Files
msd-core/tests/fixtures/install-tree/opencode.json
Cody Anderson 77e2472ca0 enhance(#4221): replace installer Read() deny rules with a managed secret-read guard hook (#4236)
* feat(#4221): gsd-secret-read-guard PreToolUse hook + registration

Add hooks/gsd-secret-read-guard.js, a blocking PreToolUse guard on
Read|Grep|Bash that denies reads of .env, .env.<suffix> and .secrets
(the .env.example/.sample/.template/.dist templates stay readable).
Read checks file_path; Grep checks an explicit path and judges the glob
per brace alternative; Bash runs a two-pass token scan (quotes, comments,
redirects with fd digits, separators, $( )/backtick/<( ) recursion,
heredoc bodies never scanned as commands, nested bash -c/eval rescans,
git <ref>:<path> shapes) with a closed non-reading exemption set for
existence checks. Fail-open crash policy; 1 MiB commands are denied as
command-too-large; more than 64 glob alternatives as glob-too-complex.

Why: Claude Code 2.1.259 makes every `cd DIR && grep …` compound prompt
for approval whenever any Read() deny rule exists, even in auto mode. A
hook denial is not a permission rule and never arms that check. The
installer-written deny rules are retired in the follow-up commit.

Registration: hooks.json (Read|Grep|Bash, timeout 5), build-hooks
HOOKS_TO_COPY, managed-hooks-registry, runtime-hooks-surface (blocking
guard with BLOCKING_GUARD_TIMEOUT_S; Kimi ReadFile|Grep|Shell),
shell-command-projection managed sets, installer-migration-report,
OpenCode/Kilo plugin (grep tool mapping, include -> glob, dispatch),
docs tables in five locales, ADR-766 always-on list, regen:derived
fixtures, and a new table-driven unit suite.

* test(#4221): pin the secret-read guard in existing hook gates

Register gsd-secret-read-guard.js in every existing hook gate: the
hooks-crash-policy table (deny row; 6 -> 7 deny cases), plugin-manifest
REQUIRED_HOOKS and its Read|Grep|Bash group, docs-hooks-table-parity
EXPECTED_SURFACE_HOOKS, install.test MANAGED_JS_HOOKS, install-minimal-
hooks JS_HOOKS/BLOCKING_GUARDS, portable-node-runner GUARD_HOOKS,
kilo-upgrades PLUGIN_GUARD_HOOKS, the Kimi normalization-parity and
typed-payload floors, the OpenCode adapter (grep mapping, include ->
glob, three dispatch tests) and a Kimi TOML matcher assertion.

* fix(#4221): retire installer Read() deny rules (legacy filter)

Rename GSD_CLAUDE_DENY_PERMISSIONS to GSD_CLAUDE_LEGACY_DENY_PERMISSIONS
and stop adding the three Read(.env) / Read(.env.*) / Read(.secrets)
strings. mergeClaudePermissions now only filters them out of an existing
permissions.deny: an absent deny key stays absent, a malformed one is
still repaired to [], and an array emptied by the filter is deleted so
no `"deny": []` residue is left. Uninstall filters the same legacy list
and, symmetric with the Antigravity branch, drops an emptied allow or
deny key and an emptied permissions object.

Unlike the #2278 allow-side migration there is no surviving current
deny list, so the constant is renamed rather than mirrored. Removal is
byte-exact: a hand-written identical rule is indistinguishable from the
installer's and is removed too (the manifest never recorded permission
strings). USER-GUIDE and CONTEXT.md updated.

* test(#4221): flip install-regressions deny-rule assertions to the retired shape

The fresh-merge, non-destructive merge, idempotency, end-to-end install,
reinstall and uninstall assertions now expect no Read(.env*) deny rules
and no permissions.deny key on a fresh install; the deny:null repair case
is kept. A new describe block covers the legacy filter: retired strings
removed with a user entry kept, partial sets, near-miss strings
untouched, idempotency, GSD-only deny array deleted, a pre-existing
empty deny preserved, and uninstall symmetry for allow/deny/permissions.

