already works.

Local behavioral repro of the current guard, confirming the tests fail for the
right reason rather than by construction:

  .env.local.example  rc=2 (blocked)   <- the defect
  .env.example        rc=0 (allowed)
  .env.local          rc=2 (blocked)
  .env.example.local  rc=2 (blocked)
  .env.               rc=0 (allowed)
  glob .env.local.example  rc=2        <- the second arm

Regressions are folded into the owning module's suite rather than a new
tests/fix-NNNN-*.test.cjs file, per scripts/lint-regression-test-names.cjs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4651): classify by final extension so .env.<name>.example is readable

Phase 1 of epic #4636, absorbing #4580. Implements ADR-4650 decision 5.

The guard compared everything after `.env.` as ONE token against a set whose
members are FINAL EXTENSIONS. `.env.local.example` yielded `local.example`,
which is not a member, so a committed, secret-free template was refused — the
guard blocked the one file that exists so nobody has to open the real `.env`.

That is a category error, not strictness. The fix is not "add local.example to
the set"; it is to compare the right token. hooks/lib/filename-classification.js
now owns that distinction and is the only place it is expressed.

Both arms are fixed, because the same classification was hand-rolled twice in
this one file:

  - isSecretBasename (Read/Bash) now tests finalExtension(suffix).
  - globAltSelectsSecret (Grep --glob) split its first branch. With no
    wildcard the alternative IS a whole filename, so it is classified exactly
    via isSecretBasename. With a wildcard present the literal is only a
    PARTIAL prefix (`.env.local.exam*` can still select `.env.local`) and
    cannot be classified, so the original conservative rule stays.

Fixing only the first would have shipped a self-contradicting guard: `cat
.env.local.example` allowed while `Grep --glob '.env.local.example'` refused —
same file, same hook, opposite answers. A cross-arm parity loop over one shared
list now asserts the two cannot drift.

Two deliberate departures from #4580's suggested patch, both verified:

  - Its `if (suffix === '') return true;` is NOT applied. That flips `.env.`
    from allowed to blocked, breaking an existing assertion in this suite and
    broadening the protected set, which epic #4636's non-goals forbid.
  - `fullSuffix` was drafted alongside finalExtension and removed before
    commit: zero production consumers, and none planned (Phases 2-4 are
    containment, duplicate draining and the path-join ratchet, none of which
    classify filenames). A zero-caller export is dead code. The distinction is
    pinned instead by a test asserting finalExtension('local.example') is
    'example' and explicitly NOT 'local.example'.

The protected set is unchanged. `.env.example.local` stays BLOCKED — its final
extension is `local`, dotenv's local-override convention and a real secret;
any fix shaped as "contains example" admits it.

Scoped out by measurement, not assumption: src/validate.cts:395 and
src/phase.cts:1674 also hand-roll lastIndexOf('.'), but both parse phase
identifiers (`3.2` -> parent `3`), owned by the phase-id.cts seam. Folding
them in would repeat this same category error in the opposite direction.

Checkpoint 1 (prove RED) on the tests-only commit 91d3d6e1: outcome=failed,
26 failures / 45330, all 26 in the two new test files, zero pre-existing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4651): document the widened template exemption and cover the Bash arm

Two findings from the isolated adversarial review, both fixed in place.

1. The header's "Stated cost" passage named only the four literal template
   names, but since this change the exemption keys on the FINAL EXTENSION, so
   the trusted set is `.env.<anything>.{example,sample,template,dist}` — an
   unbounded family. The reviewer demonstrated it: `.env.prod-real-secrets.example`
   is allowed. That is the deliberate and necessary cost of fixing #4580, but
   it was materially larger than what the header disclosed, and a silent
   expansion of a security guard's trusted set is not acceptable. The passage
   now states the family, the concrete bypass, and that it applies across
   Read, Grep and Bash alike.

2. The cross-arm parity loop asserted Read and the exact-literal Grep glob but
   not Bash, whose `namesSecret` -> `isSecretBasename` path is genuinely
   distinct. The Bash arm was covered only by two one-off tests outside the
   shared table, so the table could not have caught a drift there. The loop now
   drives all three arms from the same TEMPLATES/SECRETS arrays.

No classification logic changed. The Read-arm behavioral table is byte-identical
before and after: rc=0 for .env.local.example / .env.example / .env. ; rc=2 for
.env.local / .env.example.local / .env / .secrets.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4651): treat trailing dots and spaces as aliases of the protected file

Closes a Windows path-alias bypass surfaced by the isolated adversarial review
of this phase. Maintainer-approved as in scope.

Win32 strips trailing dots and spaces from every path component, so `.env.`,
`.env..`, `.env `, `.env. `, `.env .`, `.secrets.` and `.secrets ` all resolve
to the real `.env` / `.secrets` on Windows. The guard allowed every one of them
— a bypass of a file it already protects, reachable from Read, Grep and Bash
alike. `isSecretBasename` now normalizes the basename before classifying.

The whole class is fixed, not the reported name. `.env.` alone would have left
`.secrets.` and the trailing-space forms open, which is the same
one-cause-explains-every-failure trap this epic exists to close.

Two consequences, both measured rather than assumed:

  - `.env.example.` flips blocked -> ALLOWED. It aliases the already-trusted
    `.env.example` template, so this is correct; it was previously blocked only
    because the trailing dot broke final-extension parsing.
  - A Bash token that is exactly `.env` plus trailing whitespace flips
    allowed -> BLOCKED. Verified this is CONSISTENCY, not a new false-positive
    class: the bare `.env` token was ALREADY blocked as an operand in the same
    position before this change, so the alias now simply behaves like the thing
    it aliases.

The header's "No whitespace trimming" guarantee is preserved and now stated
precisely: leading and interior whitespace is still never trimmed, so prose
like a commit message mentioning `.env` in a sentence stays prose and stays
allowed. Only TRAILING dots and spaces are stripped. Two tests pin that.

This lands at the same behavior #4580's proposed `if (suffix === '') return
true;` would have produced for `.env.`, which this phase earlier rejected. The
rejection was correct on its stated grounds — that line broadens the protected
set, which epic #4636's non-goals forbid. The Windows framing is different:
normalizing an alias of an already-protected file is not a broadening, and the
fix is reached by normalization rather than by special-casing an empty suffix,
so it generalizes to `.secrets.` and the space forms.

