* test(116): reproduce base64-scan illegal byte sequence on non-UTF8 fixtures Adds regression fixtures and failing tests for #116. Empirically verified on macOS 26.5 (BSD tr) that `tr -cd '[:print:]'` under LC_CTYPE=en_US.UTF-8 exits non-zero with "Illegal byte sequence" when its input contains bytes that are not valid UTF-8 start sequences (e.g. lone continuation bytes 0x80–0x9F). The base64-scan.sh root cause is a known bash pitfall: the assignment `local printable_count=$(... | tr -cd '[:print:]' | ...)` uses `local` on the same line, which always returns exit 0, masking the tr failure. Result: tr errors surface only on stderr; the scan exits 0 with incomplete coverage (false-clean signal). Two new tests FAIL on origin/main: - "scans non-UTF8 file containing a b64 blob without emitting Illegal byte sequence" - "dir scan with non-UTF8 files under non-C locale completes cleanly within 30s" Fixtures in tests/fixtures/base64-locale/: utf8-with-injection.md — UTF-8 + base64-encoded injection (positive control) non-utf8-with-b64blob.bin — raw 0x80-0x9F bytes + b64 blob that decodes to binary (this is the reproducer that triggers tr error) mixed-encoding.txt — valid UTF-8 + lone continuation bytes clean-text.md — negative control (must not be flagged) Test helpers use spawnSync (not execFileSync) so stderr is captured even on exit 0 — execFileSync only surfaces stderr via the thrown error on non-zero exit. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(116): locale-safe base64-scan with portable timeout and partial-scan signaling Root cause: BSD tr(1) on macOS rejects input bytes that are not valid UTF-8 start sequences with "Illegal byte sequence" when LC_CTYPE is set to any UTF-8 locale (e.g. en_US.UTF-8). Empirically verified on macOS 26.5 using `man tr` (ENVIRONMENT section) and direct testing: printf '\x80\x81hello' | LC_ALL=en_US.UTF-8 tr -cd '[:print:]' → tr: Illegal byte sequence (exit 1) The error is silently masked because base64-scan.sh uses `local` on the same line as the tr assignment. Bash's `local` built-in always returns 0 regardless of the subshell's exit code — so the tr failure never propagates under `set -euo pipefail`. Result: the script exits 0 with truncated printable_count, causing binary-decoded blobs to be skipped (false-clean, security gap). Fix: `export LC_ALL=C` at script level (line 33). - LC_ALL=C forces the POSIX C locale throughout: tr treats every byte 0x00–0xFF as a valid character, never rejects high bytes. - Safe for all script operations: all injection patterns are ASCII, grep POSIX classes ([:space:], [:print:]) behave correctly in C locale, base64 -d is locale-independent. - Script-level export is appropriate because all operations in this script are byte-level; no multi-byte character handling is needed. Additional hardening: - MAX_LINE_BYTES=1048576 guard in extract_and_check_blobs: lines longer than 1 MiB are skipped with an explicit "partial scan" warning to stderr. This bounds grep -oE cost on pathological inputs (minified JS, single-line binary blobs) and satisfies the "partial-scan failure signaling" requirement. - Portable run_with_timeout + is_timeout_exit: probes for GNU timeout, gtimeout (homebrew), and falls back to perl alarm(N)+exec. Defined for future use guarding external sub-commands. Verified: no timeout binary on this macOS host, perl alarm fallback works correctly (exit 142 on SIGALRM). Test-rigor fixes applied per test-rigor skill review: - Fixture validity check: assert `isInvalidUtf8` (round-trip length difference) rather than checking for a specific byte range — the property that matters is "file is not valid UTF-8", not "file has bytes in 0x80–0x9F". - FAIL assertions: assert `FAIL: ${INJECTION_FIXTURE}` (specific filepath) not `result.stdout.includes('FAIL')` — rules out false-positives on other fixtures. - Test name: renamed "mixed-encoding file does not cause scan to abort or hang" to accurately describe what is tested (no extractable blobs → exits clean). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(116): fix shellcheck warnings in base64-scan.sh Address SC2034 (unused variables) and SC2329 (functions never invoked) warnings flagged by shellcheck after the locale-hardening changes. SC2034 fixes (pre-existing): - Remove unused SCRIPT_DIR variable (set but never referenced) - Remove unused printable_ratio local (declared but no assignment or use) SC2329 fixes (new functions from this PR): - Add shellcheck disable=SC2329 annotations on run_with_timeout, _init_timeout_cmd, and is_timeout_exit — these are intentionally defined as infrastructure helpers, not called from the main loop. The line-length guard (MAX_LINE_BYTES) is the primary runtime protection; the timeout helpers are available for future use. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(#116): exclude scanner fixtures from base64-scan diff mode Add tests/fixtures/* to should_skip_file() so deliberate prompt-injection samples in scanner fixture directories are never flagged in CI diff-mode. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
⚠️ This is the active fork
📢 Read the announcement: why the fork, what changed, what's next →
The original repo at gsd-build/get-shit-done appears compromised or abandoned. The maintainer (TÂCHES) has not been reachable since 2026-04-01. TÂCHES social accounts appear deleted, and a
$GSDtoken associated with the project has been linked publicly to a rug-pull.I have no inside information beyond what is publicly visible. I am stating absence-of-information deliberately — absence of news is not the same as evidence.