* chore(#4221): add changeset fragment for PR #4236

* fix(#4221): case-fold names; scan shell stdin and xargs pipes

Review round 1 (trek-e):

- Blocker: secret-name matching is now case-insensitive in the Read,
  Grep (path and glob) and Bash paths, so `.ENV` / `.Secrets` on a
  case-insensitive filesystem are recognized as the same secret file.
- Major: a shell interpreter's script is now scanned wherever it comes
  from. The tokenizer keeps heredoc bodies as per-segment tokens and
  records separator operators; pass 2 groups by segment id and resolves
  bash/sh/zsh/dash/ksh/su invocation mode: `-c` (including combined
  `-lc`) scans the script operand, a file operand is checked as a file
  (a `<( )` operand's echo/printf output is reconstructed), otherwise
  stdin is the script and heredocs, here-strings and a piped echo/printf
  source are scanned. `eval` joins all its operands; `source`/`.` handle
  process substitution. Data heredocs (`cat <<EOF`, the commit-message
  shape) stay unscanned.
- Major: `… | xargs <cmd>` checks the upstream segment's operands as
  file names when the sub-command reads (`echo .env | xargs cat`,
  `find . -name .env | xargs cat`); `-a`/`--arg-file` suppresses the
  inference; a shell sub-command's `-c` script is scanned.

Header, USER-GUIDE bullet and changeset updated; documented gaps now
include piped scripts from non-echo sources and `exec`/`timeout`
wrappers. 60 new suite cases pin the block and allow shapes.