Cannot be reproduced on this host — the remote matrix is Linux-only and Windows
coverage arrives from CI — so this ships on the Win32 path-normalization
contract plus the CI lane, and that limitation is stated rather than implied.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4651): one owner for path segmentation, closing a Read/Grep divergence

Four findings from the two-axis review, all fixed in place.

The real one: the guard had TWO path-segmentation rules. `lastSegment` (used
by Read and Bash via `namesSecret`) splits on both `/` and `\`, while
`classifyGrepGlob` hand-rolled its own on `/` only. Measured:

  Read  of `config\.env`      rc=2  BLOCKED
  Grep  --glob 'config\.env'  rc=0  ALLOWED

Same logical file, opposite answers — precisely the divergence this epic
exists to remove, sitting inside the file this phase was already fixing.
`lastSegment` now lives in hooks/lib/filename-classification.js and both arms
call it. All five path-bearing cases (both separators) now agree.

Note on how this was nearly missed: the first measurement of it reported
"both allow", which looked like the reviewer was wrong. That reading was a
measurement artifact — `config\.env` inside a printf'd JSON payload is an
invalid escape, so the hook fails open at rc=0 and the test was observing
JSON breakage rather than the predicate. Re-measured with correct escaping,
the divergence is real. The tests added here use properly escaped literals
and were verified by running, not by reasoning about the escaping.

Also fixed:

  - Both fast-check properties were satisfied by a degenerate
    always-return-'' implementation: "never contains a dot / is a suffix" and
    "never ends with dot-or-space / is a prefix" are both trivially true of
    the empty string. They now additionally pin content preservation — the
    removed tail must match /^[. ]*$/, and a name with nothing to strip must
    come back unchanged.
  - The cross-arm parity loop used only bare basenames, so it could not have
    caught the divergence above. It now covers path-bearing names with both
    separators.
  - That loop's description overclaimed: Read and Bash BOTH route through
    `namesSecret`, so they are not independent paths; only the Grep glob arm
    is genuinely separate. The description now says so rather than implying
    three-way independence.
  - `normalizeWindowsBasename` runs on every platform, not only Windows. Its
    doc now states that explicitly: the guard must answer identically
    everywhere, and a name is judged by what Win32 would resolve it to.

No classification logic changed; the 12-name regression sweep is unchanged.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(#4651): regenerate install-tree goldens, correct the guard's user-facing docs

Three things, all consequences of the fix rather than new behavior.

1. Install-tree goldens. `hooks/lib/filename-classification.js` is a SHIPPED
   file — package.json `files` includes `hooks` — so every per-runtime install
   tree gains a path. Checkpoint 2 failed on exactly this: 11 failures, all in
   tests/golden-install-tree.test.cjs, against 45356 passing. Regenerated via
   scripts/gen-install-tree-fixtures.cjs; 11 goldens changed, matching the 11
   failures one-for-one.

   This ripple was identified at design time and then not acted on. Fleet's
   impact preview named golden-install-tree.test.cjs before any code was
   written, and 40-design.md records it under "Ripples identified". Writing a
   risk down is not the same as discharging it, and a full matrix run was spent
   discovering something already known.

2. docs/USER-GUIDE.md made a precise and now-false claim about the guard's
   protected set: it named `.env.example` / `.sample` / `.template` / `.dist`
   as the four exempt names. The exemption keys on the FINAL EXTENSION, so the
   exempt set is the unbounded family `.env.<anything>.{example,sample,template,dist}`.
   The page now states that family, the widened residual, that order matters
   and only the last segment counts (`.env.example.local` is a secret), and
   that trailing dots and spaces are stripped because Windows resolves them to
   the protected file. A wrong user-facing model of what a security guard
   protects is worth correcting even though Fixed/Security changesets are
   exempt from the required-docs rule.

   docs/ARCHITECTURE.md and docs/INVENTORY.md say "templates such as
   `.env.example` exempt" — non-exhaustive, still true, deliberately left
   alone. Same for the ja-JP / zh-CN / ko-KR / pt-BR rows, which carry the same
   hedged phrasing; hand-translating a security description unreviewed is not
   something to do silently.

3. Two changeset fragments, not one. A refusal corrected is `Fixed`; a bypass
   closed is `Security`. Folding the second into the first would under-report
   it in the release notes. Both carry `pr: 0` for backfill once the PR exists.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(#4651): backfill changeset PR number to 4659