What I can confirm
- No contact with the original maintainer since 2026-04-01.
- TÂCHES social accounts appear deleted or unreachable.
- The
$GSDtoken has been linked publicly to a rug-pull.- The repo at
gsd-build/get-shit-donecontinues to exist but I cannot vouch for any changes pushed there from this point forward.What changed
Before After GitHub gsd-build/get-shit-doneopen-gsd/get-shit-done-reduxnpm (main) get-shit-done-cc→get-shit-done-redux@opengsd/get-shit-done-reduxnpm (sdk) @gsd-build/sdk→@gsd-redux/sdk@opengsd/gsd-sdkIssue numbers per source renumbered; original is in body as [from gsd-build/get-shit-done#N]If you can reach the original maintainer, please open an issue here and CC them. If you have technical evidence that materially changes the picture above, please share it in an issue.
— trek-e, fork maintainer
GET SHIT DONE
English · Português · 简体中文 · 日本語 · 한국어
A light-weight meta-prompting, context engineering, and spec-driven development system for Claude Code, OpenCode, Gemini CLI, Kilo, Codex, Copilot, Cursor, Windsurf, and more.
Solves context rot — the quality degradation that happens as your AI fills its context window.
npx @opengsd/get-shit-done-redux@latest
Works on Mac, Windows, and Linux.
"If you know clearly what you want, this WILL build it for you. No bs."
"I've done SpecKit, OpenSpec and Taskmaster — this has produced the best results for me."
"By far the most powerful addition to my Claude Code. Nothing over-engineered. Literally just gets shit done."
Trusted by engineers at Amazon, Google, Shopify, and Webflow.
Important
Returning to GSD?
Run
/gsd-map-codebaseto re-index your codebase, then/gsd-new-projectto rebuild GSD's planning context. Your code is fine — GSD just needs its context rebuilt. See the CHANGELOG for what's new.
Why I Built This
I'm a solo developer. I don't write code — Claude Code does.
Other spec-driven tools exist, but they're all built for 50-person engineering orgs — sprint ceremonies, story points, stakeholder syncs, Jira workflows. I'm not that. I'm a creative person trying to build great things consistently.
So I built GSD. The complexity is in the system, not in your workflow. Behind the scenes: context engineering, XML prompt formatting, subagent orchestration, state management. What you see: a few commands that just work.
The system gives Claude everything it needs to do the work and verify it. I trust the workflow. It just does a good job.
— TÂCHES
How It Works
The loop is six commands. Each one does exactly one thing.
1. Initialize
/gsd-new-project
Questions → research → requirements → roadmap. You approve it, then you're ready to build.
Already have code? Run
/gsd-map-codebasefirst. It analyzes your stack, architecture, and conventions so/gsd-new-projectasks the right questions.
2. Discuss
/gsd-discuss-phase 1
Your roadmap has a sentence per phase. That's not enough to build it the way you imagine it. Discuss captures your decisions before anything gets planned: layouts, API shapes, error handling, data structures — whatever gray areas exist for this specific phase.
The output feeds directly into research and planning. Skip it, get reasonable defaults. Use it, get your vision.
3. Plan
/gsd-plan-phase 1
Research → plan → verify, in a loop until the plans pass. Each plan is small enough to execute in a fresh context window.
4. Execute
/gsd-execute-phase 1
Plans run in parallel waves. Each executor gets a fresh 200k-token context. Each task gets its own atomic commit. Walk away, come back to completed work with a clean git history.
Your main context window stays at 30–40%. The work happens in the subagents.
5. Verify
/gsd-verify-work 1
Walk through what was built. Anything broken gets a diagnosed fix plan — ready for immediate re-execution. You don't debug manually; you just run execute again.
6. Repeat → Ship
/gsd-ship 1
/gsd-complete-milestone
/gsd-new-milestone
Loop discuss → plan → execute → verify → ship until the milestone is done. Then archive, tag, and start the next one fresh.
Getting Started
npx @opengsd/get-shit-done-redux@latest
The installer prompts for your runtime (Claude Code, OpenCode, Gemini CLI, Kilo, Codex, Copilot, Cursor, Windsurf, and more) and whether to install globally or locally.
claude --dangerously-skip-permissions
GSD is built for frictionless automation. Skip-permissions is how it's intended to run.
Install only the skills you need with --profile=core (six core-loop skills), --profile=standard (core + phase management), or the default full install. Profiles compose: --profile=core,audit. --minimal is an alias for --profile=core. See docs/USER-GUIDE.md for the full walkthrough, non-interactive install flags for all 15 runtimes, and permissions configuration. See ADR-0011 for the profile model and runtime surface control.