---------

Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
2026-09-05 04:00:08 -04:00

604 lines
25 KiB
JSON

[
".gsd-profile",
"agents/gsd-advisor-researcher.md",
"agents/gsd-ai-researcher.md",
"agents/gsd-assumptions-analyzer.md",
"agents/gsd-code-fixer.md",
"agents/gsd-code-reviewer.md",
"agents/gsd-codebase-mapper.md",
"agents/gsd-debug-session-manager.md",
"agents/gsd-debugger.md",
"agents/gsd-doc-classifier.md",
"agents/gsd-doc-synthesizer.md",
"agents/gsd-doc-verifier.md",
"agents/gsd-doc-writer.md",
"agents/gsd-dom-verifier.md",
"agents/gsd-domain-researcher.md",
"agents/gsd-eval-auditor.md",
"agents/gsd-eval-planner.md",
"agents/gsd-executor.md",
"agents/gsd-framework-selector.md",
"agents/gsd-integration-checker.md",
"agents/gsd-intel-updater.md",
"agents/gsd-mempalace-curator.md",
"agents/gsd-nyquist-auditor.md",
"agents/gsd-pattern-mapper.md",
"agents/gsd-phase-researcher.md",
"agents/gsd-plan-checker.md",
"agents/gsd-planner.md",
"agents/gsd-project-researcher.md",
"agents/gsd-research-synthesizer.md",
"agents/gsd-roadmapper.md",
"agents/gsd-security-auditor.md",
"agents/gsd-ui-auditor.md",
"agents/gsd-ui-checker.md",
"agents/gsd-ui-researcher.md",
"agents/gsd-user-profiler.md",
"agents/gsd-verifier.md",
"commands/gsd-add-tests.md",
"commands/gsd-ai-integration-phase.md",
"commands/gsd-audit-fix.md",
"commands/gsd-audit-milestone.md",
"commands/gsd-audit-uat.md",
"commands/gsd-autonomous.md",
"commands/gsd-capture.md",
"commands/gsd-cleanup.md",
"commands/gsd-code-review.md",
"commands/gsd-complete-milestone.md",
"commands/gsd-config.md",
"commands/gsd-debug.md",
"commands/gsd-discuss-phase.md",
"commands/gsd-docs-update.md",
"commands/gsd-eval-review.md",
"commands/gsd-execute-phase.md",
"commands/gsd-explore.md",
"commands/gsd-extract-learnings.md",
"commands/gsd-fast.md",
"commands/gsd-forensics.md",
"commands/gsd-graphify.md",
"commands/gsd-health.md",
"commands/gsd-help.md",
"commands/gsd-import.md",
"commands/gsd-inbox.md",
"commands/gsd-ingest-docs.md",
"commands/gsd-manager.md",
"commands/gsd-map-codebase.md",
"commands/gsd-mempalace-capture.md",
"commands/gsd-mempalace-recall.md",
"commands/gsd-milestone-summary.md",
"commands/gsd-mvp-phase.md",
"commands/gsd-new-milestone.md",
"commands/gsd-new-project.md",
"commands/gsd-next.md",
"commands/gsd-ns-context.md",
"commands/gsd-ns-ideate.md",
"commands/gsd-ns-manage.md",
"commands/gsd-ns-project.md",
"commands/gsd-ns-review.md",
"commands/gsd-ns-workflow.md",
"commands/gsd-onboard.md",
"commands/gsd-pause-work.md",
"commands/gsd-phase.md",
"commands/gsd-plan-phase.md",
"commands/gsd-plan-review-convergence.md",
"commands/gsd-pr-branch.md",
"commands/gsd-profile-user.md",
"commands/gsd-progress.md",
"commands/gsd-quick-batch.md",
"commands/gsd-quick.md",
"commands/gsd-resume-work.md",
"commands/gsd-review-backlog.md",
"commands/gsd-review.md",
"commands/gsd-secure-phase.md",
"commands/gsd-settings.md",
"commands/gsd-ship.md",
"commands/gsd-sketch.md",
"commands/gsd-spec-phase.md",
"commands/gsd-spike.md",
"commands/gsd-stats.md",
"commands/gsd-surface.md",
"commands/gsd-thread.md",
"commands/gsd-ui-phase.md",
"commands/gsd-ui-review.md",
"commands/gsd-ultraplan-phase.md",
"commands/gsd-undo.md",
"commands/gsd-update.md",
"commands/gsd-validate-phase.md",
"commands/gsd-verify-work.md",
"commands/gsd-workspace.md",
"commands/gsd-workstreams.md",
"gsd-core/.gsd-runtime",
"gsd-core/VERSION",
"gsd-core/bin/check-latest-version.cjs",
"gsd-core/bin/ensure-runtime-build.cjs",
"gsd-core/bin/gsd-tools.cjs",
"gsd-core/bin/gsd_run",
"gsd-core/bin/shared/config-defaults.manifest.json",
"gsd-core/bin/shared/config-schema.manifest.json",
"gsd-core/bin/shared/exit-codes.json",
"gsd-core/bin/shared/exit-codes.sh",
"gsd-core/bin/shared/model-catalog.json",
"gsd-core/bin/shared/runtime-aliases.manifest.json",
"gsd-core/bin/verify-reapply-patches.cjs",
"gsd-core/contexts/dev.md",
"gsd-core/contexts/research.md",
"gsd-core/contexts/review.md",
"gsd-core/references/agent-contracts.md",
"gsd-core/references/agent-skills-bootstrap.md",
"gsd-core/references/ai-evals.md",