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-12 08:42:43 -04:00

779 lines
33 KiB
JSON

[
".gsd-profile",
"agents/gsd-advisor-researcher.compact.md",
"agents/gsd-advisor-researcher.md",
"agents/gsd-ai-researcher.compact.md",
"agents/gsd-ai-researcher.md",
"agents/gsd-assumptions-analyzer.compact.md",
"agents/gsd-assumptions-analyzer.md",
"agents/gsd-code-fixer.compact.md",
"agents/gsd-code-fixer.md",
"agents/gsd-code-reviewer.compact.md",
"agents/gsd-code-reviewer.md",
"agents/gsd-codebase-mapper.compact.md",
"agents/gsd-codebase-mapper.md",
"agents/gsd-debug-session-manager.compact.md",
"agents/gsd-debug-session-manager.md",
"agents/gsd-debugger.md",
"agents/gsd-doc-classifier.compact.md",
"agents/gsd-doc-classifier.md",
"agents/gsd-doc-synthesizer.compact.md",
"agents/gsd-doc-synthesizer.md",
"agents/gsd-doc-verifier.compact.md",
"agents/gsd-doc-verifier.md",
"agents/gsd-doc-writer.compact.md",
"agents/gsd-doc-writer.md",
"agents/gsd-dom-verifier.compact.md",
"agents/gsd-dom-verifier.md",
"agents/gsd-domain-researcher.compact.md",
"agents/gsd-domain-researcher.md",
"agents/gsd-eval-auditor.compact.md",
"agents/gsd-eval-auditor.md",
"agents/gsd-eval-planner.compact.md",
"agents/gsd-eval-planner.md",
"agents/gsd-executor.md",
"agents/gsd-framework-selector.compact.md",
"agents/gsd-framework-selector.md",
"agents/gsd-integration-checker.compact.md",
"agents/gsd-integration-checker.md",
"agents/gsd-intel-updater.compact.md",
"agents/gsd-intel-updater.md",
"agents/gsd-mempalace-curator.compact.md",
"agents/gsd-mempalace-curator.md",
"agents/gsd-nyquist-auditor.compact.md",
"agents/gsd-nyquist-auditor.md",
"agents/gsd-pattern-mapper.compact.md",
"agents/gsd-pattern-mapper.md",
"agents/gsd-phase-researcher.md",
"agents/gsd-plan-checker.md",
"agents/gsd-planner.md",
"agents/gsd-project-researcher.compact.md",
"agents/gsd-project-researcher.md",
"agents/gsd-research-synthesizer.compact.md",
"agents/gsd-research-synthesizer.md",
"agents/gsd-roadmapper.compact.md",
"agents/gsd-roadmapper.md",
"agents/gsd-security-auditor.compact.md",
"agents/gsd-security-auditor.md",
"agents/gsd-ui-auditor.compact.md",
"agents/gsd-ui-auditor.md",
"agents/gsd-ui-checker.compact.md",
"agents/gsd-ui-checker.md",
"agents/gsd-ui-researcher.compact.md",
"agents/gsd-ui-researcher.md",
"agents/gsd-user-profiler.compact.md",
"agents/gsd-user-profiler.md",
"agents/gsd-verifier.md",
"commands/gsd-add-tests.md",
"commands/gsd-ai-integration-phase.md",
"commands/gsd-audit-fix.md",
"commands/gsd-audit-milestone.md",
"commands/gsd-audit-uat.md",
"commands/gsd-autonomous.md",
"commands/gsd-capture.md",
"commands/gsd-cleanup.md",
"commands/gsd-code-review.md",
"commands/gsd-complete-milestone.md",
"commands/gsd-config.md",
"commands/gsd-debug.md",
"commands/gsd-discuss-phase.md",
"commands/gsd-docs-update.md",
"commands/gsd-eval-review.md",
"commands/gsd-execute-phase.md",
"commands/gsd-explore.md",
"commands/gsd-extract-learnings.md",
"commands/gsd-fast.md",
"commands/gsd-forensics.md",
"commands/gsd-graphify.md",
"commands/gsd-health.md",
"commands/gsd-help.md",
"commands/gsd-import.md",
"commands/gsd-inbox.md",
"commands/gsd-ingest-docs.md",
"commands/gsd-manager.md",
"commands/gsd-map-codebase.md",
"commands/gsd-mempalace-capture.md",
"commands/gsd-mempalace-recall.md",
"commands/gsd-milestone-summary.md",
"commands/gsd-mvp-phase.md",
"commands/gsd-new-milestone.md",
"commands/gsd-new-project.md",
"commands/gsd-next.md",
"commands/gsd-ns-context.md",
"commands/gsd-ns-ideate.md",
"commands/gsd-ns-manage.md",
"commands/gsd-ns-project.md",
"commands/gsd-ns-review.md",
"commands/gsd-ns-workflow.md",
"commands/gsd-onboard.md",
"commands/gsd-pause-work.md",
"commands/gsd-phase.md",
"commands/gsd-plan-phase.md",
"commands/gsd-plan-review-convergence.md",
"commands/gsd-pr-branch.md",
"commands/gsd-profile-user.md",
"commands/gsd-progress.md",
"commands/gsd-quick-batch.md",
"commands/gsd-quick.md",
"commands/gsd-resume-work.md",
"commands/gsd-review-backlog.md",
"commands/gsd-review.md",
"commands/gsd-secure-phase.md",
"commands/gsd-settings.md",
"commands/gsd-ship.md",
"commands/gsd-sketch.md",
"commands/gsd-spec-phase.md",
"commands/gsd-spike.md",
"commands/gsd-stats.md",
"commands/gsd-surface.md",
"commands/gsd-thread.md",
"commands/gsd-ui-phase.md",
"commands/gsd-ui-review.md",
"commands/gsd-ultraplan-phase.md",
"commands/gsd-undo.md",
"commands/gsd-update.md",
"commands/gsd-validate-phase.md",
"commands/gsd-verify-work.md",
"commands/gsd-workspace.md",
"commands/gsd-workstreams.md",
"gsd-core/.gsd-runtime",
"gsd-core/VERSION",
"gsd-core/agents/gsd-advisor-researcher.compact.md",
"gsd-core/agents/gsd-advisor-researcher.md",
"gsd-core/agents/gsd-ai-researcher.compact.md",
"gsd-core/agents/gsd-ai-researcher.md",
"gsd-core/agents/gsd-assumptions-analyzer.compact.md",
"gsd-core/agents/gsd-assumptions-analyzer.md",
"gsd-core/agents/gsd-code-fixer.compact.md",
"gsd-core/agents/gsd-code-fixer.md",
"gsd-core/agents/gsd-code-reviewer.compact.md",
"gsd-core/agents/gsd-code-reviewer.md",
"gsd-core/agents/gsd-codebase-mapper.compact.md",
"gsd-core/agents/gsd-codebase-mapper.md",
"gsd-core/agents/gsd-debug-session-manager.compact.md",
"gsd-core/agents/gsd-debug-session-manager.md",
"gsd-core/agents/gsd-debugger.md",
"gsd-core/agents/gsd-doc-classifier.compact.md",
