Files
msd-core/docs
sim 9953d02184 docs(#4653): describe the consolidated path-containment seam in the security model
The security model's input-validation section still described path traversal as
a per-call check with a macOS symlink footnote. It now describes what actually
exists: one predicate, a module-internal engine, three exported shapes none of
which can hand back a usable path when the answer is unsafe, the branded return
type, and the named acceptance policy — including the point the old wording
invited a reader to get wrong, that allowing an absolute candidate does not
relax containment.

Also records the two checks deliberately NOT routed through the predicate and
why each is narrower or stricter rather than a second opinion, so a later
cleanup pass does not read them as stragglers.

Required by the Changed changeset: scripts/lint-docs-required.cjs makes
Added/Changed/Deprecated/Removed fragments demand a file under docs/, and
CONTEXT.md is at the repo root, so the glossary entry alone would not have
satisfied it. The lint currently reports invalid_pr against the mandated pr:0
placeholder and becomes meaningful after backfill.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-12 13:41:40 -04:00
..

GSD Core documentation

Documentation is organised into four quadrants: tutorials help you learn by doing, how-to guides solve specific tasks, reference states authoritative facts, and explanation explores concepts and design decisions.

Language versions: English · Português (pt-BR) · 日本語 · 简体中文


Tutorials


How-to guides


Reference

  • Commands — every command with flags and examples
  • Configuration — full config schema, model profiles, git branching strategies
  • CLI tools — gsd-tools.cjs programmatic API for workflows and agents
  • JSON error mode — gsd-tools failure channels: faults (stderr, exit 1) vs degraded results (stdout, exit 0), and the reason-code taxonomy
  • Features — complete feature index
  • Inventory — installed skills and surface map
  • STATE.md schema — field-by-field reference for .planning/STATE.md
  • CONTEXT.md schema — field-by-field reference for .planning/phases/<N>/CONTEXT.md
  • PLAN.md schema — field-by-field reference for .planning/phases/<N>/PLAN.md
  • Planning artifacts — all .planning/ files and their roles
  • Review and verification capabilities — code review, security, and Nyquist capability ownership and hook contracts
  • Gate predicates — canonical specification of the phase-gate predicate vocabulary
  • Capability matrix — generated catalogue of every capability's role, tier, extension points, hook kinds, and engines.gsd
  • Exit code reference — generated catalogue of every registered process exit code, its name, meaning, and owning module, plus the reserved bands and the v1/v2 exit contract
  • Capability manifest — the full capability.json schema and validation rules
  • gsd capability command — install / update / remove / list reference for third-party capabilities
  • Workflow fragments — in-file <!-- gsd:section --> marker grammar for fragmentizing workflow markdown at emission time
  • Partition rules for compact-content splits — the protected-content list, sentinel syntax, and the five CI checks a workflow.compact_content spine/detail split must obey
  • Reviewer Lane Registry — generated catalogue of third-party reviewer lanes, with their flags, transport, and install commands

Explanation