Files
msd-core/tests/workflow-size-baseline.json
Tom Boucher b5ce72f729 fix(#2119): single SECURITY.md writer — auditor is return-only (#2154)
* fix(2119): single SECURITY.md writer — auditor is return-only

The gsd-security-auditor held Write/Edit and was instructed to write
SECURITY.md (no <N>- prefix, no template frontmatter), while the
orchestrator's Step 6 also wrote the correct padded <N>-SECURITY.md
from templates/SECURITY.md. Two writers, two naming conventions, two
shapes — the auditor's unprefixed file was invisible to the workflow's
*-SECURITY.md glob detector and unparseable for the threats_open gate.

Fix (option 1 from the issue): make the auditor return-only.
- Remove Write/Edit from auditor's tools
- Rewrite all 'Write SECURITY.md' instructions to 'Return structured
  verdict' with threats_open count
- Add explicit constraint in workflow Step 5 spawn prompt
- Update existing test (was asserting Write in tools — now asserts absence)
- Add new regression test for single-writer contract
- Update docs/AGENTS.md stale Tools/Produces rows
- Regenerate golden fixtures + agent size baseline

* docs(changeset): backfill PR number (#2154)

* chore(#2119): regenerate pi/qwen golden fixtures after next merge

The single-writer change edits gsd-core/workflows/secure-phase.md and
agents/gsd-security-auditor.md; pi.json (added on next) and qwen.json (merge
straggler) were the only runtime fixtures still holding pre-change hashes for
those files. All other runtimes already reflect the change. Regenerated via
the sanctioned gen-golden-install-parity script.

* merge origin/next — regenerate goldens + baseline for merged state

* fix slash-command syntax: /gsd-secure-phase → /gsd:secure-phase (#2154 CI fix)
2026-07-13 00:47:15 -04:00

94 lines
2.4 KiB
JSON

{
"add-backlog.md": 7176,
"add-phase.md": 7247,
"add-tests.md": 16961,
"add-todo.md": 8996,
"ai-integration-phase.md": 14805,
"analyze-dependencies.md": 3887,
"audit-fix.md": 11717,
"audit-milestone.md": 18448,
"audit-uat.md": 7469,
"autonomous.md": 42474,
"check-todos.md": 9475,
"cleanup.md": 9941,
"code-review-fix.md": 24320,
"code-review.md": 31916,
"complete-milestone.md": 31071,
"debug.md": 14241,
"diagnose-issues.md": 12864,
"discovery-phase.md": 8651,
"discuss-phase-assumptions.md": 27302,
"discuss-phase-power.md": 11273,
"discuss-phase.md": 31986,
"do.md": 10353,
"docs-update.md": 55706,
"edit-phase.md": 12927,
"eval-review.md": 9967,
"execute-phase.md": 93132,
"execute-plan.md": 32655,
"explore.md": 10541,
"extract-learnings.md": 12893,
"fast.md": 4790,
"forensics.md": 12531,
"graduation.md": 11622,
"health.md": 11868,
"help.md": 1722,
"import.md": 14648,
"inbox.md": 14407,
"ingest-docs.md": 18380,
"insert-phase.md": 8987,
"list-phase-assumptions.md": 4305,
"list-seeds.md": 6987,
"list-workspaces.md": 5699,
"manager.md": 27302,
"map-codebase.md": 20833,
"milestone-summary.md": 11842,
"mvp-phase.md": 13626,
"new-milestone.md": 32888,
"new-project.md": 66182,
"new-workspace.md": 11298,
"next.md": 20138,
"node-repair.md": 4173,
"note.md": 6563,
"onboard.md": 8590,
"pause-work.md": 14441,
"plan-milestone-gaps.md": 11809,
"plan-phase.md": 93113,
"plan-review-convergence.md": 23512,
"plant-seed.md": 11785,
"pr-branch.md": 15963,
"profile-user.md": 21246,
"progress.md": 30599,
"quick.md": 50470,
"reapply-patches.md": 20312,
"remove-phase.md": 8513,
"remove-workspace.md": 7551,
"resume-project.md": 17270,
"review.md": 47168,
"scan.md": 7732,
"secure-phase.md": 13622,
"session-report.md": 4044,
"settings-advanced.md": 40019,
"settings-integrations.md": 15892,
"settings.md": 33467,
"ship.md": 25222,
"sketch-wrap-up.md": 14267,
"sketch.md": 20004,
"smart-entry.md": 11124,
"spec-phase.md": 31987,
"spike-wrap-up.md": 15136,
"spike.md": 24561,
"stats.md": 6762,
"sync-skills.md": 6125,
"thread.md": 12508,
"transition.md": 22060,
"ui-phase.md": 26054,
"ui-review.md": 11216,
"ultraplan-phase.md": 10512,
"undo.md": 10431,
"update.md": 20914,
"validate-phase.md": 10849,
"verify-phase.md": 40923,
"verify-work.md": 40247
}