* feat(#4221): gsd-secret-read-guard PreToolUse hook + registration Add hooks/gsd-secret-read-guard.js, a blocking PreToolUse guard on Read|Grep|Bash that denies reads of .env, .env.<suffix> and .secrets (the .env.example/.sample/.template/.dist templates stay readable). Read checks file_path; Grep checks an explicit path and judges the glob per brace alternative; Bash runs a two-pass token scan (quotes, comments, redirects with fd digits, separators, $( )/backtick/<( ) recursion, heredoc bodies never scanned as commands, nested bash -c/eval rescans, git <ref>:<path> shapes) with a closed non-reading exemption set for existence checks. Fail-open crash policy; 1 MiB commands are denied as command-too-large; more than 64 glob alternatives as glob-too-complex. Why: Claude Code 2.1.259 makes every `cd DIR && grep …` compound prompt for approval whenever any Read() deny rule exists, even in auto mode. A hook denial is not a permission rule and never arms that check. The installer-written deny rules are retired in the follow-up commit. Registration: hooks.json (Read|Grep|Bash, timeout 5), build-hooks HOOKS_TO_COPY, managed-hooks-registry, runtime-hooks-surface (blocking guard with BLOCKING_GUARD_TIMEOUT_S; Kimi ReadFile|Grep|Shell), shell-command-projection managed sets, installer-migration-report, OpenCode/Kilo plugin (grep tool mapping, include -> glob, dispatch), docs tables in five locales, ADR-766 always-on list, regen:derived fixtures, and a new table-driven unit suite. * test(#4221): pin the secret-read guard in existing hook gates Register gsd-secret-read-guard.js in every existing hook gate: the hooks-crash-policy table (deny row; 6 -> 7 deny cases), plugin-manifest REQUIRED_HOOKS and its Read|Grep|Bash group, docs-hooks-table-parity EXPECTED_SURFACE_HOOKS, install.test MANAGED_JS_HOOKS, install-minimal- hooks JS_HOOKS/BLOCKING_GUARDS, portable-node-runner GUARD_HOOKS, kilo-upgrades PLUGIN_GUARD_HOOKS, the Kimi normalization-parity and typed-payload floors, the OpenCode adapter (grep mapping, include -> glob, three dispatch tests) and a Kimi TOML matcher assertion. * fix(#4221): retire installer Read() deny rules (legacy filter) Rename GSD_CLAUDE_DENY_PERMISSIONS to GSD_CLAUDE_LEGACY_DENY_PERMISSIONS and stop adding the three Read(.env) / Read(.env.*) / Read(.secrets) strings. mergeClaudePermissions now only filters them out of an existing permissions.deny: an absent deny key stays absent, a malformed one is still repaired to [], and an array emptied by the filter is deleted so no `"deny": []` residue is left. Uninstall filters the same legacy list and, symmetric with the Antigravity branch, drops an emptied allow or deny key and an emptied permissions object. Unlike the #2278 allow-side migration there is no surviving current deny list, so the constant is renamed rather than mirrored. Removal is byte-exact: a hand-written identical rule is indistinguishable from the installer's and is removed too (the manifest never recorded permission strings). USER-GUIDE and CONTEXT.md updated. * test(#4221): flip install-regressions deny-rule assertions to the retired shape The fresh-merge, non-destructive merge, idempotency, end-to-end install, reinstall and uninstall assertions now expect no Read(.env*) deny rules and no permissions.deny key on a fresh install; the deny:null repair case is kept. A new describe block covers the legacy filter: retired strings removed with a user entry kept, partial sets, near-miss strings untouched, idempotency, GSD-only deny array deleted, a pre-existing empty deny preserved, and uninstall symmetry for allow/deny/permissions. * chore(#4221): add changeset fragment for PR #4236 * fix(#4221): case-fold names; scan shell stdin and xargs pipes Review round 1 (trek-e): - Blocker: secret-name matching is now case-insensitive in the Read, Grep (path and glob) and Bash paths, so `.ENV` / `.Secrets` on a case-insensitive filesystem are recognized as the same secret file. - Major: a shell interpreter's script is now scanned wherever it comes from. The tokenizer keeps heredoc bodies as per-segment tokens and records separator operators; pass 2 groups by segment id and resolves bash/sh/zsh/dash/ksh/su invocation mode: `-c` (including combined `-lc`) scans the script operand, a file operand is checked as a file (a `<( )` operand's echo/printf output is reconstructed), otherwise stdin is the script and heredocs, here-strings and a piped echo/printf source are scanned. `eval` joins all its operands; `source`/`.` handle process substitution. Data heredocs (`cat <<EOF`, the commit-message shape) stay unscanned. - Major: `… | xargs <cmd>` checks the upstream segment's operands as file names when the sub-command reads (`echo .env | xargs cat`, `find . -name .env | xargs cat`); `-a`/`--arg-file` suppresses the inference; a shell sub-command's `-c` script is scanned. Header, USER-GUIDE bullet and changeset updated; documented gaps now include piped scripts from non-echo sources and `exec`/`timeout` wrappers. 60 new suite cases pin the block and allow shapes. --------- Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
GSD Core 문서
문서는 네 가지 유형으로 구성됩니다. 튜토리얼은 직접 해보며 배우고, how-to 가이드는 특정 작업을 해결하며, 레퍼런스는 권위 있는 사실을 제시하고, 설명은 개념과 설계 결정을 탐구합니다.
