Files
msd-core/docs/INVENTORY-MANIFEST.json
Behruz Nassre Esfahani a44d513566 fix(#3712): confine in-process installs to a sandboxed HOME (#3725)
* fix(#3712): confine in-process installs to a sandboxed HOME

A runtime kind may declare a global `home` override resolved from os.homedir()
rather than from the caller's configDir — codex's skills kind (`home: ".agents"`,
ADR-1239 / #2088) is the only live case. Sandboxing configDir/targetDir does not
contain it, and assertDestWithinConfigHome cannot see the class: that gate
confines a destSubpath to whatever root it is handed, and here the root IS the
escaped home. So an in-process caller that forgot to sandbox HOME wrote to, and
pruned gsd-* entries from, the developer's REAL ~/.agents/skills.

tests/agent-descriptor-parity.install.test.cjs's K1 loop did exactly that: it
iterates every agents-kind runtime (codex included) with a sandboxed targetDir
and an un-sandboxed HOME. Reproduced against a canary home on next @ adb46cdd8 —
71 gsd-* skill dirs deleted, a foreign `cloudflare` skill surviving, suite still
exit 0. It is silent because the runtime's own config home is untouched, so the
manifest keeps reporting a healthy install.

FIVE writers resolve a kind `home` and then destroy under it. Three are reachable
today — installRuntimeArtifacts, uninstallRuntimeArtifacts (install-engine.cts)
and applySurface (surface.cts). Two are descriptor-dependent and guarded against a
future descriptor change rather than a present escape: installOpencodeFamilySkills
(behind the combined-family early return) and installAgentsKindStandalone. Those
two are scoped to the single kind each destroys — passing the whole layout made
codex's unrelated skills override trip a writer that never touches it.

- src/test-home-guard.cts: refuse when a run under a test runner cannot be shown
  to have sandboxed HOME. NODE_TEST_CONTEXT (set by `node --test`) gates it, so
  installs outside a Node test context are untouched; GSD_TEST_MODE is unusable,
  as several candidate files including the offender never set it. Homes are
  compared by FILESYSTEM IDENTITY (st_dev + st_ino), not by pathname:
  path.resolve() resolves neither symlinks nor case, and realpath returns a
  canonical pathname that two routes to one directory can still disagree on (bind
  mounts). Verified on macOS/APFS — HOME=/users/<name> made the strings differ
  while naming the same directory, and the lexical form ALLOWED a write into the
  physical real home. FAILS CLOSED: a pair is "different" only when both identify,
  or one is definitively absent (ENOENT/ENOTDIR) while the other identifies; every
  other errno is "cannot tell" and refuses. Only when neither home identifies is a
  marker consulted, and it carries the sandbox PATH and must equal the home in
  effect — a boolean checked first let an ambient or stale value disarm the guard.
- helpers: promote sandboxHome() out of its two byte-identical private copies,
  which is also what makes them record the sandbox; the three withFakeHome()
  helpers record it too. The marker NAME is duplicated as a bare string rather
  than required from the compiled guard, keeping helpers.cjs's documented
  no-built-lib-at-import-time contract; a test pins the two together.
- agent-descriptor-parity: sandbox HOME across the K1 loop.
- helpers-process-isolation: #3156's canary asserts on <home>/.gsd only, and its
  `--cursor --local` spawn cannot reach `.agents` at all, so an assertion added
  there would pass with all confinement removed. Add a discriminating row — a
  `--codex --global` spawn against a seeded ambient home — which also asserts the
  runtime still declares the override. Its check is a sampled inventory (dir names
  + each SKILL.md), not a tree compare.
- install-write-confinement: predicate rows through the deps seam, covering the
  symlinked HOME, ambient and stale markers, and each sameDirectory branch
  (both-identify, one-absent, neither-identifiable), plus wiring rows that drive
  the REAL entrypoints so deleting a guard call site is red.

Verified: guard fires end-to-end against a real un-sandboxed HOME (exit 1, zero
deletions); the case-variant fail-open reproduced on APFS before the fix and
refuses after; K1 file 29/29 green with skills intact; mutation-tested — each of
the three reachable call sites, lexical-only comparison, and treating an unknown
errno as "absent" each take exactly one row red, with every mutation echoed back;
the process-isolation row negative-controlled by reverting installerEnv to its
pre-#3156 leak (16/0 -> 13/3); a full npm test leaves ~/.agents/skills at 71.

Stated residual: the two descriptor-dependent writers have no wiring test, because
no runtime declares a `home` override on those kinds and neither can be exercised
without inventing a descriptor.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(#3712): add changeset

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#3712): let a sandbox nested inside the real home through the guard

All six Windows shards of #3725 failed on legitimately sandboxed
destinations. On Windows os.tmpdir() is %LOCALAPPDATA%\Temp — inside the
user's home — so every sandbox a test creates is a descendant of the real
home, and "does this land inside the real home?" answers yes for the safe
case and the dangerous one alike. POSIX conceals this: /tmp and
/var/folders both sit outside $HOME.