"gsd-core/agents/gsd-doc-classifier.md",
"gsd-core/agents/gsd-doc-synthesizer.compact.md",
"gsd-core/agents/gsd-doc-synthesizer.md",
"gsd-core/agents/gsd-doc-verifier.compact.md",
"gsd-core/agents/gsd-doc-verifier.md",
"gsd-core/agents/gsd-doc-writer.compact.md",
"gsd-core/agents/gsd-doc-writer.md",
"gsd-core/agents/gsd-dom-verifier.compact.md",
"gsd-core/agents/gsd-dom-verifier.md",
"gsd-core/agents/gsd-domain-researcher.compact.md",
"gsd-core/agents/gsd-domain-researcher.md",
"gsd-core/agents/gsd-eval-auditor.compact.md",
"gsd-core/agents/gsd-eval-auditor.md",
"gsd-core/agents/gsd-eval-planner.compact.md",
"gsd-core/agents/gsd-eval-planner.md",
"gsd-core/agents/gsd-executor.md",
"gsd-core/agents/gsd-framework-selector.compact.md",
"gsd-core/agents/gsd-framework-selector.md",
"gsd-core/agents/gsd-integration-checker.compact.md",
"gsd-core/agents/gsd-integration-checker.md",
"gsd-core/agents/gsd-intel-updater.compact.md",
"gsd-core/agents/gsd-intel-updater.md",
"gsd-core/agents/gsd-mempalace-curator.compact.md",
"gsd-core/agents/gsd-mempalace-curator.md",
"gsd-core/agents/gsd-nyquist-auditor.compact.md",
"gsd-core/agents/gsd-nyquist-auditor.md",
"gsd-core/agents/gsd-pattern-mapper.compact.md",
"gsd-core/agents/gsd-pattern-mapper.md",
"gsd-core/agents/gsd-phase-researcher.md",
"gsd-core/agents/gsd-plan-checker.md",
"gsd-core/agents/gsd-planner.md",
"gsd-core/agents/gsd-project-researcher.compact.md",
"gsd-core/agents/gsd-project-researcher.md",
"gsd-core/agents/gsd-research-synthesizer.compact.md",
"gsd-core/agents/gsd-research-synthesizer.md",
"gsd-core/agents/gsd-roadmapper.compact.md",
"gsd-core/agents/gsd-roadmapper.md",
"gsd-core/agents/gsd-security-auditor.compact.md",
"gsd-core/agents/gsd-security-auditor.md",
"gsd-core/agents/gsd-ui-auditor.compact.md",
"gsd-core/agents/gsd-ui-auditor.md",
"gsd-core/agents/gsd-ui-checker.compact.md",
"gsd-core/agents/gsd-ui-checker.md",
"gsd-core/agents/gsd-ui-researcher.compact.md",
"gsd-core/agents/gsd-ui-researcher.md",
"gsd-core/agents/gsd-user-profiler.compact.md",
"gsd-core/agents/gsd-user-profiler.md",
"gsd-core/agents/gsd-verifier.md",
"gsd-core/bin/check-latest-version.cjs",
"gsd-core/bin/ensure-runtime-build.cjs",
"gsd-core/bin/gsd-tools.cjs",
"gsd-core/bin/gsd_run",
"gsd-core/bin/shared/config-defaults.manifest.json",
"gsd-core/bin/shared/config-schema.manifest.json",
"gsd-core/bin/shared/exit-codes.json",
"gsd-core/bin/shared/exit-codes.sh",
"gsd-core/bin/shared/model-catalog.json",
"gsd-core/bin/shared/runtime-aliases.manifest.json",
"gsd-core/bin/verify-reapply-patches.cjs",
"gsd-core/commands/gsd/add-tests.md",
"gsd-core/commands/gsd/ai-integration-phase.md",
"gsd-core/commands/gsd/audit-fix.md",
"gsd-core/commands/gsd/audit-milestone.md",
"gsd-core/commands/gsd/audit-uat.md",
"gsd-core/commands/gsd/autonomous.md",
"gsd-core/commands/gsd/capture.md",
"gsd-core/commands/gsd/cleanup.md",
"gsd-core/commands/gsd/code-review.md",
"gsd-core/commands/gsd/complete-milestone.md",
"gsd-core/commands/gsd/config.md",
"gsd-core/commands/gsd/debug.md",
"gsd-core/commands/gsd/discuss-phase.md",
"gsd-core/commands/gsd/docs-update.md",
"gsd-core/commands/gsd/eval-review.md",
"gsd-core/commands/gsd/execute-phase.md",
"gsd-core/commands/gsd/explore.md",
"gsd-core/commands/gsd/extract-learnings.md",
"gsd-core/commands/gsd/fast.md",
"gsd-core/commands/gsd/forensics.md",
"gsd-core/commands/gsd/graphify.md",
"gsd-core/commands/gsd/health.md",
"gsd-core/commands/gsd/help.md",
"gsd-core/commands/gsd/import.md",
"gsd-core/commands/gsd/inbox.md",
"gsd-core/commands/gsd/ingest-docs.md",
"gsd-core/commands/gsd/manager.md",
"gsd-core/commands/gsd/map-codebase.md",
"gsd-core/commands/gsd/mempalace-capture.md",
"gsd-core/commands/gsd/mempalace-recall.md",
"gsd-core/commands/gsd/milestone-summary.md",
"gsd-core/commands/gsd/mvp-phase.md",
"gsd-core/commands/gsd/new-milestone.md",
"gsd-core/commands/gsd/new-project.md",
"gsd-core/commands/gsd/next.md",
"gsd-core/commands/gsd/ns-context.md",
"gsd-core/commands/gsd/ns-ideate.md",
"gsd-core/commands/gsd/ns-manage.md",
"gsd-core/commands/gsd/ns-project.md",
"gsd-core/commands/gsd/ns-review.md",
"gsd-core/commands/gsd/ns-workflow.md",
"gsd-core/commands/gsd/onboard.md",
"gsd-core/commands/gsd/pause-work.md",
"gsd-core/commands/gsd/phase.md",
"gsd-core/commands/gsd/plan-phase.md",
"gsd-core/commands/gsd/plan-review-convergence.md",
"gsd-core/commands/gsd/pr-branch.md",
"gsd-core/commands/gsd/profile-user.md",
"gsd-core/commands/gsd/progress.md",
"gsd-core/commands/gsd/quick-batch.md",
"gsd-core/commands/gsd/quick.md",
"gsd-core/commands/gsd/resume-work.md",
"gsd-core/commands/gsd/review-backlog.md",
"gsd-core/commands/gsd/review.md",
"gsd-core/commands/gsd/secure-phase.md",
"gsd-core/commands/gsd/settings.md",
"gsd-core/commands/gsd/ship.md",
"gsd-core/commands/gsd/sketch.md",
"gsd-core/commands/gsd/spec-phase.md",
"gsd-core/commands/gsd/spike.md",
"gsd-core/commands/gsd/stats.md",
"gsd-core/commands/gsd/surface.md",
"gsd-core/commands/gsd/thread.md",
"gsd-core/commands/gsd/ui-phase.md",
"gsd-core/commands/gsd/ui-review.md",
"gsd-core/commands/gsd/ultraplan-phase.md",
"gsd-core/commands/gsd/undo.md",
"gsd-core/commands/gsd/update.md",
"gsd-core/commands/gsd/validate-phase.md",
"gsd-core/commands/gsd/verify-work.md",
"gsd-core/commands/gsd/workspace.md",
"gsd-core/commands/gsd/workstreams.md",