Current release highlights are in docs/RELEASE-v1.42.1.md: package legitimacy checks, safer installer migrations, runtime surface control, custom ship PR sections, reviewer defaults, fallow structural review, and quota-aware execution recovery.
Commands
The main loop:
| Command | What it does |
|---|---|
/gsd-new-project |
Questions → research → requirements → roadmap |
/gsd-discuss-phase [N] |
Capture implementation decisions before planning |
/gsd-plan-phase [N] |
Research + plan + verify |
/gsd-execute-phase <N> |
Execute plans in parallel waves |
/gsd-verify-work [N] |
Manual acceptance testing |
/gsd-ship [N] |
Create PR from verified phase work |
/gsd-progress --next |
Auto-detect and run the next step |
/gsd-complete-milestone |
Archive milestone and tag release |
/gsd-new-milestone |
Start next version |
/gsd:surface |
Enable/disable skill clusters at runtime without reinstall |
For ad-hoc tasks, autonomous mode, codebase analysis, forensics, and the full command surface — see docs/COMMANDS.md.
Why It Works
Three things most AI-coding setups get wrong:
1. Context bloat. As a session grows, quality degrades. GSD keeps your main context clean by doing the heavy work in fresh subagent contexts. Researchers, planners, and executors each start fresh with exactly what they need.
2. No shared memory. GSD maintains structured artifacts that survive session boundaries: PROJECT.md (vision), REQUIREMENTS.md (scope), ROADMAP.md (where you're going), STATE.md (current position and decisions), CONTEXT.md (per-phase implementation decisions). Every new session loads these and knows exactly where things stand.
3. No verification. Code that "runs" isn't code that "works." GSD's verify step walks you through what was built, diagnoses failures with dedicated debug agents, and generates fix plans before you declare a phase done.
See docs/ARCHITECTURE.md for how the multi-agent orchestration and context engineering work in detail.
Configuration
Settings live in .planning/config.json. Configure during /gsd-new-project or update with /gsd-settings.
Key dials:
| Setting | What it controls |
|---|---|
mode |
interactive (confirm each step) or yolo (auto-approve) |
| Model profiles | quality / balanced / budget — controls which model each agent uses |
workflow.research / plan_check / verifier |
Toggle the quality agents that add tokens and time |
parallelization.enabled |
Run independent plans simultaneously |
Optional structural review: set code_quality.fallow.enabled to true to add a fallow pre-pass to /gsd-code-review. GSD writes .planning/phases/<phase>/FALLOW.json and surfaces a Structural Findings (fallow) section in REVIEW.md. Install with npm install -D fallow@^2.70.0 (or system-wide via cargo install fallow; note that the Rust binary's JSON schema must match the documented v2.70+ contract — older versions may produce silent zero-finding output).
Package legitimacy checks are built into the research, planning, and execution path: recommended dependencies get audited, unverified packages require a human checkpoint, and failed installs stop instead of trying similarly named alternatives.
For the full configuration reference — all settings, git branching strategies, per-runtime model overrides, workstream config inheritance, agent skills injection — see docs/CONFIGURATION.md.
Documentation
| Doc | What's in it |
|---|---|
| User Guide | End-to-end walkthrough, install options, all runtime flags, configuration reference |
| Commands | Every command with flags and examples |
| Configuration | Full config schema, model profiles, git branching |
| Architecture | How the multi-agent orchestration works |
| CLI Tools | gsd-sdk query and programmatic SDK dispatch seams |
| Features | Complete feature index |
| Changelog | What changed in each release |
Troubleshooting
Commands not showing up? Restart your runtime after install. GSD installs to ~/.claude/skills/gsd-*/ (Claude Code), ~/.codex/skills/gsd-*/ (Codex), or the equivalent for your runtime.
Codex users — minimum supported CLI version is 0.130.0. Codex CLI 0.130.0 (release notes) removed extra-skill-roots discovery via openai/codex#21485; from that version onward Codex discovers skills from standard roots (including ~/.codex/skills/<name>/SKILL.md). GSD installs there directly. Earlier Codex CLI versions may still discover additional roots, which can surface duplicate gsd-* entries (one from extra-roots discovery, one from ~/.codex/skills/); restart Codex after install and either upgrade or accept the duplicate listing.
Something broken? Re-run the installer — it's idempotent:
npx @opengsd/get-shit-done-redux@latest
Containers or Docker? Set CLAUDE_CONFIG_DIR before installing to avoid tilde-expansion issues:
CLAUDE_CONFIG_DIR=/home/youruser/.claude npx @opengsd/get-shit-done-redux --global
Full troubleshooting and uninstall instructions in docs/USER-GUIDE.md.
Community
| Project | Platform |
|---|---|
| gsd-opencode | Original OpenCode port |
| Discord | Community support |
Star History
License
MIT License. See LICENSE for details.
Claude Code is powerful. GSD makes it reliable.