Add the missing conjunct: a destination inside the real home is allowed
only when it also sits beneath a HOME that was sandboxed away from the
passwd home. Both halves are required — dropping the first re-admits a
plain un-sandboxed install, and dropping the second decays into the
"is HOME sandboxed?" check the module rejects, which a layout resolved
before the sandbox walks straight through. Each is mutation-proven by a
row that goes red without it.

Also covers the two fail-closed branches of the new exemption, which
survived mutation to `true` with the suite green, and avoids `<user>` in
a docblock — the prompt-injection scanner reads it as a delimiter tag.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(#3712): close three writer/rollback gaps found reviewing the whole PR

Cross-AI review of the full PR (not just the round's delta) surfaced
three ways the guard could still be defeated:

- The nested-sandbox exemption trusted the SPELLING of a destination.
  With HOME sandboxed to a directory inside the real home — legitimate on
  Windows — an aliased `.agents` (symlink, junction, subordinate bind
  mount) beneath it redirected an allowed path into the real home. Decide
  containment on the path the write RESOLVES to: walk up to the nearest
  existing ancestor, canonicalize, re-append the tail.

- `migrateLegacyDevPreferencesToSkill` is a SIXTH writer that resolves a
  skills-kind `home` override. It creates rather than prunes, which is
  why it was missed, and `_runLegacyInstallMigrations` runs it before
  `installRuntimeArtifacts`' own assertion. Guarded, scoped to that kind.

- Worst of the three: `bin/install.js` snapshots the resolved skills root
  before installing, and its outer catch rolls back by deleting and
  recreating every snapshotted `gsd-*` directory there. The guard's own
  throw landed in that catch, so refusing an un-sandboxed codex install
  provoked exactly the mutation the guard exists to prevent. Refusals are
  now marked and rethrown without rollback — nothing was written, so
  there is no partial install to undo. Every other error still rolls back.

Also carries the sandbox marker into `installSpawnEnv`, so spawned
installers are not refused on passwd-less CI images, and corrects three
claims that no longer hold: "every writer" (six, and named), the
unconditional "fails CLOSED" (the passwd-less marker branch is a
deliberate weakening, and TOCTOU is out of scope), and the assertion that
Windows os.tmpdir() is always %LOCALAPPDATA%\Temp (Node honors TEMP/TMP).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs(#3712): name the guard's two limits instead of overclaiming

Round-2 review found the prose had drifted ahead of the code. Corrected,
with no behavior change:

- The module still said FIVE writers; there are six, and the sixth is
  now named along with why it was missed (it creates rather than prunes)
  and why it carries its own assertion (it runs before the main one).
- The canonicalization docblock listed subordinate bind mounts among the
  aliases it closes. It does not close them: a bind mount is not a link,
  so realpath keeps the mount-point spelling. `sameDirectory` already
  recorded that limit; the new helper now inherits it explicitly rather
  than contradicting it. Closing it needs mount-table introspection.
- "FAILS CLOSED" was unqualified while the passwd-less marker branch is
  a deliberate weakening — with no passwd entry, nothing can contradict a
  marker naming the real home.
- "Refuses BEFORE any write" was too broad: legacy install migrations run
  ahead of the layout-driven ones, which is exactly why the two
  rollbackInstallerMigrations() calls still execute before the rethrow.
  Only the codex skills-root rollback is skipped, and that is the only
  _codexPreConfigRollback() call site — applySurface is never called from
  bin/install.js and uninstall cannot reach it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(#3712): sandbox HOME in the opencode-family home-override parity rows

The last two Windows failures, and the same platform asymmetry in a
different disguise. This row drives a skills-kind `home` override on
purpose — precisely what the guard polices — but relied on the override
temp dir happening to sit outside the real home. It does on POSIX
(/tmp, /var/folders); on Windows os.tmpdir() is under %USERPROFILE%, so
the guard correctly refused and only Windows went red.

Declare the sandbox instead of depending on the platform: HOME becomes
the override itself, which is the home the call writes under. This is the
fix the guard's own message prescribes, applied to the test rather than
to the guard.

Both failing Windows shards fail on exactly these two rows and nothing
else; every other shard is green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(#3712): make sameDirectory answer NO when it cannot tell

Review Major 1. sameDirectory()'s only caller is the passwd-less marker
branch, which reads a `true` as permission to PROCEED:

    if (marker && sameDirectory(marker, osMod.homedir())) return;

The fallthrough returned `true` whenever neither side identified — two
absent paths, or two stats failing EACCES/EPERM/EIO on a locked-down
host — on the reasoning that "cannot tell" should make the caller refuse.
That reasoning was inverted with respect to this caller: it turned the
passwd-less escape hatch into an unconditional bypass for any marker
value at all, on precisely the hosts the fallback exists to serve. Only
two things now answer yes: one resolved pathname, or two readable
identities that match. Restoring the old fallthrough takes the new row
red.