"gsd-core/contexts/dev.md",
"gsd-core/contexts/research.md",
"gsd-core/contexts/review.md",
"gsd-core/references/agent-contracts.md",
"gsd-core/references/agent-skills-bootstrap.md",
"gsd-core/references/ai-evals.md",
"gsd-core/references/ai-frameworks.md",
"gsd-core/references/api-coverage.md",
"gsd-core/references/artifact-types.md",
"gsd-core/references/autonomous-smart-discuss.md",
"gsd-core/references/autonomous-ui-design-contract.md",
"gsd-core/references/checkpoints.md",
"gsd-core/references/common-bug-patterns.md",
"gsd-core/references/compact-content-gate.md",
"gsd-core/references/context-budget.md",
"gsd-core/references/continuation-format.md",
"gsd-core/references/debugger-bug-taxonomy.md",
"gsd-core/references/debugger-fix-acceptance.md",
"gsd-core/references/debugger-philosophy.md",
"gsd-core/references/debugger-prevention.md",
"gsd-core/references/debugger-rca-branching.md",
"gsd-core/references/debugger-repro-hardening.md",
"gsd-core/references/debugger-sbfl.md",
"gsd-core/references/debugger-semantic-recall.md",
"gsd-core/references/debugger-techniques.md",
"gsd-core/references/decimal-phase-calculation.md",
"gsd-core/references/dispatch-isolation-gate.md",
"gsd-core/references/doc-conflict-engine.md",
"gsd-core/references/domain-probes.md",
"gsd-core/references/edge-probe-fixtures/01-round-half-even/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/01-round-half-even/requirements.json",
"gsd-core/references/edge-probe-fixtures/02-merge-intervals/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/02-merge-intervals/requirements.json",
"gsd-core/references/edge-probe-fixtures/03-truncate-graphemes/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/03-truncate-graphemes/requirements.json",
"gsd-core/references/edge-probe-fixtures/04-money-rounding/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/04-money-rounding/requirements.json",
"gsd-core/references/edge-probe-fixtures/05-list-dedupe/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/05-list-dedupe/requirements.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/requirements.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/resolutions.json",
"gsd-core/references/edge-probe.md",
"gsd-core/references/execute-mvp-tdd.md",
"gsd-core/references/execute-phase-between-wave-reset.md",
"gsd-core/references/execute-phase-context-guard.md",
"gsd-core/references/execute-phase-quota-recovery.md",
"gsd-core/references/execute-phase-requirement-revert.md",
"gsd-core/references/execute-phase-response-language.md",
"gsd-core/references/execute-phase-wave-guard.md",
"gsd-core/references/executor-examples.md",
"gsd-core/references/failing-direction.md",
"gsd-core/references/few-shot-examples/plan-checker.md",
"gsd-core/references/few-shot-examples/verifier.md",
"gsd-core/references/gate-prompts.md",
"gsd-core/references/gates.md",
"gsd-core/references/git-integration.md",
"gsd-core/references/git-planning-commit.md",
"gsd-core/references/gsd-run-resolver.md",
"gsd-core/references/honest-verifier.md",
"gsd-core/references/ios-scaffold.md",
"gsd-core/references/loop-hook-dispatch.md",
"gsd-core/references/mandatory-initial-read.md",
"gsd-core/references/model-profile-resolution.md",
"gsd-core/references/model-profiles.md",
"gsd-core/references/mvp-concepts.md",
"gsd-core/references/nyquist-compliance.md",
"gsd-core/references/offer-next.md",
"gsd-core/references/phase-argument-parsing.md",
"gsd-core/references/plan-checker-examples.md",
"gsd-core/references/planner-antipatterns.md",
"gsd-core/references/planner-chunked.md",
"gsd-core/references/planner-coupling.md",
"gsd-core/references/planner-failing-direction.md",
"gsd-core/references/planner-gap-closure.md",
"gsd-core/references/planner-graphify-auto-update.md",
"gsd-core/references/planner-guidance.md",
"gsd-core/references/planner-human-verify-mode.md",
"gsd-core/references/planner-interface-context.md",
"gsd-core/references/planner-load-graph-context.md",
"gsd-core/references/planner-mvp-mode.md",
"gsd-core/references/planner-preconditions.md",
"gsd-core/references/planner-quick-batch.md",
"gsd-core/references/planner-reversibility.md",
"gsd-core/references/planner-reviews.md",
"gsd-core/references/planner-revision.md",
"gsd-core/references/planner-source-audit.md",
"gsd-core/references/planner-verify-command-grounding.md",
"gsd-core/references/planning-config.md",
"gsd-core/references/prohibition-probe-fixtures/01-streak-reminder/expected.json",
"gsd-core/references/prohibition-probe-fixtures/02-clean-utility/expected.json",
"gsd-core/references/prohibition-probe-fixtures/03-multi-prohibition/expected.json",
"gsd-core/references/prohibition-probe.md",
"gsd-core/references/project-skills-discovery.md",
"gsd-core/references/questioning.md",
"gsd-core/references/research-documentation-lookup.md",
"gsd-core/references/research-philosophy.md",
"gsd-core/references/research-verification-protocol.md",
"gsd-core/references/response-language-directive.md",
"gsd-core/references/reviewer-instances.md",
"gsd-core/references/revision-loop.md",
"gsd-core/references/runtime-aware-dispatch.md",
"gsd-core/references/scout-codebase.md",
"gsd-core/references/security-asvs-levels.md",
"gsd-core/references/skeleton-template.md",
"gsd-core/references/sketch-interactivity.md",
"gsd-core/references/sketch-theme-system.md",