언어 버전: English · Português (pt-BR) · 日本語 · 简体中文 · 한국어
튜토리얼
- 첫 번째 프로젝트 — 설치부터 첫 단계 출시까지, 확실한 한 가지 경로
- 기존 코드베이스 온보딩 — 기존 저장소에 GSD Core 적용하기
How-to guides
- 런타임에 설치하기 — 지원하는 15개 런타임 각각의 설치 단계
- 단계 논의하기 — 기획 시작 전 구현 결정 사항 정리
- 단계 기획하기 — 리서치 실행, 작업 분해, 플랜 품질 검증
- 단계 실행하기 — 새 컨텍스트 서브에이전트로 병렬 웨이브 실행
- 검증 및 출시 — 완료된 작업 검토, 오류 진단, PR 생성
- 단계 자율 실행하기 — 무인 단계 실행을 위한 자율 모드 사용
- 빠른 임시 작업 처리 — 단계 루프 외 임시 작업에
/gsd-quick과/gsd-fast활용 - 모델 프로필 설정 — 고품질, 균형, 예산 모델 티어 전환
- 크로스 AI 리뷰 설정 — 주 에이전트가 생성한 코드를 두 번째 AI가 검토하도록 설정
- 워크스트림으로 병렬 작업 — 워크스트림을 사용해 독립적인 작업 라인 동시 실행
- 워크스페이스로 작업 격리 — 워크스페이스로 실험적이거나 위험한 변경 사항 샌드박스 처리
- 실패한 실행 디버깅 — 깨지거나 불완전한 단계 실행 진단 및 복구
- 스파이크와 스케치 — 플랜 확정 전 탐색 작업에
/gsd-spike와/gsd-sketch활용 - UI 단계 설계 — 프론트엔드 및 시각적 작업에 UI 단계 루프 활용
- 트래커 이슈로 GSD 구동 — GitHub, Linear, Jira 이슈에서 단계 시작
- GSD 2에서 마이그레이션 — 기존 GSD 2 프로젝트를 GSD Core로 업그레이드
- GSD 업데이트 — 설치 프로그램을 재실행해 최신 릴리스 적용
- 복구 및 문제 해결 — 일반적인 문제 해결, 컨텍스트 재구축, 제거
레퍼런스
- 명령어 — 플래그와 예제가 포함된 모든 명령어
- 설정 — 전체 설정 스키마, 모델 프로필, git 브랜칭 전략
- CLI 도구 — 워크플로우와 에이전트를 위한
gsd-tools.cjs프로그래밍 API - 기능 — 전체 기능 색인
- 인벤토리 — 설치된 스킬과 서피스 맵
- STATE.md 스키마 —
.planning/STATE.md필드별 레퍼런스 - CONTEXT.md 스키마 —
.planning/phases/<N>/CONTEXT.md필드별 레퍼런스 - PLAN.md 스키마 —
.planning/phases/<N>/PLAN.md필드별 레퍼런스 - 기획 아티팩트 — 모든
.planning/파일과 역할
설명
- 컨텍스트 엔지니어링 — 컨텍스트 rot가 형성되는 방식과 GSD Core의 방지 방법
- 단계 루프 — 논의 → 기획 → 실행 → 검증 → 출시 사이클의 설계 근거
- 멀티 에이전트 오케스트레이션 — 서브에이전트의 생성, 범위 지정, 조율 방식
- 보안 모델 — 신뢰 경계, 권한, 안전한 자동화
- 아키텍처 — 시스템 아키텍처, 에이전트 모델, 데이터 흐름
- 논의 모드 —
/gsd-discuss-phase의 가정 모드와 인터뷰 모드 - 컨텍스트 모니터링 — 컨텍스트 창 모니터링 훅 아키텍처
- 이슈 기반 오케스트레이션 — 기존 프리미티브를 사용해 트래커 이슈로 GSD를 구동하는 레시피