Also from review:

- Major 2 asked whether st_dev/st_ino discriminate directories on
  Windows, where Node derives them from BY_HANDLE_FILE_INFORMATION. The
  whole guard rests on that primitive, so assert it rather than argue it:
  a row comparing two distinct temp directories, and one directory
  reached by two spellings. It runs on every platform in the matrix, so
  Windows answers the question itself.

- Minor 1: the refusal now names the real home it compared against, not
  just the destination it refused. That is the one fact needed to tell a
  true positive from a false one, and its absence is what made the
  Windows case a CI-log dig rather than a glance.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(#3712): refuse a HOME that merely spells the real home more widely

Review round: one Blocker, four Minors, a Nit.

N2 (the one with teeth) — a destination's ancestor chain is linear, so
"inside the real home AND inside the effective HOME" admits two
arrangements, not one. The intended `effectiveHome ⊂ realHome` is the
Windows temp shape; `realHome ⊂ effectiveHome` — HOME at /Users, /home,
C:\Users — is not a sandbox at all, it is the real home reached by a
wider spelling, and it was exempting a stale destination pointing
straight at ~/.agents. Third conjunct added; the docblock no longer
claims two conditions suffice. Removing the conjunct reds the new row
and nothing else.

N4 — the migration guard resolved its OWN layout, and without
capabilityRegistry, so a registry-dependent descriptor could make it
vouch for a path the migration does not write: a guard reporting safe
while the unsafe write proceeds. It now guards the destination already
resolved by _resolveDevPreferencesSkillTarget, keyed on
`installRoot !== targetDir` — which is exactly the condition under which
a `home` override was declared, read off that same result.

N1 — CONTEXT.md gains the Test Home Guard Module glossary entry that
contributor-standards.md requires of a new Module. Not CI-enforced, so
green CI was never evidence it was met.

N3 — the docs/INVENTORY.md row was misfiled between install-fs-adapter
and install-model-override-resolver; the table is alphabetical and the
manifest already had it right. Moved, and its text now names six writers
and the third conjunct.

N5 — applySurface's signature docblock was two parameters stale; this PR
added the second of them.

N6 — the duplicated rollbackInstallerMigrations() adjacent to the new
rethrow: two identical consecutive calls, not two phases.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(#3712): guard the sixth writer, and close two false-ALLOW paths

Review round 3 (NEW-1, NEW-2) plus three defects Codex found in the
whole-PR pass, each reproduced before it was fixed.

NEW-1 — migrateLegacyDevPreferencesToSkill called the guard with no
`deps`, so it bound real os/process.env and could not be wiring-tested
the way the other three reachable writers were. It now takes the same
optional `deps: { os?, env? }` tail parameter. The wiring block gains
the missing fourth row, and a fifth pinning the ALLOW half; the test
file's header docblock said "FIVE writers ... the three reachable
today", contradicting the six/four statement this PR already put in
src/test-home-guard.cts, CONTEXT.md, docs/INVENTORY.md and the
changeset. Both directions of the guard's condition now fail a row
when broken — previously neither did.

NEW-2 — derivesFromSandboxedHome's docblock claimed "THREE conditions
are required, and no two of them suffice". False for {2,3}: isInside is
reflexive, so whenever conjunct 1 fires conjunct 2 already returns
false on its own. Reworded as a fast path, which is what it is.

Codex 1 (false ALLOW) — on a host with no readable passwd entry the
marker branch returned as soon as the marker matched the effective
HOME. That attests a caller sandboxed HOME and says nothing about where
an already-resolved destination points, so a layout captured before
sandboxHome() — still naming the real ~/.agents — was waved straight
through: the same stale-layout shape the primary branch refuses by
design. The marker must now identify AND contain every destination.

Codex 2 (false ALLOW) — `installRoot !== targetDir` was the stand-in
for "the skills kind declared a home override". The two are not
equivalent: the inequality is false when the override resolves onto
targetDir itself, which is exactly a configDir of $HOME/.agents. The
guard was skipped and SKILL.md written into the real home under a test
runner. _resolveDevPreferencesSkillTarget now reports hasHomeOverride
off the same resolution instead of inferring it from two paths.

Codex 3 (prose) — the shared refusal message claimed every guarded
writer prunes; the migrate writer only creates. The changeset headline
claimed in-process installer calls can no longer reach the real home,
which is wider than the guard: writeNonClaudeDefaults still writes
~/.gsd/defaults.json through os.homedir(). INVENTORY's and CONTEXT's
fail-closed sentences omitted sameDirectory's pathname-equality
shortcut. All four narrowed to what the code does.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(#3712): let the sandbox marker follow an overridden HOME

Found by Codex in the whole-PR pass. installSpawnEnv spreads
`overrides` last so an explicit HOME wins — deliberate, and its
docblock tells callers needing per-spawn isolation to pass their own
{ HOME, USERPROFILE }. But the #3712 marker was set before that spread,
so such a caller got HOME=<theirs> and marker=<helper default>. On a
host with no readable passwd entry the guard compares the two and
refuses a legitimately sandboxed spawn — tests/install.test.cjs:7143
and install-shared.cjs's own runInstaller both take that path.

