* fix(#1577): isolate WebFetch/WebSearch ingress + opt-in injection blocking Split A of #1573 (security-critical). Scans WebFetch/WebSearch output (the largest untrusted channel) in gsd-read-injection-scanner; shared untrusted-input-boundary reference @-included by the 8 ingest agents (randomized per-wrap delimiters, in-prompt self-scan guard, task-anchoring); opt-in security.injection_blocking (default advisory — non-breaking). arXiv: 2506.05739 (PPA), 2507.15219 (PromptArmor), 2504.20472 (Referencing), 2503.00061 (defense-in-depth). * fix(#1577): address review — honest blocking docs, config key, ADR, property test, revert localized - A1: rewrote the opt-in-blocking doc + Security changeset honestly — the PostToolUse hook is a circuit-breaker (halts the agent's next step), NOT a redactor; it does not scrub content already in the transcript. The prompt-level data/instruction boundary is the primary control. - A2: registered security.injection_blocking in the config schema + defaults manifests (default false) + an e2e config-roundtrip test; the dotted setter writes the nested shape the hook reads. - A3: reverted the 4 hand-edited localized security-model.md (canonical EN only, per convention). - A5: ADR-1577 (untrusted-input boundary + opt-in blocking; redaction-vs-circuit-breaker rationale). - A6: property test — scanner never crashes / only emits valid JSON on unicode/large/malformed input. - Also: inventory (untrusted-input-boundary.md) + agent-size baseline (8 ingest agents) + drift-guard matcher update (Read -> Read|WebFetch|WebSearch). A7 (content<20 early-exit) left as the noted pre-existing follow-up. * fix(#1577): allowlist untrusted-input-boundary.md in injection-scan CI gate The new reference quotes injection phrases ('ignore previous instructions', 'you are now…') as examples agents must NOT comply with, tripping the repo's own prompt-injection-scan.sh diff gate (the standalone 'security' CI job, red on HEAD). Allowlist it alongside the other security docs (security-model.md, TEST-EXAMPLES.md) that legitimately demonstrate injection patterns. The JS scanner test doesn't scan references/, so only the shell gate needed it. Verified: scan --diff origin/next -> 0 findings; scanner JS test 15/15. * fix(#1577): cover AC #2's gsd-ui-researcher + gsd-assumptions-analyzer trek-e Major 1: the @-included set dropped two AC #2 agents. Restore them so no named web-ingress agent is uncovered, keeping the two justified additions (gsd-ai-researcher, gsd-domain-researcher). Final set = AC's 8 + 2 = 10. - gsd-ui-researcher carries the full WebSearch/WebFetch + MCP-fetch toolset. - gsd-assumptions-analyzer reads 5-15 codebase source files (external/source- document ingress per the boundary), though it has no web tools. INGEST_AGENTS in the isolation test now asserts all 10; size baselines regenerated (+60 bytes each, both well under the DEFAULT cap); changeset reworded 8 -> 10. Verified: untrusted-input-isolation 14/14; agent-size-budget 39/39. * docs(#1577): document security.injection_blocking + boundary seam trek-e Major 2 + Minor: - docs/CONFIGURATION.md: add the top-level security.injection_blocking key to the Full Schema and a Security Settings subsection, distinguishing it from the workflow.security_* namespace; honest circuit-breaker-not-redactor framing matching ADR-1577 / security-model. - CONTEXT.md: add the 'Untrusted-input boundary' seam glossary entry. Verified: lint:docs ok; config-field-docs + contributor-standards green. * test(#1577): make read-injection property test git-text, not binary trek-e nit (and more): the file embedded a raw U+FFFF AND a raw NUL byte as degenerate-edge inputs. The NUL is what actually made git classify it binary (git binary = NUL in first 8K). Replace both with text-safe escapes that keep the identical runtime values: '\\x00' and String.fromCodePoint(0xFFFF). File now diffs/blames line-by-line. Verified: property test 2/2; no NUL/raw-noncharacter bytes remain. * docs(#1577): align untrusted boundary docs Name all 10 ingress agents in INVENTORY/security-model and allowlist the intentional read-injection property corpus for the prompt-injection scanner. * docs(#1577): align ADR ingest agent count Update ADR-1577 from 8 to 10 ingest agents so it matches the actual boundary include set and the rest of the docs. --------- Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
