* feat(#4221): gsd-secret-read-guard PreToolUse hook + registration Add hooks/gsd-secret-read-guard.js, a blocking PreToolUse guard on Read|Grep|Bash that denies reads of .env, .env.<suffix> and .secrets (the .env.example/.sample/.template/.dist templates stay readable). Read checks file_path; Grep checks an explicit path and judges the glob per brace alternative; Bash runs a two-pass token scan (quotes, comments, redirects with fd digits, separators, $( )/backtick/<( ) recursion, heredoc bodies never scanned as commands, nested bash -c/eval rescans, git <ref>:<path> shapes) with a closed non-reading exemption set for existence checks. Fail-open crash policy; 1 MiB commands are denied as command-too-large; more than 64 glob alternatives as glob-too-complex. Why: Claude Code 2.1.259 makes every `cd DIR && grep …` compound prompt for approval whenever any Read() deny rule exists, even in auto mode. A hook denial is not a permission rule and never arms that check. The installer-written deny rules are retired in the follow-up commit. Registration: hooks.json (Read|Grep|Bash, timeout 5), build-hooks HOOKS_TO_COPY, managed-hooks-registry, runtime-hooks-surface (blocking guard with BLOCKING_GUARD_TIMEOUT_S; Kimi ReadFile|Grep|Shell), shell-command-projection managed sets, installer-migration-report, OpenCode/Kilo plugin (grep tool mapping, include -> glob, dispatch), docs tables in five locales, ADR-766 always-on list, regen:derived fixtures, and a new table-driven unit suite. * test(#4221): pin the secret-read guard in existing hook gates Register gsd-secret-read-guard.js in every existing hook gate: the hooks-crash-policy table (deny row; 6 -> 7 deny cases), plugin-manifest REQUIRED_HOOKS and its Read|Grep|Bash group, docs-hooks-table-parity EXPECTED_SURFACE_HOOKS, install.test MANAGED_JS_HOOKS, install-minimal- hooks JS_HOOKS/BLOCKING_GUARDS, portable-node-runner GUARD_HOOKS, kilo-upgrades PLUGIN_GUARD_HOOKS, the Kimi normalization-parity and typed-payload floors, the OpenCode adapter (grep mapping, include -> glob, three dispatch tests) and a Kimi TOML matcher assertion. * fix(#4221): retire installer Read() deny rules (legacy filter) Rename GSD_CLAUDE_DENY_PERMISSIONS to GSD_CLAUDE_LEGACY_DENY_PERMISSIONS and stop adding the three Read(.env) / Read(.env.*) / Read(.secrets) strings. mergeClaudePermissions now only filters them out of an existing permissions.deny: an absent deny key stays absent, a malformed one is still repaired to [], and an array emptied by the filter is deleted so no `"deny": []` residue is left. Uninstall filters the same legacy list and, symmetric with the Antigravity branch, drops an emptied allow or deny key and an emptied permissions object. Unlike the #2278 allow-side migration there is no surviving current deny list, so the constant is renamed rather than mirrored. Removal is byte-exact: a hand-written identical rule is indistinguishable from the installer's and is removed too (the manifest never recorded permission strings). USER-GUIDE and CONTEXT.md updated. * test(#4221): flip install-regressions deny-rule assertions to the retired shape The fresh-merge, non-destructive merge, idempotency, end-to-end install, reinstall and uninstall assertions now expect no Read(.env*) deny rules and no permissions.deny key on a fresh install; the deny:null repair case is kept. A new describe block covers the legacy filter: retired strings removed with a user entry kept, partial sets, near-miss strings untouched, idempotency, GSD-only deny array deleted, a pre-existing empty deny preserved, and uninstall symmetry for