The marker is now derived from the final HOME unless the caller
supplied one explicitly. The contract test asserted HOME after an
override but not the marker, which is why it stayed green.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* docs(#3712): name the shipped guard condition, not the deleted one

Review round 4 of #3725. Two artifacts this PR adds still described
`target.installRoot !== targetDir` in the PRESENT tense as the live guard
condition on `migrateLegacyDevPreferencesToSkill`. The shipped condition is
`runtime && target.hasHomeOverride` (src/install-engine.cts:510).

This is not ordinary doc drift. The named condition is the exact false-ALLOW
the previous round closed: a `home` override resolving onto `targetDir` — a
configDir of `$HOME/.agents`, which is where codex's override points — makes
the inequality FALSE while the override is declared, so the guard was skipped.
A maintainer reading CONTEXT.md:290 as authoritative would believe the guard
still skips that case.

  - tests/install-write-confinement.test.cjs — the ALLOW-half row's comment.
    Its "teeth" rationale is unchanged and still correct as written.
  - CONTEXT.md:290 — the Test Home Guard Module glossary entry, a documented
    PR gate. Now states the condition and names the inequality only as what it
    is NOT, with the reason.

The three surviving mentions of the inequality are all past-tense or negated
(src/install-engine.cts:448, :508 and the sibling test comment at :3698) and
are correct as they stand.

Verified: `npm run lint:ci` exit 0; full `npm test` 31327 tests / 31312 pass /
0 fail / 14 skipped, run with TMPDIR unset.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(#3712): canonicalization fails closed, matching identify's errno split

Codex full-PR review of #3725, run against the round-4 head.

`resolveThroughLinks` caught EVERY realpathSync error and fell back to
`path.resolve(dest)` — the lexical spelling. That inverts the function's own
purpose. An aliased `<sandbox>/.agents` that cannot be canonicalized keeps its
sandbox spelling, satisfies the nested-sandbox exemption at :227, and the write
is ALLOWED into the real home — the exact escape this walk exists to close. The
module documents that it fails CLOSED with ONE named exception (the marker
branch); this was a second, unnamed one.

Split by errno, and deliberately by the SAME split `identify` already draws
rather than a second policy in one module — both answer "does this path exist
as named?", so they must not disagree:

  ENOENT / ENOTDIR -> walk up. The ordinary case: a fresh install resolves a
    destination nothing has created yet, so realpath fails on the leaf and on
    every not-yet-created ancestor. Refusing here rejects every install.
  anything else (EACCES, EPERM, ELOOP, EIO) -> refuse. The component exists but
    cannot be resolved, so the guard cannot tell where the write lands.

Three rows in the predicate block, beside the other aliasing rows:
  - a symlink CYCLE in the destination path (ELOOP)   -> REFUSE
  - a destination that does not exist yet (ENOENT)    -> ALLOW
  - a component behind a regular file (ENOTDIR)       -> ALLOW

Teeth checked against the artifact the test loads, not the source: reverting
the condition to the swallow-everything shape in the compiled
test-home-guard.cjs turns row 1 — and only row 1 — red. The ENOTDIR row caught
a stale build during development, which is the point of asserting on the
compiled file.

CONTEXT.md and the resolveThroughLinks docblock both record the new behaviour,
so this does not repeat the prose-vs-code drift the round-4 finding was about.

The changeset's existing scope sentence now bounds "six writers" to the
`installRuntimeArtifacts` call tree and names `cmdGenerateDevPreferences` —
which resolves the same codex `home` override through `getGlobalSkillsBase` and
writes SKILL.md beneath it unguarded. It has no in-process caller today (its
only direct require-and-call is a spawnSync with HOME sandboxed), so it is
latent rather than live, and whether it belongs in this PR is raised with the
maintainer rather than decided here.

Verified: `npm run lint:ci` exit 0; full `npm test` 31330 tests / 31315 pass /
0 fail / 14 skipped, TMPDIR unset.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-23 18:27:02 -04:00