"gsd-core/references/ai-frameworks.md",
"gsd-core/references/api-coverage.md",
"gsd-core/references/artifact-types.md",
"gsd-core/references/autonomous-smart-discuss.md",
"gsd-core/references/autonomous-ui-design-contract.md",
"gsd-core/references/checkpoints.md",
"gsd-core/references/common-bug-patterns.md",
"gsd-core/references/context-budget.md",
"gsd-core/references/continuation-format.md",
"gsd-core/references/debugger-bug-taxonomy.md",
"gsd-core/references/debugger-fix-acceptance.md",
"gsd-core/references/debugger-philosophy.md",
"gsd-core/references/debugger-prevention.md",
"gsd-core/references/debugger-rca-branching.md",
"gsd-core/references/debugger-repro-hardening.md",
"gsd-core/references/debugger-sbfl.md",
"gsd-core/references/debugger-semantic-recall.md",
"gsd-core/references/debugger-techniques.md",
"gsd-core/references/decimal-phase-calculation.md",
"gsd-core/references/dispatch-isolation-gate.md",
"gsd-core/references/doc-conflict-engine.md",
"gsd-core/references/domain-probes.md",
"gsd-core/references/edge-probe-fixtures/01-round-half-even/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/01-round-half-even/requirements.json",
"gsd-core/references/edge-probe-fixtures/02-merge-intervals/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/02-merge-intervals/requirements.json",
"gsd-core/references/edge-probe-fixtures/03-truncate-graphemes/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/03-truncate-graphemes/requirements.json",
"gsd-core/references/edge-probe-fixtures/04-money-rounding/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/04-money-rounding/requirements.json",
"gsd-core/references/edge-probe-fixtures/05-list-dedupe/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/05-list-dedupe/requirements.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/requirements.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/resolutions.json",
"gsd-core/references/edge-probe.md",
"gsd-core/references/execute-mvp-tdd.md",
"gsd-core/references/execute-phase-between-wave-reset.md",
"gsd-core/references/execute-phase-context-guard.md",
"gsd-core/references/execute-phase-quota-recovery.md",
"gsd-core/references/execute-phase-requirement-revert.md",
"gsd-core/references/execute-phase-response-language.md",
"gsd-core/references/execute-phase-wave-guard.md",
"gsd-core/references/executor-examples.md",
"gsd-core/references/failing-direction.md",
"gsd-core/references/few-shot-examples/plan-checker.md",
"gsd-core/references/few-shot-examples/verifier.md",
"gsd-core/references/gate-prompts.md",
"gsd-core/references/gates.md",
"gsd-core/references/git-integration.md",
"gsd-core/references/git-planning-commit.md",
"gsd-core/references/gsd-run-resolver.md",
"gsd-core/references/honest-verifier.md",
"gsd-core/references/ios-scaffold.md",
"gsd-core/references/loop-hook-dispatch.md",
"gsd-core/references/mandatory-initial-read.md",
"gsd-core/references/model-profile-resolution.md",
"gsd-core/references/model-profiles.md",
"gsd-core/references/mvp-concepts.md",
"gsd-core/references/nyquist-compliance.md",
"gsd-core/references/offer-next.md",
"gsd-core/references/phase-argument-parsing.md",
"gsd-core/references/plan-checker-examples.md",
"gsd-core/references/planner-antipatterns.md",
"gsd-core/references/planner-chunked.md",
"gsd-core/references/planner-coupling.md",
"gsd-core/references/planner-failing-direction.md",
"gsd-core/references/planner-gap-closure.md",
"gsd-core/references/planner-graphify-auto-update.md",
"gsd-core/references/planner-guidance.md",
"gsd-core/references/planner-human-verify-mode.md",
"gsd-core/references/planner-interface-context.md",
"gsd-core/references/planner-load-graph-context.md",
"gsd-core/references/planner-mvp-mode.md",
"gsd-core/references/planner-preconditions.md",
"gsd-core/references/planner-quick-batch.md",
"gsd-core/references/planner-reversibility.md",
"gsd-core/references/planner-reviews.md",
"gsd-core/references/planner-revision.md",
"gsd-core/references/planner-source-audit.md",
"gsd-core/references/planner-verify-command-grounding.md",
"gsd-core/references/planning-config.md",