allow/deny/permissions. * chore(#4221): add changeset fragment for PR #4236 * fix(#4221): case-fold names; scan shell stdin and xargs pipes Review round 1 (trek-e): - Blocker: secret-name matching is now case-insensitive in the Read, Grep (path and glob) and Bash paths, so `.ENV` / `.Secrets` on a case-insensitive filesystem are recognized as the same secret file. - Major: a shell interpreter's script is now scanned wherever it comes from. The tokenizer keeps heredoc bodies as per-segment tokens and records separator operators; pass 2 groups by segment id and resolves bash/sh/zsh/dash/ksh/su invocation mode: `-c` (including combined `-lc`) scans the script operand, a file operand is checked as a file (a `<( )` operand's echo/printf output is reconstructed), otherwise stdin is the script and heredocs, here-strings and a piped echo/printf source are scanned. `eval` joins all its operands; `source`/`.` handle process substitution. Data heredocs (`cat <<EOF`, the commit-message shape) stay unscanned. - Major: `… | xargs <cmd>` checks the upstream segment's operands as file names when the sub-command reads (`echo .env | xargs cat`, `find . -name .env | xargs cat`); `-a`/`--arg-file` suppresses the inference; a shell sub-command's `-c` script is scanned. Header, USER-GUIDE bullet and changeset updated; documented gaps now include piped scripts from non-echo sources and `exec`/`timeout` wrappers. 60 new suite cases pin the block and allow shapes. --------- Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
GSD Core ドキュメント
ドキュメントは 4 つの象限で構成されています。チュートリアルは実践で学ぶ、ハウツーガイドは特定のタスクを解決する、リファレンスは信頼できる情報を示す、解説はコンセプトと設計上の決定を探求する。
言語バージョン: English · Português (pt-BR) · 日本語 · 简体中文 · 한국어
チュートリアル
- はじめてのプロジェクト — インストールから最初のフェーズ出荷まで、確実な一本道
- 既存コードベースのオンボーディング — ブラウンフィールドのリポジトリに GSD Core を導入する
How-to guides
- ランタイムへのインストール — サポートされる全 16 ランタイムのランタイム別インストール手順
- フェーズを議論する — 計画を始める前に実装上の決定事項を記録する
- フェーズを計画する — リサーチを実行し、作業を分解し、計画の品質を検証する
- フェーズを実行する — 新鮮なコンテキストのサブエージェントで並列ウェーブとして計画を実行する
- 検証と出荷 — 完成した作業を確認し、障害を診断し、PR を作成する
- フェーズを自律的に実行する — 無人フェーズ実行に自律モードを使用する
- クイックおよびファストタスクを処理する — フェーズループ外のアドホック作業に
/gsd-quickと/gsd-fastを使用する - モデルプロファイルを設定する — クオリティ・バランス・バジェットのモデルティア間を切り替える
- クロス AI レビューをセットアップする — プライマリエージェントが生成したコードをレビューする 2 番目の AI を設定する
- ワークストリームで並列作業する — ワークストリームを使って独立した作業ラインを同時に実行する
- ワークスペースで作業を隔離する — ワークスペースを使って実験的またはリスクのある変更をサンドボックス化する
- 失敗した実行をデバッグする — 壊れたまたは不完全なフェーズ実行を診断・回復する
- スパイクとスケッチ — 計画を確定する前の探索的作業に
/gsd-spikeと/gsd-sketchを使用する - UI フェーズを設計する — フロントエンドおよびビジュアル作業に UI フェーズループを使用する
- トラッカーイシューから GSD を動かす — GitHub、Linear、または Jira のイシューからフェーズを開始する
- GSD 2 から移行する — 既存の GSD 2 プロジェクトを GSD Core にアップグレードする
- GSD をアップデートする — インストーラーを再実行して最新リリースを取得する
- 回復とトラブルシューティング — よくある問題を修正し、コンテキストを再構築し、アンインストールする
リファレンス
- コマンド — フラグと例を含むすべてのコマンド
- 設定 — 完全な設定スキーマ、モデルプロファイル、Git ブランチ戦略
- CLI ツール — ワークフローとエージェント向け
gsd-tools.cjsプログラマティック API - 機能 — 完全な機能インデックス
- インベントリ — インストール済みスキルとサーフェスマップ
- STATE.md スキーマ —
.planning/STATE.mdのフィールド別リファレンス - CONTEXT.md スキーマ —
.planning/phases/<N>/CONTEXT.mdのフィールド別リファレンス - PLAN.md スキーマ —
.planning/phases/<N>/PLAN.mdのフィールド別リファレンス - 計画アーティファクト — すべての
.planning/ファイルとその役割
解説
- コンテキストエンジニアリング — コンテキストの腐敗がどのように形成され、GSD Core がどのように防ぐか
- フェーズループ — Discuss → Plan → Execute → Verify → Ship サイクルの設計理念
- マルチエージェントオーケストレーション — サブエージェントがどのように生成・スコープ設定・調整されるか
- セキュリティモデル — 信頼境界、パーミッション、安全な自動化
- アーキテクチャ — システムアーキテクチャ、エージェントモデル、データフロー
- ディスカスモード —
/gsd-discuss-phaseの assumptions モードと interview モード - コンテキストモニタリング — コンテキストウィンドウ監視フックのアーキテクチャ
- イシュー駆動オーケストレーション — 既存のプリミティブを使ってトラッカーイシューから GSD を動かすレシピ
Related
- ルート README — ランディングページ、クイックスタート、ドキュメント概要
- 変更履歴 — リリース履歴