635 lines
19 KiB
JSON

{
"families": {
"agents": [
"gsd-advisor-researcher",
"gsd-ai-researcher",
"gsd-assumptions-analyzer",
"gsd-code-fixer",
"gsd-code-reviewer",
"gsd-codebase-mapper",
"gsd-debug-session-manager",
"gsd-debugger",
"gsd-doc-classifier",
"gsd-doc-synthesizer",
"gsd-doc-verifier",
"gsd-doc-writer",
"gsd-dom-verifier",
"gsd-domain-researcher",
"gsd-eval-auditor",
"gsd-eval-planner",
"gsd-executor",
"gsd-framework-selector",
"gsd-integration-checker",
"gsd-intel-updater",
"gsd-mempalace-curator",
"gsd-nyquist-auditor",
"gsd-pattern-mapper",
"gsd-phase-researcher",
"gsd-plan-checker",
"gsd-planner",
"gsd-project-researcher",
"gsd-research-synthesizer",
"gsd-roadmapper",
"gsd-security-auditor",
"gsd-ui-auditor",
"gsd-ui-checker",
"gsd-ui-researcher",
"gsd-user-profiler",
"gsd-verifier"
],
"commands": [
"/gsd-add-tests",
"/gsd-ai-integration-phase",
"/gsd-audit-fix",
"/gsd-audit-milestone",
"/gsd-audit-uat",
"/gsd-autonomous",
"/gsd-capture",
"/gsd-cleanup",
"/gsd-code-review",
"/gsd-complete-milestone",
"/gsd-config",
"/gsd-debug",
"/gsd-discuss-phase",
"/gsd-docs-update",
"/gsd-eval-review",
"/gsd-execute-phase",
"/gsd-explore",
"/gsd-extract-learnings",
"/gsd-fast",
"/gsd-forensics",
"/gsd-graphify",
"/gsd-health",
"/gsd-help",
"/gsd-import",
"/gsd-inbox",
"/gsd-ingest-docs",
"/gsd-manager",
"/gsd-map-codebase",
"/gsd-mempalace-capture",
"/gsd-mempalace-recall",
"/gsd-milestone-summary",
"/gsd-mvp-phase",
"/gsd-new-milestone",
"/gsd-new-project",
"/gsd-next",
"/gsd-ns-context",
"/gsd-ns-ideate",
"/gsd-ns-manage",
"/gsd-ns-project",
"/gsd-ns-review",
"/gsd-ns-workflow",
"/gsd-onboard",
"/gsd-pause-work",
"/gsd-phase",
"/gsd-plan-phase",
"/gsd-plan-review-convergence",
"/gsd-pr-branch",
"/gsd-profile-user",
"/gsd-progress",
"/gsd-quick",
"/gsd-resume-work",
"/gsd-review",
"/gsd-review-backlog",
"/gsd-secure-phase",
"/gsd-settings",
"/gsd-ship",
"/gsd-sketch",
"/gsd-spec-phase",
"/gsd-spike",
"/gsd-stats",
"/gsd-surface",
"/gsd-thread",
"/gsd-ui-phase",
"/gsd-ui-review",
"/gsd-ultraplan-phase",
"/gsd-undo",
"/gsd-update",
"/gsd-validate-phase",
"/gsd-verify-work",
"/gsd-workspace",
"/gsd-workstreams"
],
"workflows": [
"add-backlog.md",
"add-phase.md",
"add-tests.md",
"add-todo.md",
"ai-integration-phase.md",
"analyze-dependencies.md",
"audit-fix.md",
"audit-milestone.md",
"audit-uat.md",
"autonomous.md",
"check-todos.md",
"cleanup.md",
"code-review-fix.md",
"code-review.md",
"complete-milestone.md",
"debug.md",
"diagnose-issues.md",
"discuss-phase-assumptions.md",
"discuss-phase-power.md",
"discuss-phase.md",
"do.md",
"docs-update.md",
"edit-phase.md",
"eval-review.md",
"execute-phase.md",
"execute-plan.md",
"explore.md",
"extract-learnings.md",
"fast.md",
"forensics.md",
"graduation.md",
"health.md",
"help.md",
"import.md",
"inbox.md",
"ingest-docs.md",
"insert-phase.md",
"list-phase-assumptions.md",
"list-seeds.md",
"list-workspaces.md",
"manager.md",
"map-codebase.md",
"milestone-summary.md",
"mvp-phase.md",
"new-milestone.md",
"new-project.md",
"new-workspace.md",
"next.md",
"node-repair.md",
"note.md",
"onboard.md",
"pause-work.md",
"plan-phase.md",
"plan-review-convergence.md",
"plant-seed.md",
"pr-branch.md",
"profile-user.md",
"progress.md",
"quick.md",
"reapply-patches.md",
"remove-phase.md",
"remove-workspace.md",
"resume-project.md",
"review.md",
"scan.md",
"secure-phase.md",
"session-report.md",
"settings-advanced.md",
"settings-integrations.md",
"settings.md",
"ship.md",
"sketch-wrap-up.md",
"sketch.md",
"smart-entry.md",
"spec-phase.md",
"spike-wrap-up.md",
"spike.md",
"stats.md",
"sync-skills.md",
"thread.md",
"transition.md",
"ui-phase.md",
"ui-review.md",
"ultraplan-phase.md",
"undo.md",
"update.md",
"validate-phase.md",
"verify-work.md"
],
"references": [
"agent-contracts.md",
"agent-skills-bootstrap.md",
"ai-evals.md",
"ai-frameworks.md",
"api-coverage.md",
"artifact-types.md",
"autonomous-smart-discuss.md",
"autonomous-ui-design-contract.md",
"checkpoints.md",
"common-bug-patterns.md",