"gsd-core/references/prohibition-probe-fixtures/01-streak-reminder/expected.json",
"gsd-core/references/prohibition-probe-fixtures/02-clean-utility/expected.json",
"gsd-core/references/prohibition-probe-fixtures/03-multi-prohibition/expected.json",
"gsd-core/references/prohibition-probe.md",
"gsd-core/references/project-skills-discovery.md",
"gsd-core/references/questioning.md",
"gsd-core/references/research-documentation-lookup.md",
"gsd-core/references/research-philosophy.md",
"gsd-core/references/research-verification-protocol.md",
"gsd-core/references/response-language-directive.md",
"gsd-core/references/reviewer-instances.md",
"gsd-core/references/revision-loop.md",
"gsd-core/references/runtime-aware-dispatch.md",
"gsd-core/references/scout-codebase.md",
"gsd-core/references/security-asvs-levels.md",
"gsd-core/references/skeleton-template.md",
"gsd-core/references/sketch-interactivity.md",
"gsd-core/references/sketch-theme-system.md",
"gsd-core/references/sketch-tooling.md",
"gsd-core/references/sketch-variant-patterns.md",
"gsd-core/references/specless-probe-fallback.md",
"gsd-core/references/spidr-splitting.md",
"gsd-core/references/tdd.md",
"gsd-core/references/thinking-models-debug.md",
"gsd-core/references/thinking-models-execution.md",
"gsd-core/references/thinking-models-planning.md",
"gsd-core/references/thinking-models-research.md",
"gsd-core/references/thinking-models-verification.md",
"gsd-core/references/thinking-partner.md",
"gsd-core/references/ui-brand.md",
"gsd-core/references/ui-consideration-probe.md",
"gsd-core/references/universal-anti-patterns.md",
"gsd-core/references/untrusted-input-boundary.md",
"gsd-core/references/user-profiling.md",
"gsd-core/references/user-story-template.md",
"gsd-core/references/verification-overrides.md",
"gsd-core/references/verification-patterns.md",
"gsd-core/references/verifier-evidence-gate.md",
"gsd-core/references/verifier-phase-gates.md",
"gsd-core/references/verifier-wiring-patterns.md",
"gsd-core/references/verify-command-path-resolvability.md",
"gsd-core/references/verify-mvp-mode.md",
"gsd-core/references/workstream-flag.md",
"gsd-core/references/worktree-branch-check.md",
"gsd-core/references/worktree-path-safety.md",
"gsd-core/templates/AI-SPEC.md",
"gsd-core/templates/DEBUG.md",
"gsd-core/templates/README.md",
"gsd-core/templates/SECURITY.md",
"gsd-core/templates/UAT.md",
"gsd-core/templates/UI-SPEC.md",
"gsd-core/templates/VALIDATION.md",
"gsd-core/templates/claude-md.md",
"gsd-core/templates/codebase/architecture.md",
"gsd-core/templates/codebase/concerns.md",
"gsd-core/templates/codebase/conventions.md",
"gsd-core/templates/codebase/integrations.md",
"gsd-core/templates/codebase/stack.md",
"gsd-core/templates/codebase/structure.md",
"gsd-core/templates/codebase/testing.md",
"gsd-core/templates/config.json",
"gsd-core/templates/context.md",
"gsd-core/templates/continue-here.md",
"gsd-core/templates/copilot-instructions.md",
"gsd-core/templates/debug-subagent-prompt.md",
"gsd-core/templates/dev-preferences.md",
"gsd-core/templates/discovery.md",
"gsd-core/templates/discussion-log.md",
"gsd-core/templates/milestone-archive.md",
"gsd-core/templates/milestone.md",
"gsd-core/templates/phase-prompt.md",
"gsd-core/templates/planner-subagent-prompt.md",
"gsd-core/templates/project.md",
"gsd-core/templates/requirements.md",
"gsd-core/templates/research-project/ARCHITECTURE.md",
"gsd-core/templates/research-project/FEATURES.md",
"gsd-core/templates/research-project/PITFALLS.md",
"gsd-core/templates/research-project/STACK.md",
"gsd-core/templates/research-project/SUMMARY.md",
"gsd-core/templates/research.md",
"gsd-core/templates/retrospective.md",
"gsd-core/templates/roadmap.md",
"gsd-core/templates/spec.md",
"gsd-core/templates/state.md",
"gsd-core/templates/summary-complex.md",
"gsd-core/templates/summary-minimal.md",
"gsd-core/templates/summary-standard.md",
"gsd-core/templates/summary.md",
"gsd-core/templates/user-profile.md",
"gsd-core/templates/user-setup.md",
"gsd-core/templates/verification-report.md",
"gsd-core/workflows/_runtime-launcher.snippet.sh",