"gsd-core/references/sketch-tooling.md",
"gsd-core/references/sketch-variant-patterns.md",
"gsd-core/references/specless-probe-fallback.md",
"gsd-core/references/spidr-splitting.md",
"gsd-core/references/tdd.md",
"gsd-core/references/thinking-models-debug.md",
"gsd-core/references/thinking-models-execution.md",
"gsd-core/references/thinking-models-planning.md",
"gsd-core/references/thinking-models-research.md",
"gsd-core/references/thinking-models-verification.md",
"gsd-core/references/thinking-partner.md",
"gsd-core/references/ui-brand.md",
"gsd-core/references/ui-consideration-probe.md",
"gsd-core/references/universal-anti-patterns.md",
"gsd-core/references/untrusted-input-boundary.md",
"gsd-core/references/user-profiling.md",
"gsd-core/references/user-story-template.md",
"gsd-core/references/verification-overrides.md",
"gsd-core/references/verification-patterns.md",
"gsd-core/references/verifier-evidence-gate.md",
"gsd-core/references/verifier-phase-gates.md",
"gsd-core/references/verifier-wiring-patterns.md",
"gsd-core/references/verify-command-path-resolvability.md",
"gsd-core/references/verify-mvp-mode.md",
"gsd-core/references/workstream-flag.md",
"gsd-core/references/worktree-branch-check.md",
"gsd-core/references/worktree-path-safety.md",
"gsd-core/templates/AI-SPEC.md",
"gsd-core/templates/DEBUG.md",
"gsd-core/templates/README.md",
"gsd-core/templates/SECURITY.md",
"gsd-core/templates/UAT.md",
"gsd-core/templates/UI-SPEC.md",
"gsd-core/templates/VALIDATION.md",
"gsd-core/templates/codebase/architecture.md",
"gsd-core/templates/codebase/stack.md",
"gsd-core/templates/config.json",
"gsd-core/templates/context.md",
"gsd-core/templates/continue-here.md",
"gsd-core/templates/copilot-instructions.md",
"gsd-core/templates/dev-preferences.md",
"gsd-core/templates/discussion-log.md",
"gsd-core/templates/milestone-archive.md",
"gsd-core/templates/milestone.md",
"gsd-core/templates/phase-prompt.md",
"gsd-core/templates/planner-subagent-prompt.md",
"gsd-core/templates/project.md",
"gsd-core/templates/requirements.md",
"gsd-core/templates/research-project/ARCHITECTURE.md",
"gsd-core/templates/research-project/FEATURES.md",
"gsd-core/templates/research-project/PITFALLS.md",
"gsd-core/templates/research-project/STACK.md",
"gsd-core/templates/research-project/SUMMARY.md",
"gsd-core/templates/research.md",
"gsd-core/templates/retrospective.md",
"gsd-core/templates/roadmap.md",
"gsd-core/templates/spec.md",
"gsd-core/templates/state.md",
"gsd-core/templates/summary-complex.md",
"gsd-core/templates/summary-minimal.md",
"gsd-core/templates/summary-standard.md",
"gsd-core/templates/summary.compact.md",
"gsd-core/templates/summary.md",
"gsd-core/templates/user-profile.md",
"gsd-core/templates/user-setup.compact.md",
"gsd-core/templates/user-setup.md",
"gsd-core/templates/verification-report.md",
"gsd-core/workflows/_runtime-launcher.snippet.sh",
"gsd-core/workflows/add-backlog.md",
"gsd-core/workflows/add-phase.md",
"gsd-core/workflows/add-tests.md",
"gsd-core/workflows/add-todo.md",
"gsd-core/workflows/ai-integration-phase.md",
"gsd-core/workflows/analyze-dependencies.md",
"gsd-core/workflows/audit-fix.md",
"gsd-core/workflows/audit-milestone.md",
"gsd-core/workflows/audit-uat.md",
"gsd-core/workflows/autonomous.md",
"gsd-core/workflows/autonomous/steps/converge-banner.md",
"gsd-core/workflows/autonomous/steps/converge-dispatch-bg.md",
"gsd-core/workflows/autonomous/steps/converge-dispatch-inline.md",
"gsd-core/workflows/autonomous/steps/converge-fail-fast.md",
"gsd-core/workflows/autonomous/steps/converge-loop.md",
"gsd-core/workflows/check-todos.md",
"gsd-core/workflows/cleanup.md",
"gsd-core/workflows/code-review-fix.md",
"gsd-core/workflows/code-review.md",
"gsd-core/workflows/code-review/steps/dispatch-fix.md",
"gsd-core/workflows/code-review/steps/structural-pre-pass.md",
"gsd-core/workflows/complete-milestone.md",
"gsd-core/workflows/complete-milestone/detail/elaboration.md",
"gsd-core/workflows/complete-milestone/steps/git-tag.md",
"gsd-core/workflows/debug.md",
"gsd-core/workflows/diagnose-issues.md",
"gsd-core/workflows/discuss-phase-assumptions.md",
"gsd-core/workflows/discuss-phase-assumptions/steps/auto-advance-dispatch.md",
"gsd-core/workflows/discuss-phase-power.md",
"gsd-core/workflows/discuss-phase.md",
"gsd-core/workflows/discuss-phase/modes/advisor.md",
"gsd-core/workflows/discuss-phase/modes/all.md",
"gsd-core/workflows/discuss-phase/modes/analyze.md",
"gsd-core/workflows/discuss-phase/modes/auto.md",
"gsd-core/workflows/discuss-phase/modes/batch.md",
"gsd-core/workflows/discuss-phase/modes/chain.md",
"gsd-core/workflows/discuss-phase/modes/default.md",
"gsd-core/workflows/discuss-phase/modes/power.md",
"gsd-core/workflows/discuss-phase/modes/text.md",
"gsd-core/workflows/discuss-phase/templates/checkpoint.json",
"gsd-core/workflows/discuss-phase/templates/context.md",
"gsd-core/workflows/discuss-phase/templates/discussion-log.md",
"gsd-core/workflows/do.md",
"gsd-core/workflows/docs-update.md",
"gsd-core/workflows/docs-update/detail/elaboration.md",
"gsd-core/workflows/docs-update/steps/dispatch-monorepo-packages.md",
"gsd-core/workflows/edit-phase.md",
"gsd-core/workflows/eval-review.md",
"gsd-core/workflows/execute-phase.md",
"gsd-core/workflows/execute-phase/detail/elaboration.md",
"gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md",