"context-budget.md",
"continuation-format.md",
"debugger-bug-taxonomy.md",
"debugger-fix-acceptance.md",
"debugger-philosophy.md",
"debugger-prevention.md",
"debugger-rca-branching.md",
"debugger-repro-hardening.md",
"debugger-sbfl.md",
"debugger-semantic-recall.md",
"debugger-techniques.md",
"decimal-phase-calculation.md",
"dispatch-isolation-gate.md",
"doc-conflict-engine.md",
"domain-probes.md",
"edge-probe.md",
"execute-mvp-tdd.md",
"execute-phase-between-wave-reset.md",
"execute-phase-context-guard.md",
"execute-phase-quota-recovery.md",
"execute-phase-requirement-revert.md",
"execute-phase-response-language.md",
"execute-phase-wave-guard.md",
"executor-examples.md",
"gate-prompts.md",
"gates.md",
"git-integration.md",
"git-planning-commit.md",
"gsd-run-resolver.md",
"honest-verifier.md",
"ios-scaffold.md",
"loop-hook-dispatch.md",
"mandatory-initial-read.md",
"model-profile-resolution.md",
"model-profiles.md",
"mvp-concepts.md",
"offer-next.md",
"phase-argument-parsing.md",
"planner-antipatterns.md",
"planner-chunked.md",
"planner-gap-closure.md",
"planner-graphify-auto-update.md",
"planner-guidance.md",
"planner-human-verify-mode.md",
"planner-interface-context.md",
"planner-load-graph-context.md",
"planner-mvp-mode.md",
"planner-preconditions.md",
"planner-reversibility.md",
"planner-reviews.md",
"planner-revision.md",
"planner-source-audit.md",
"planner-verify-command-grounding.md",
"planning-config.md",
"prohibition-probe.md",
"project-skills-discovery.md",
"questioning.md",
"research-documentation-lookup.md",
"research-philosophy.md",
"research-verification-protocol.md",
"reviewer-instances.md",
"revision-loop.md",
"runtime-aware-dispatch.md",
"scout-codebase.md",
"security-asvs-levels.md",
"skeleton-template.md",
"sketch-interactivity.md",
"sketch-theme-system.md",
"sketch-tooling.md",
"sketch-variant-patterns.md",
"specless-probe-fallback.md",
"spidr-splitting.md",
"tdd.md",
"thinking-models-debug.md",
"thinking-models-execution.md",
"thinking-models-planning.md",
"thinking-models-research.md",
"thinking-models-verification.md",
"thinking-partner.md",
"ui-brand.md",
"ui-consideration-probe.md",
"universal-anti-patterns.md",
"untrusted-input-boundary.md",
"user-profiling.md",
"user-story-template.md",
"verification-overrides.md",
"verification-patterns.md",
"verifier-phase-gates.md",
"verifier-wiring-patterns.md",
"verify-command-path-resolvability.md",
"verify-mvp-mode.md",
"workstream-flag.md",
"worktree-branch-check.md",
"worktree-path-safety.md"
],
"cli_modules": [
"active-workstream-store.cjs",
"adapter-declarative.cjs",
"adapter-imperative.cjs",
"adr-parser.cjs",
"agent-command-router.cjs",
"agent-install-check.cjs",
"api-coverage.cjs",
"artifacts.cjs",
"assumption-delta.cjs",
"audit-command-router.cjs",
"audit.cjs",
"broken-windows.cjs",
"capability-activation.cjs",
"capability-command-router.cjs",
"capability-consent.cjs",
"capability-ledger.cjs",
"capability-lifecycle.cjs",
"capability-loader.cjs",
"capability-lock.cjs",
"capability-registry.cjs",
"capability-source.cjs",
"capability-state.cjs",
"capability-trust.cjs",
"capability-validator.cjs",
"capability-writer.cjs",
"check-command-router.cjs",
"cjs-command-router-adapter.cjs",
"claude-orchestration-command-router.cjs",
"claude-orchestration.cjs",
"cli-exit.cjs",
"cli-skew-check.cjs",
"clock.cjs",
"clusters.cjs",
"code-review-depth.cjs",
"code-review-flags.cjs",
"codex-agent-toml.cjs",
"command-aliases.cjs",
"command-arg-projection.cjs",
"command-roster.cjs",
"command-routing-hub.cjs",
"commands.cjs",
"commonjs-marker.cjs",
"complexity-trigger.cjs",
"config-loader.cjs",
"config-schema.cjs",
"config-types.cjs",
"config.cjs",
"configuration.cjs",
"context-composer.cjs",
"context-predicates.cjs",
"context-utilization.cjs",
"core-utils.cjs",
"coverage.cjs",
"decisions.cjs",
"docs.cjs",
"drift.cjs",
"edge-probe.cjs",
"embedding-adapter.cjs",
"estimate-cli.cjs",
"eval-command-router.cjs",
"eval.cjs",
"external-descriptor-trust.cjs",