"gsd-core/workflows/add-backlog.md",
"gsd-core/workflows/add-phase.md",
"gsd-core/workflows/add-tests.md",
"gsd-core/workflows/add-todo.md",
"gsd-core/workflows/ai-integration-phase.md",
"gsd-core/workflows/analyze-dependencies.md",
"gsd-core/workflows/audit-fix.md",
"gsd-core/workflows/audit-milestone.md",
"gsd-core/workflows/audit-uat.md",
"gsd-core/workflows/autonomous.md",
"gsd-core/workflows/autonomous/steps/converge-banner.md",
"gsd-core/workflows/autonomous/steps/converge-dispatch-bg.md",
"gsd-core/workflows/autonomous/steps/converge-dispatch-inline.md",
"gsd-core/workflows/autonomous/steps/converge-fail-fast.md",
"gsd-core/workflows/autonomous/steps/converge-loop.md",
"gsd-core/workflows/check-todos.md",
"gsd-core/workflows/cleanup.md",
"gsd-core/workflows/code-review-fix.md",
"gsd-core/workflows/code-review.md",
"gsd-core/workflows/code-review/steps/dispatch-fix.md",
"gsd-core/workflows/code-review/steps/structural-pre-pass.md",
"gsd-core/workflows/complete-milestone.md",
"gsd-core/workflows/complete-milestone/steps/git-tag.md",
"gsd-core/workflows/debug.md",
"gsd-core/workflows/diagnose-issues.md",
"gsd-core/workflows/discuss-phase-assumptions.md",
"gsd-core/workflows/discuss-phase-assumptions/steps/auto-advance-dispatch.md",
"gsd-core/workflows/discuss-phase-power.md",
"gsd-core/workflows/discuss-phase.md",
"gsd-core/workflows/discuss-phase/modes/advisor.md",
"gsd-core/workflows/discuss-phase/modes/all.md",
"gsd-core/workflows/discuss-phase/modes/analyze.md",
"gsd-core/workflows/discuss-phase/modes/auto.md",
"gsd-core/workflows/discuss-phase/modes/batch.md",
"gsd-core/workflows/discuss-phase/modes/chain.md",
"gsd-core/workflows/discuss-phase/modes/default.md",
"gsd-core/workflows/discuss-phase/modes/power.md",
"gsd-core/workflows/discuss-phase/modes/text.md",
"gsd-core/workflows/discuss-phase/templates/checkpoint.json",
"gsd-core/workflows/discuss-phase/templates/context.md",
"gsd-core/workflows/discuss-phase/templates/discussion-log.md",
"gsd-core/workflows/do.md",
"gsd-core/workflows/docs-update.md",
"gsd-core/workflows/docs-update/steps/dispatch-monorepo-packages.md",
"gsd-core/workflows/edit-phase.md",
"gsd-core/workflows/eval-review.md",
"gsd-core/workflows/execute-phase.md",
"gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md",
"gsd-core/workflows/execute-phase/steps/executor-isolation-dispatch.md",
"gsd-core/workflows/execute-phase/steps/gap-closure-artifacts.md",
"gsd-core/workflows/execute-phase/steps/partial-wave.md",
"gsd-core/workflows/execute-phase/steps/per-plan-executor-routing.md",
"gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md",
"gsd-core/workflows/execute-phase/steps/post-merge-gate.md",
"gsd-core/workflows/execute-phase/steps/protected-branch.md",
"gsd-core/workflows/execute-phase/steps/regression-gate-run.md",
"gsd-core/workflows/execute-phase/steps/regression-gate.md",
"gsd-core/workflows/execute-phase/steps/tdd-applicability-resolution.md",
"gsd-core/workflows/execute-phase/steps/wave-post-gate-hooks.md",
"gsd-core/workflows/execute-phase/steps/worktree-recovery-policy.md",
"gsd-core/workflows/execute-plan.md",
"gsd-core/workflows/explore.md",
"gsd-core/workflows/extract-learnings.md",
"gsd-core/workflows/fast.md",
"gsd-core/workflows/forensics.md",
"gsd-core/workflows/graduation.md",
"gsd-core/workflows/health.md",
"gsd-core/workflows/help.md",
"gsd-core/workflows/help/modes/brief.md",
"gsd-core/workflows/help/modes/default.md",
"gsd-core/workflows/help/modes/full.md",
"gsd-core/workflows/help/modes/topic.md",
"gsd-core/workflows/import.md",
"gsd-core/workflows/inbox.md",
"gsd-core/workflows/ingest-docs.md",
"gsd-core/workflows/insert-phase.md",
"gsd-core/workflows/list-phase-assumptions.md",
"gsd-core/workflows/list-seeds.md",
"gsd-core/workflows/list-workspaces.md",
"gsd-core/workflows/manager.md",
"gsd-core/workflows/map-codebase.md",
"gsd-core/workflows/milestone-summary.md",
"gsd-core/workflows/mvp-phase.md",
"gsd-core/workflows/new-milestone.md",
"gsd-core/workflows/new-milestone/steps/project-md-milestone-write.md",
"gsd-core/workflows/new-milestone/steps/reset-phase-safety.md",