"gsd-core/workflows/execute-phase/steps/completion-reconciliation.md",
"gsd-core/workflows/execute-phase/steps/executor-isolation-dispatch.md",
"gsd-core/workflows/execute-phase/steps/executor-progress-policy.md",
"gsd-core/workflows/execute-phase/steps/gap-closure-artifacts.md",
"gsd-core/workflows/execute-phase/steps/partial-wave.md",
"gsd-core/workflows/execute-phase/steps/per-plan-executor-routing.md",
"gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md",
"gsd-core/workflows/execute-phase/steps/post-merge-gate.md",
"gsd-core/workflows/execute-phase/steps/protected-branch.md",
"gsd-core/workflows/execute-phase/steps/regression-gate-run.md",
"gsd-core/workflows/execute-phase/steps/regression-gate.md",
"gsd-core/workflows/execute-phase/steps/sequential-root-pin.md",
"gsd-core/workflows/execute-phase/steps/tdd-applicability-resolution.md",
"gsd-core/workflows/execute-phase/steps/wave-post-gate-hooks.md",
"gsd-core/workflows/execute-phase/steps/worktree-recovery-policy.md",
"gsd-core/workflows/execute-plan.md",
"gsd-core/workflows/explore.md",
"gsd-core/workflows/extract-learnings.md",
"gsd-core/workflows/fast.md",
"gsd-core/workflows/forensics.md",
"gsd-core/workflows/graduation.md",
"gsd-core/workflows/health.md",
"gsd-core/workflows/help.md",
"gsd-core/workflows/help/modes/brief.md",
"gsd-core/workflows/help/modes/default.md",
"gsd-core/workflows/help/modes/full.compact.md",
"gsd-core/workflows/help/modes/full.md",
"gsd-core/workflows/help/modes/topic.md",
"gsd-core/workflows/import.md",
"gsd-core/workflows/inbox.md",
"gsd-core/workflows/ingest-docs.md",
"gsd-core/workflows/insert-phase.md",
"gsd-core/workflows/list-phase-assumptions.md",
"gsd-core/workflows/list-seeds.md",
"gsd-core/workflows/list-workspaces.md",
"gsd-core/workflows/manager.md",
"gsd-core/workflows/map-codebase.md",
"gsd-core/workflows/milestone-summary.md",
"gsd-core/workflows/mvp-phase.md",
"gsd-core/workflows/new-milestone.md",
"gsd-core/workflows/new-milestone/steps/project-md-milestone-write.md",
"gsd-core/workflows/new-milestone/steps/reset-phase-safety.md",
"gsd-core/workflows/new-project.md",
"gsd-core/workflows/new-project/detail/elaboration.md",
"gsd-core/workflows/new-project/steps/auto-mode-config.md",
"gsd-core/workflows/new-project/steps/auto-mode-detection.md",
"gsd-core/workflows/new-project/steps/codebase-map-offer.md",
"gsd-core/workflows/new-workspace.md",
"gsd-core/workflows/next.md",
"gsd-core/workflows/node-repair.md",
"gsd-core/workflows/note.md",
"gsd-core/workflows/onboard.md",
"gsd-core/workflows/pause-work.md",
"gsd-core/workflows/plan-phase.md",
"gsd-core/workflows/plan-phase/detail/elaboration.md",
"gsd-core/workflows/plan-phase/steps/adr-ingest-express-path.md",
"gsd-core/workflows/plan-phase/steps/chunked-planning-mode.md",
"gsd-core/workflows/plan-phase/steps/closed-phase-gate.md",
"gsd-core/workflows/plan-phase/steps/prd-express-gate.md",
"gsd-core/workflows/plan-phase/steps/prd-express-path.md",
"gsd-core/workflows/plan-phase/steps/research-only-early-exit.md",
"gsd-core/workflows/plan-phase/steps/research-only-modifiers.md",
"gsd-core/workflows/plan-phase/steps/reviews-prerequisite.md",
"gsd-core/workflows/plan-phase/steps/stall-detection-helpers.md",
"gsd-core/workflows/plan-phase/steps/windows-troubleshooting.md",
"gsd-core/workflows/plan-review-convergence.md",
"gsd-core/workflows/plant-seed.md",
"gsd-core/workflows/pr-branch.md",
"gsd-core/workflows/profile-user.md",
"gsd-core/workflows/progress.md",
"gsd-core/workflows/progress/steps/forensic-audit.md",
"gsd-core/workflows/progress/steps/mvp-display.md",
"gsd-core/workflows/quick-batch.md",
"gsd-core/workflows/quick-batch/steps/batch-init.md",
"gsd-core/workflows/quick-batch/steps/completion.md",
"gsd-core/workflows/quick-batch/steps/merge-wave.md",
"gsd-core/workflows/quick-batch/steps/plan-checker-loop.md",
"gsd-core/workflows/quick-batch/steps/planner-wave.md",
"gsd-core/workflows/quick-batch/steps/research-phase.md",
"gsd-core/workflows/quick-batch/steps/resume-mode.md",
"gsd-core/workflows/quick-batch/steps/verification-wave.md",
"gsd-core/workflows/quick-batch/steps/worktree-dispatch.md",
"gsd-core/workflows/quick.md",
"gsd-core/workflows/quick/steps/discussion-phase.md",
"gsd-core/workflows/quick/steps/plan-checker-loop.md",
"gsd-core/workflows/quick/steps/quick-verification.md",
"gsd-core/workflows/quick/steps/research-phase.md",
"gsd-core/workflows/quick/steps/worktree-pre-dispatch-commit.md",
"gsd-core/workflows/reapply-patches.md",
"gsd-core/workflows/remove-phase.md",
"gsd-core/workflows/remove-workspace.md",
"gsd-core/workflows/resume-project.md",
"gsd-core/workflows/review.md",
"gsd-core/workflows/review/steps/reviewer-instances-note-1.md",
"gsd-core/workflows/review/steps/reviewer-instances-note-2.md",
"gsd-core/workflows/scan.md",
"gsd-core/workflows/section-manifest.json",
"gsd-core/workflows/secure-phase.md",
"gsd-core/workflows/session-report.md",
"gsd-core/workflows/settings-advanced.md",
"gsd-core/workflows/settings-integrations.md",
"gsd-core/workflows/settings.md",
"gsd-core/workflows/ship.md",
"gsd-core/workflows/sketch-wrap-up.md",
"gsd-core/workflows/sketch.md",
"gsd-core/workflows/smart-entry.md",
"gsd-core/workflows/spec-phase.md",
"gsd-core/workflows/spike-wrap-up.md",
"gsd-core/workflows/spike.md",