"external-job.cjs",
"fallow-runner.cjs",
"federated-config.cjs",
"frontmatter.cjs",
"gap-checker.cjs",
"gate-predicate-evaluator.cjs",
"git-base-branch.cjs",
"graphify-command-router.cjs",
"graphify.cjs",
"gsd2-import.cjs",
"handshake-serialized.cjs",
"health-diagnostic-rules/agent-install.cjs",
"health-diagnostic-rules/config-validation.cjs",
"health-diagnostic-rules/consistency.cjs",
"health-diagnostic-rules/install-surface-shadowing.cjs",
"health-diagnostic-rules/milestone-archive-hygiene.cjs",
"health-diagnostic-rules/phase-structure.cjs",
"health-diagnostic-rules/roadmap-disk-consistency.cjs",
"health-diagnostic-rules/root-existence.cjs",
"health-diagnostic-rules/state-consistency.cjs",
"health-diagnostic-rules/worktree-health.cjs",
"health-diagnostic-types.cjs",
"health-diagnostic.cjs",
"hook-bus.cjs",
"host-integration-adapters/cline-sdk-binding.cjs",
"host-integration-adapters/imperative-hook-bus.cjs",
"host-integration-sdk.cjs",
"host-integration.cjs",
"host-runtime-detection.cjs",
"init-command-router.cjs",
"init.cjs",
"install-effort-resolver.cjs",
"install-engine.cjs",
"install-fs-adapter.cjs",
"install-model-override-resolver.cjs",
"install-profiles.cjs",
"install-scope.cjs",
"install-shadow-report.cjs",
"installed-surface-resolver.cjs",
"installer-migration-authoring.cjs",
"installer-migration-report.cjs",
"installer-migrations.cjs",
"installer-migrations/000-first-time-baseline.cjs",
"installer-migrations/001-legacy-orphan-files.cjs",
"installer-migrations/002-codex-legacy-hooks-json.cjs",
"installer-migrations/003-rename-get-shit-done-to-gsd-core.cjs",
"installer-migrations/004-prune-stale-pristine-snapshots.cjs",
"installer-migrations/005-opencode-baseline-commands-dir.cjs",
"installer-migrations/006-pi-extension-cjs-to-js.cjs",
"installer-migrations/007-retire-config-root-commonjs-marker.cjs",
"installer-migrations/008-cursor-retire-commands-surface.cjs",
"installer-migrations/009-pi-retire-reserved-hooks-dir.cjs",
"intel-command-router.cjs",
"intel.cjs",
"io.cjs",
"learnings.cjs",
"legacy-cleanup.cjs",
"loop-host-contract.cjs",
"loop-resolver.cjs",
"markdown-sectionizer.cjs",
"markdown-table.cjs",
"mcp-catalog.cjs",
"mcp-server.cjs",
"milestone-lock.cjs",
"milestone.cjs",
"model-adapter.cjs",
"model-catalog.cjs",
"model-profiles.cjs",
"model-resolver.cjs",
"normalize-test-command.cjs",
"observability/event.cjs",
"observability/logger.cjs",
"observability/redaction.cjs",
"onboard-projection.cjs",
"package-identity.cjs",
"package-legitimacy.cjs",
"pattern.cjs",
"phase-command-router.cjs",
"phase-estimation.cjs",
"phase-id.cjs",
"phase-lifecycle.cjs",
"phase-locator.cjs",
"phase.cjs",
"phases-command-router.cjs",
"plan-dependency-graph.cjs",
"plan-document.cjs",
"plan-drift-guard.cjs",
"plan-scan.cjs",
"planning-command-router.cjs",
"planning-inspect.cjs",
"planning-scope.cjs",
"planning-snapshot.cjs",
"planning-workspace.cjs",
"probe-core.cjs",
"profile-output.cjs",
"profile-pipeline-command-router.cjs",
"profile-pipeline.cjs",
"prohibition-enforcement.cjs",
"project-root.cjs",
"prompt-budget.cjs",
"refactor-trigger-command-router.cjs",
"research-provider.cjs",
"research-store.cjs",
"resolution.cjs",
"retired-artifact-cleanup.cjs",
"review-lane-descriptor.cjs",
"review-lane-invocation.cjs",
"review-lane-runner.cjs",
"review-reviewer-selection.cjs",
"roadmap-command-router.cjs",
"roadmap-parser.cjs",
"roadmap-upgrade.cjs",
"roadmap.cjs",
"runtime-artifact-conversion.cjs",
"runtime-artifact-install-plan.cjs",
"runtime-artifact-layout.cjs",
"runtime-config-adapter-registry.cjs",
"runtime-homes.cjs",
"runtime-hooks-surface.cjs",
"runtime-name-policy.cjs",
"runtime-slash.cjs",
"schema-detect.cjs",
"secrets.cjs",
"section-manifest.cjs",
"security.cjs",
"semver-compare.cjs",
"shell-command-projection.cjs",
"smart-entry.cjs",
"spec-section.cjs",
"stale-bake-guard.cjs",
"state-command-router.cjs",
"state-document.cjs",
"state-io.cjs",
"state-transition.cjs",
"state.cjs",
"surface.cjs",
"task-command-router.cjs",