"gsd-core/workflows/new-project.md",
"gsd-core/workflows/new-project/steps/auto-mode-config.md",
"gsd-core/workflows/new-project/steps/auto-mode-detection.md",
"gsd-core/workflows/new-project/steps/codebase-map-offer.md",
"gsd-core/workflows/new-workspace.md",
"gsd-core/workflows/next.md",
"gsd-core/workflows/node-repair.md",
"gsd-core/workflows/note.md",
"gsd-core/workflows/onboard.md",
"gsd-core/workflows/pause-work.md",
"gsd-core/workflows/plan-phase.md",
"gsd-core/workflows/plan-phase/steps/adr-ingest-express-path.md",
"gsd-core/workflows/plan-phase/steps/chunked-planning-mode.md",
"gsd-core/workflows/plan-phase/steps/closed-phase-gate.md",
"gsd-core/workflows/plan-phase/steps/prd-express-gate.md",
"gsd-core/workflows/plan-phase/steps/prd-express-path.md",
"gsd-core/workflows/plan-phase/steps/research-only-early-exit.md",
"gsd-core/workflows/plan-phase/steps/research-only-modifiers.md",
"gsd-core/workflows/plan-phase/steps/reviews-prerequisite.md",
"gsd-core/workflows/plan-phase/steps/stall-detection-helpers.md",
"gsd-core/workflows/plan-phase/steps/windows-troubleshooting.md",
"gsd-core/workflows/plan-review-convergence.md",
"gsd-core/workflows/plant-seed.md",
"gsd-core/workflows/pr-branch.md",
"gsd-core/workflows/profile-user.md",
"gsd-core/workflows/progress.md",
"gsd-core/workflows/progress/steps/forensic-audit.md",
"gsd-core/workflows/progress/steps/mvp-display.md",
"gsd-core/workflows/quick-batch.md",
"gsd-core/workflows/quick-batch/steps/batch-init.md",
"gsd-core/workflows/quick-batch/steps/completion.md",
"gsd-core/workflows/quick-batch/steps/merge-wave.md",
"gsd-core/workflows/quick-batch/steps/plan-checker-loop.md",
"gsd-core/workflows/quick-batch/steps/planner-wave.md",
"gsd-core/workflows/quick-batch/steps/research-phase.md",
"gsd-core/workflows/quick-batch/steps/resume-mode.md",
"gsd-core/workflows/quick-batch/steps/verification-wave.md",
"gsd-core/workflows/quick-batch/steps/worktree-dispatch.md",
"gsd-core/workflows/quick.md",
"gsd-core/workflows/quick/steps/discussion-phase.md",
"gsd-core/workflows/quick/steps/plan-checker-loop.md",
"gsd-core/workflows/quick/steps/quick-verification.md",
"gsd-core/workflows/quick/steps/research-phase.md",
"gsd-core/workflows/quick/steps/worktree-pre-dispatch-commit.md",
"gsd-core/workflows/reapply-patches.md",
"gsd-core/workflows/remove-phase.md",
"gsd-core/workflows/remove-workspace.md",
"gsd-core/workflows/resume-project.md",
"gsd-core/workflows/review.md",
"gsd-core/workflows/review/steps/reviewer-instances-note-1.md",
"gsd-core/workflows/review/steps/reviewer-instances-note-2.md",
"gsd-core/workflows/scan.md",
"gsd-core/workflows/section-manifest.json",
"gsd-core/workflows/secure-phase.md",
"gsd-core/workflows/session-report.md",
"gsd-core/workflows/settings-advanced.md",
"gsd-core/workflows/settings-integrations.md",
"gsd-core/workflows/settings.md",
"gsd-core/workflows/ship.md",
"gsd-core/workflows/sketch-wrap-up.md",
"gsd-core/workflows/sketch.md",
"gsd-core/workflows/smart-entry.md",
"gsd-core/workflows/spec-phase.md",
"gsd-core/workflows/spike-wrap-up.md",
"gsd-core/workflows/spike.md",
"gsd-core/workflows/stats.md",
"gsd-core/workflows/sync-skills.md",
"gsd-core/workflows/thread.md",
"gsd-core/workflows/transition.md",
"gsd-core/workflows/transition/steps/workstream-collision-check.md",
"gsd-core/workflows/ui-phase.md",
"gsd-core/workflows/ui-review.md",
"gsd-core/workflows/ultraplan-phase.md",
"gsd-core/workflows/undo.md",
"gsd-core/workflows/update.md",
"gsd-core/workflows/update/steps/channel-banner.md",
"gsd-core/workflows/validate-phase.md",
"gsd-core/workflows/verify-work.md",
"gsd-core/workflows/verify-work/steps/automated-ui-verification.md",
"gsd-core/workflows/verify-work/steps/mvp-uat-framing.md",
"hooks/gsd-agent-isolation-guard.js",
"hooks/gsd-check-update-worker.js",
"hooks/gsd-check-update.js",
"hooks/gsd-config-reload.js",
"hooks/gsd-context-monitor.js",
"hooks/gsd-cursor-post-tool.js",
"hooks/gsd-cursor-pre-tool.js",
"hooks/gsd-cursor-session-start.js",
"hooks/gsd-cursor-stop.js",
"hooks/gsd-cursor-subagent-start.js",