106 lines
3.2 KiB
JSON
106 lines
3.2 KiB
JSON
{
|
|
"_comment": "Canonical CONFIG_DEFAULTS for the Configuration Module. Nested shape is canonical. CJS flat projection (branching_strategy, sub_repos, etc.) is handled by consumers at the boundary. Security keys (security_enforcement, security_asvs_level, security_block_on) and post_planning_gaps live in workflow.* as their canonical location. resolve_model_ids, context_window, phase_naming are CJS-originated top-level keys included here. brave_search, firecrawl, exa_search default to false in the manifest; at runtime buildNewProjectConfig detects API keys. The plan_checker (CJS flat) → workflow.plan_check (canonical nested) divergence is resolved: canonical name is workflow.plan_check. _auto_chain_active is a runtime-state field included for completeness.",
|
|
"model_profile": "balanced",
|
|
"commit_docs": true,
|
|
"parallelization": true,
|
|
"search_gitignored": false,
|
|
"brave_search": false,
|
|
"firecrawl": false,
|
|
"exa_search": false,
|
|
"resolve_model_ids": false,
|
|
"context_window": 200000,
|
|
"phase_naming": "sequential",
|
|
"project_code": null,
|
|
"phase_id_convention": null,
|
|
"mode": "interactive",
|
|
"claude_md_path": "./.claude/CLAUDE.md",
|
|
"git": {
|
|
"branching_strategy": "none",
|
|
"create_tag": true,
|
|
"base_branch": null,
|
|
"phase_branch_template": "gsd/phase-{phase}-{slug}",
|
|
"milestone_branch_template": "gsd/{milestone}-{slug}",
|
|
"quick_branch_template": null
|
|
},
|
|
"workflow": {
|
|
"research": true,
|
|
"plan_check": true,
|
|
"verifier": true,
|
|
"nyquist_validation": true,
|
|
"ai_integration_phase": true,
|
|
"human_verify_mode": "end-of-phase",
|
|
"auto_advance": false,
|
|
"_auto_chain_active": false,
|
|
"node_repair": true,
|
|
"node_repair_budget": 2,
|
|
"ui_phase": true,
|
|
"ui_safety_gate": true,
|
|
"text_mode": false,
|
|
"research_before_questions": false,
|
|
"discuss_mode": "discuss",
|
|
"skip_discuss": false,
|
|
"max_discuss_passes": 3,
|
|
"subagent_timeout": 300000,
|
|
"context_coverage_gate": true,
|
|
"code_review": true,
|
|
"code_review_depth": "standard",
|
|
"code_review_command": null,
|
|
"pattern_mapper": true,
|
|
"plan_bounce": false,
|
|
"plan_bounce_script": null,
|
|
"plan_bounce_passes": 2,
|
|
"auto_prune_state": false,
|
|
"post_planning_gaps": true,
|
|
"security_enforcement": true,
|
|
"security_asvs_level": 1,
|
|
"security_block_on": "high",
|
|
"context_guard_mode": "warn"
|
|
},
|
|
"planning": {
|
|
"commit_docs": true,
|
|
"search_gitignored": false,
|
|
"sub_repos": [],
|
|
"granularity": "standard"
|
|
},
|
|
"hooks": {
|
|
"context_warnings": true,
|
|
"workflow_guard": false
|
|
},
|
|
"ship": {
|
|
"pr_body_sections": []
|
|
},
|
|
"graphify": {
|
|
"auto_update": false
|
|
},
|
|
"agent_skills": {},
|
|
"effort": {
|
|
"default": "high",
|
|
"routing_tier_defaults": {
|
|
"light": "low",
|
|
"standard": "high",
|
|
"heavy": "xhigh"
|
|
},
|
|
"agent_overrides": {}
|
|
},
|
|
"fast_mode": {
|
|
"enabled": false,
|
|
"routing_tier_defaults": {
|
|
"light": true,
|
|
"standard": false,
|
|
"heavy": false
|
|
},
|
|
"agent_overrides": {}
|
|
},
|
|
"plan_review": {
|
|
"source_grounding": true,
|
|
"source_grounding_authority": "grep"
|
|
},
|
|
"capabilities": {
|
|
"strict_known_registries": null,
|
|
"auto_update": false
|
|
},
|
|
"security": {
|
|
"injection_blocking": false
|
|
}
|
|
}
|