"gsd-core/workflows/stats.md",
"gsd-core/workflows/sync-skills.md",
"gsd-core/workflows/thread.md",
"gsd-core/workflows/transition.md",
"gsd-core/workflows/transition/steps/workstream-collision-check.md",
"gsd-core/workflows/ui-phase.md",
"gsd-core/workflows/ui-review.md",
"gsd-core/workflows/ultraplan-phase.md",
"gsd-core/workflows/undo.md",
"gsd-core/workflows/update.md",
"gsd-core/workflows/update/steps/channel-banner.md",
"gsd-core/workflows/validate-phase.md",
"gsd-core/workflows/verify-work.md",
"gsd-core/workflows/verify-work/detail/elaboration.md",
"gsd-core/workflows/verify-work/steps/automated-ui-verification.md",
"gsd-core/workflows/verify-work/steps/mvp-uat-framing.md",
"hooks/gsd-agent-isolation-guard.js",
"hooks/gsd-check-update-worker.js",
"hooks/gsd-check-update.js",
"hooks/gsd-config-reload.js",
"hooks/gsd-context-monitor.js",
"hooks/gsd-cursor-post-tool.js",
"hooks/gsd-cursor-pre-tool.js",
"hooks/gsd-cursor-session-start.js",
"hooks/gsd-cursor-stop.js",
"hooks/gsd-cursor-subagent-start.js",
"hooks/gsd-cursor-subagent-stop.js",
"hooks/gsd-ensure-canonical-path.js",
"hooks/gsd-graphify-update.sh",
"hooks/gsd-node-runner.sh",
"hooks/gsd-phase-boundary.sh",
"hooks/gsd-prompt-guard.js",
"hooks/gsd-read-guard.js",
"hooks/gsd-read-injection-scanner.js",
"hooks/gsd-secret-read-guard.js",
"hooks/gsd-session-state.sh",
"hooks/gsd-statusline.js",
"hooks/gsd-update-banner.js",
"hooks/gsd-validate-commit.sh",
"hooks/gsd-windsurf-pre-command.js",
"hooks/gsd-windsurf-pre-write.js",
"hooks/gsd-workflow-guard.js",
"hooks/gsd-worktree-path-guard.js",
"hooks/gsd-write-guard.js",
"hooks/lib/cli-exit.js",
"hooks/lib/cursor-workspace.js",
"hooks/lib/exit-code-registry.js",
"hooks/lib/filename-classification.js",
"hooks/lib/git-cmd.js",
"hooks/lib/git-probe.js",
"hooks/lib/gsd-graphify-rebuild.sh",
"hooks/lib/hook-exit.js",
"hooks/lib/injection-patterns.js",
"hooks/lib/isolation-deny-reason.js",
"hooks/lib/isolation-sentinel.js",
"hooks/managed-hooks-registry.cjs",
"hooks/package.json",
"opencode.json",
"plugins/gsd-core.js",
"plugins/package.json",
"scripts/changeset/README.md",
"scripts/changeset/cli.cjs",
"scripts/changeset/github-release-notes.cjs",
"scripts/changeset/lint.cjs",
"scripts/changeset/new.cjs",
"scripts/changeset/parse.cjs",
"scripts/changeset/render.cjs",
"scripts/changeset/serialize.cjs",
"scripts/fix-slash-commands.cjs",
"scripts/gen-capability-registry.cjs",
"scripts/gen-loop-host-contract.cjs",
"scripts/lib/alias-drift-families.cjs",
"scripts/lib/allowlist-ratchet.cjs",
"scripts/lib/ci-job-timing.cjs",
"scripts/lib/cli-exit.cjs",
"scripts/lib/drift-scan.cjs",
"scripts/lib/exit-code-registry.cjs",
"scripts/lib/macos-conformance-tier.generated.cjs",
"scripts/lib/ndjson-reporter.cjs",
"scripts/lib/npm-version-check-diagnosis.cjs",
"scripts/lib/platform-conformance-tier.generated.cjs",
"scripts/lib/shellcheck-fetch.cjs",
"scripts/lib/suite-detection.cjs",
"skills/gsd-add-tests/SKILL.md",
"skills/gsd-ai-integration-phase/SKILL.md",
"skills/gsd-audit-fix/SKILL.md",
"skills/gsd-audit-milestone/SKILL.md",
"skills/gsd-audit-uat/SKILL.md",
"skills/gsd-autonomous/SKILL.md",
"skills/gsd-capture/SKILL.md",
"skills/gsd-cleanup/SKILL.md",
"skills/gsd-code-review/SKILL.md",
"skills/gsd-complete-milestone/SKILL.md",
"skills/gsd-config/SKILL.md",
"skills/gsd-debug/SKILL.md",
"skills/gsd-discuss-phase/SKILL.md",
"skills/gsd-docs-update/SKILL.md",
"skills/gsd-eval-review/SKILL.md",
"skills/gsd-execute-phase/SKILL.md",
"skills/gsd-explore/SKILL.md",
"skills/gsd-extract-learnings/SKILL.md",
"skills/gsd-fast/SKILL.md",
"skills/gsd-forensics/SKILL.md",
"skills/gsd-graphify/SKILL.md",
"skills/gsd-health/SKILL.md",
"skills/gsd-help/SKILL.md",
"skills/gsd-import/SKILL.md",
"skills/gsd-inbox/SKILL.md",
"skills/gsd-ingest-docs/SKILL.md",
"skills/gsd-manager/SKILL.md",
"skills/gsd-map-codebase/SKILL.md",
"skills/gsd-mempalace-capture/SKILL.md",
"skills/gsd-mempalace-recall/SKILL.md",
"skills/gsd-milestone-summary/SKILL.md",
"skills/gsd-mvp-phase/SKILL.md",
"skills/gsd-new-milestone/SKILL.md",
"skills/gsd-new-project/SKILL.md",
"skills/gsd-next/SKILL.md",
"skills/gsd-ns-context/SKILL.md",
"skills/gsd-ns-ideate/SKILL.md",
"skills/gsd-ns-manage/SKILL.md",
"skills/gsd-ns-project/SKILL.md",
"skills/gsd-ns-review/SKILL.md",
"skills/gsd-ns-workflow/SKILL.md",
"skills/gsd-onboard/SKILL.md",
"skills/gsd-pause-work/SKILL.md",
"skills/gsd-phase/SKILL.md",
"skills/gsd-plan-phase/SKILL.md",
"skills/gsd-plan-review-convergence/SKILL.md",
"skills/gsd-pr-branch/SKILL.md",
"skills/gsd-profile-user/SKILL.md",
"skills/gsd-progress/SKILL.md",
"skills/gsd-quick-batch/SKILL.md",
"skills/gsd-quick/SKILL.md",
"skills/gsd-resume-work/SKILL.md",
"skills/gsd-review-backlog/SKILL.md",
"skills/gsd-review/SKILL.md",
"skills/gsd-secure-phase/SKILL.md",
"skills/gsd-settings/SKILL.md",
"skills/gsd-ship/SKILL.md",
"skills/gsd-sketch/SKILL.md",
"skills/gsd-spec-phase/SKILL.md",
"skills/gsd-spike/SKILL.md",
"skills/gsd-stats/SKILL.md",
"skills/gsd-surface/SKILL.md",
"skills/gsd-thread/SKILL.md",
"skills/gsd-ui-phase/SKILL.md",
"skills/gsd-ui-review/SKILL.md",
"skills/gsd-ultraplan-phase/SKILL.md",
"skills/gsd-undo/SKILL.md",
"skills/gsd-update/SKILL.md",
"skills/gsd-validate-phase/SKILL.md",
"skills/gsd-verify-work/SKILL.md",
"skills/gsd-workspace/SKILL.md",
"skills/gsd-workstreams/SKILL.md"
]