"hooks/gsd-cursor-subagent-stop.js",
"hooks/gsd-ensure-canonical-path.js",
"hooks/gsd-graphify-update.sh",
"hooks/gsd-node-runner.sh",
"hooks/gsd-phase-boundary.sh",
"hooks/gsd-prompt-guard.js",
"hooks/gsd-read-guard.js",
"hooks/gsd-read-injection-scanner.js",
"hooks/gsd-secret-read-guard.js",
"hooks/gsd-session-state.sh",
"hooks/gsd-statusline.js",
"hooks/gsd-update-banner.js",
"hooks/gsd-validate-commit.sh",
"hooks/gsd-windsurf-pre-command.js",
"hooks/gsd-windsurf-pre-write.js",
"hooks/gsd-workflow-guard.js",
"hooks/gsd-worktree-path-guard.js",
"hooks/gsd-write-guard.js",
"hooks/lib/cli-exit.js",
"hooks/lib/cursor-workspace.js",
"hooks/lib/exit-code-registry.js",
"hooks/lib/git-cmd.js",
"hooks/lib/git-probe.js",
"hooks/lib/gsd-graphify-rebuild.sh",
"hooks/lib/hook-exit.js",
"hooks/lib/injection-patterns.js",
"hooks/lib/isolation-deny-reason.js",
"hooks/lib/isolation-sentinel.js",
"hooks/managed-hooks-registry.cjs",
"hooks/package.json",
"opencode.json",
"plugins/gsd-core.js",
"plugins/package.json",
"scripts/changeset/README.md",
"scripts/changeset/cli.cjs",
"scripts/changeset/github-release-notes.cjs",
"scripts/changeset/lint.cjs",
"scripts/changeset/new.cjs",
"scripts/changeset/parse.cjs",
"scripts/changeset/render.cjs",
"scripts/changeset/serialize.cjs",
"scripts/fix-slash-commands.cjs",
"scripts/gen-capability-registry.cjs",
"scripts/gen-loop-host-contract.cjs",
"scripts/lib/alias-drift-families.cjs",
"scripts/lib/allowlist-ratchet.cjs",
"scripts/lib/ci-job-timing.cjs",
"scripts/lib/cli-exit.cjs",
"scripts/lib/drift-scan.cjs",
"scripts/lib/exit-code-registry.cjs",
"scripts/lib/ndjson-reporter.cjs",
"scripts/lib/shellcheck-fetch.cjs",
"skills/gsd-add-tests/SKILL.md",
"skills/gsd-ai-integration-phase/SKILL.md",
"skills/gsd-audit-fix/SKILL.md",
"skills/gsd-audit-milestone/SKILL.md",
"skills/gsd-audit-uat/SKILL.md",
"skills/gsd-autonomous/SKILL.md",
"skills/gsd-capture/SKILL.md",
"skills/gsd-cleanup/SKILL.md",
"skills/gsd-code-review/SKILL.md",
"skills/gsd-complete-milestone/SKILL.md",
"skills/gsd-config/SKILL.md",
"skills/gsd-debug/SKILL.md",
"skills/gsd-discuss-phase/SKILL.md",
"skills/gsd-docs-update/SKILL.md",
"skills/gsd-eval-review/SKILL.md",
"skills/gsd-execute-phase/SKILL.md",
"skills/gsd-explore/SKILL.md",
"skills/gsd-extract-learnings/SKILL.md",
"skills/gsd-fast/SKILL.md",
"skills/gsd-forensics/SKILL.md",
"skills/gsd-graphify/SKILL.md",
"skills/gsd-health/SKILL.md",
"skills/gsd-help/SKILL.md",
"skills/gsd-import/SKILL.md",
"skills/gsd-inbox/SKILL.md",
"skills/gsd-ingest-docs/SKILL.md",
"skills/gsd-manager/SKILL.md",
"skills/gsd-map-codebase/SKILL.md",
"skills/gsd-mempalace-capture/SKILL.md",
"skills/gsd-mempalace-recall/SKILL.md",
"skills/gsd-milestone-summary/SKILL.md",
"skills/gsd-mvp-phase/SKILL.md",
"skills/gsd-new-milestone/SKILL.md",
"skills/gsd-new-project/SKILL.md",
"skills/gsd-next/SKILL.md",
"skills/gsd-ns-context/SKILL.md",
"skills/gsd-ns-ideate/SKILL.md",
"skills/gsd-ns-manage/SKILL.md",
"skills/gsd-ns-project/SKILL.md",
"skills/gsd-ns-review/SKILL.md",
"skills/gsd-ns-workflow/SKILL.md",
"skills/gsd-onboard/SKILL.md",
"skills/gsd-pause-work/SKILL.md",
"skills/gsd-phase/SKILL.md",
"skills/gsd-plan-phase/SKILL.md",
"skills/gsd-plan-review-convergence/SKILL.md",
"skills/gsd-pr-branch/SKILL.md",
"skills/gsd-profile-user/SKILL.md",
"skills/gsd-progress/SKILL.md",
"skills/gsd-quick-batch/SKILL.md",
"skills/gsd-quick/SKILL.md",
"skills/gsd-resume-work/SKILL.md",
"skills/gsd-review-backlog/SKILL.md",
"skills/gsd-review/SKILL.md",
"skills/gsd-secure-phase/SKILL.md",
"skills/gsd-settings/SKILL.md",
"skills/gsd-ship/SKILL.md",
"skills/gsd-sketch/SKILL.md",
"skills/gsd-spec-phase/SKILL.md",
"skills/gsd-spike/SKILL.md",
"skills/gsd-stats/SKILL.md",
"skills/gsd-surface/SKILL.md",
"skills/gsd-thread/SKILL.md",
"skills/gsd-ui-phase/SKILL.md",
"skills/gsd-ui-review/SKILL.md",
"skills/gsd-ultraplan-phase/SKILL.md",
"skills/gsd-undo/SKILL.md",
"skills/gsd-update/SKILL.md",
"skills/gsd-validate-phase/SKILL.md",
"skills/gsd-verify-work/SKILL.md",
"skills/gsd-workspace/SKILL.md",
"skills/gsd-workstreams/SKILL.md"
]