"teams-status.cjs",
"template.cjs",
"test-home-guard.cjs",
"text-lines.cjs",
"token-scanner.cjs",
"uat-predicate.cjs",
"uat.cjs",
"ui-consideration-probe.cjs",
"ui-frontend-evidence.cjs",
"ui-safety-gate.cjs",
"unusable-input.cjs",
"update-context.cjs",
"user-artifact-staging.cjs",
"validate-command-router.cjs",
"validate.cjs",
"vendor/re2js.cjs",
"verification-command-router.cjs",
"verification.cjs",
"verify-command-grounding.cjs",
"verify-command-router.cjs",
"verify.cjs",
"workflow-fragments.cjs",
"workstream-inventory-builder.cjs",
"workstream-inventory.cjs",
"workstream-name-policy.cjs",
"workstream.cjs",
"worktree-base-ref.cjs",
"worktree-safety.cjs",
"write-set.cjs"
],
"hooks": [
"gsd-agent-isolation-guard.js",
"gsd-check-update-worker.js",
"gsd-check-update.js",
"gsd-config-reload.js",
"gsd-context-monitor.js",
"gsd-cursor-post-tool.js",
"gsd-cursor-pre-tool.js",
"gsd-cursor-session-start.js",
"gsd-cursor-stop.js",
"gsd-cursor-subagent-start.js",
"gsd-cursor-subagent-stop.js",
"gsd-ensure-canonical-path.js",
"gsd-graphify-update.sh",
"gsd-phase-boundary.sh",
"gsd-prompt-guard.js",
"gsd-read-guard.js",
"gsd-read-injection-scanner.js",
"gsd-session-state.sh",
"gsd-statusline.js",
"gsd-update-banner.js",
"gsd-validate-commit.sh",
"gsd-windsurf-pre-command.js",
"gsd-windsurf-pre-write.js",
"gsd-workflow-guard.js",
"gsd-worktree-path-guard.js",
"gsd-write-guard.js"
],
"workflow_modes": [
"discuss-phase/modes/advisor.md",
"discuss-phase/modes/all.md",
"discuss-phase/modes/analyze.md",
"discuss-phase/modes/auto.md",
"discuss-phase/modes/batch.md",
"discuss-phase/modes/chain.md",
"discuss-phase/modes/default.md",
"discuss-phase/modes/power.md",
"discuss-phase/modes/text.md",
"help/modes/brief.md",
"help/modes/default.md",
"help/modes/full.md",
"help/modes/topic.md"
],
"workflow_steps": [
"autonomous/steps/converge-banner.md",
"autonomous/steps/converge-dispatch-bg.md",
"autonomous/steps/converge-dispatch-inline.md",
"autonomous/steps/converge-fail-fast.md",
"autonomous/steps/converge-loop.md",
"code-review/steps/dispatch-fix.md",
"code-review/steps/structural-pre-pass.md",
"complete-milestone/steps/git-tag.md",
"discuss-phase-assumptions/steps/auto-advance-dispatch.md",
"docs-update/steps/dispatch-monorepo-packages.md",
"execute-phase/steps/codebase-drift-gate.md",
"execute-phase/steps/executor-isolation-dispatch.md",
"execute-phase/steps/gap-closure-artifacts.md",
"execute-phase/steps/partial-wave.md",
"execute-phase/steps/per-plan-executor-routing.md",
"execute-phase/steps/per-plan-worktree-gate.md",
"execute-phase/steps/post-merge-gate.md",
"execute-phase/steps/regression-gate-run.md",
"execute-phase/steps/regression-gate.md",
"execute-phase/steps/wave-post-gate-hooks.md",
"execute-phase/steps/worktree-recovery-policy.md",
"new-milestone/steps/project-md-milestone-write.md",
"new-milestone/steps/reset-phase-safety.md",
"new-project/steps/auto-mode-config.md",
"new-project/steps/auto-mode-detection.md",
"new-project/steps/codebase-map-offer.md",
"plan-phase/steps/adr-ingest-express-path.md",
"plan-phase/steps/chunked-planning-mode.md",
"plan-phase/steps/closed-phase-gate.md",
"plan-phase/steps/prd-express-gate.md",
"plan-phase/steps/prd-express-path.md",
"plan-phase/steps/research-only-early-exit.md",
"plan-phase/steps/research-only-modifiers.md",
"plan-phase/steps/reviews-prerequisite.md",
"plan-phase/steps/stall-detection-helpers.md",
"plan-phase/steps/windows-troubleshooting.md",
"progress/steps/forensic-audit.md",
"progress/steps/mvp-display.md",
"quick/steps/discussion-phase.md",
"quick/steps/plan-checker-loop.md",
"quick/steps/quick-verification.md",
"quick/steps/research-phase.md",
"quick/steps/worktree-pre-dispatch-commit.md",
"review/steps/reviewer-instances-note-1.md",
"review/steps/reviewer-instances-note-2.md",
"transition/steps/workstream-collision-check.md",
"update/steps/channel-banner.md",
"verify-work/steps/automated-ui-verification.md",
"verify-work/steps/mvp-uat-framing.md"
]
}
}