* feat: Phase 2 caller migration — gsd-sdk query in workflows (#2122) Cherry-picked orchestration rewrites from feat/sdk-foundation (#2008, 4018fee) onto current main, resolving conflicts to keep upstream worktree guards and post-merge test gate. SDK stub registry omitted (out of Phase 2 scope per #2122). Refs: #2122 #2008 Made-with: Cursor * docs: add gsd-sdk query migration blurb Made-with: Cursor * docs(workflows): extend Phase 2 gsd-sdk query caller migration - Swap node gsd-tools.cjs for gsd-sdk query in review, plan-phase, execute-plan, ship, extract_learnings, ai-integration-phase, eval-review, next, thread - Document graphify CJS-only in gsd-planner; dual-path in CLI-TOOLS and ARCHITECTURE - Update tests: workstreams gsd-sdk path, thread frontmatter.get, workspace init.*, CRLF-safe autonomous frontmatter parse - CHANGELOG: Phase 2 caller migration scope Made-with: Cursor * docs(phase2): USER-GUIDE + remaining gsd-sdk query call sites - USER-GUIDE: dual-path CLI section; state validate/sync use full CJS path - Commands: debug (config-get+tdd), quick (security note), intel Task prompt - Agent: gsd-debug-session-manager resolve-model via jq - Workflows: milestone-summary, forensics, next, complete-milestone/verify-work (audit-open CJS notes), discuss-phase, progress, verify-phase, add/insert/remove phase, transition, manager, quick workflow; remove-phase commit without --files - Test: quick-session-management accepts frontmatter.get - CHANGELOG: Phase 2 follow-up bullet Made-with: Cursor * docs(phase2): align gsd-sdk query examples in commands and agents - init.* query names; frontmatter.get uses positional field name - state.* handlers use positional args; commit uses positional paths - CJS-only notes for from-gsd2 and graphify; learnings.query wording - CHANGELOG: Phase 2 orchestration doc pass Made-with: Cursor * docs(phase2): normalize gsd-sdk query commit to positional file paths - Strip --files from commit examples in workflows, references, commands - Keep commit-to-subrepo ... --files (separate handler) - git-planning-commit.md: document positional args - Tests: new-project commit line, state.record-session, gates CRLF, roadmap.analyze - CHANGELOG [Unreleased] Made-with: Cursor * feat(sdk): gsd-sdk query parity with gsd-tools and PR 2179 registry fixes - Route query via longest-prefix match and dotted single-token expansion; fall back to runGsdToolsQuery (same argv as node gsd-tools.cjs) for full CLI coverage. - Parse gsd-sdk query permissively so gsd-tools flags (--json, --verify, etc.) are not rejected by strict parseArgs. - resolveGsdToolsPath: honor GSD_TOOLS_PATH; prefer bundled get-shit-done copy over project .claude installs; export runGsdToolsQuery from the SDK. - Fix gsd-tools audit-open (core.output; pass object for --json JSON). - Register summary-extract as alias of summary.extract; fix audit-fix workflow to call audit-uat instead of invalid init.audit-uat (PR review). Updates QUERY-HANDLERS.md and CHANGELOG [Unreleased]. Made-with: Cursor * fix(sdk): Phase 2 scope — Trek-e review (#2179, #2122) - Remove gsd-sdk query passthrough to gsd-tools.cjs; drop GSD_TOOLS_PATH - Consolidate argv routing in resolveQueryArgv(); update USAGE and QUERY-HANDLERS - Surface @file: read failures in GSDTools.parseOutput - execute-plan: defer Task Commit Protocol to gsd-executor - stale-colon-refs: skip .planning/ and root CLAUDE.md (gitignored overlays) - CHANGELOG [Unreleased]: maintainer review and routing notes Made-with: Cursor
167 lines
5.7 KiB
Markdown
167 lines
5.7 KiB
Markdown
<purpose>
|
|
Verify threat mitigations for a completed phase. Confirm PLAN.md threat register dispositions are resolved. Update SECURITY.md.
|
|
</purpose>
|
|
|
|
<required_reading>
|
|
@~/.claude/get-shit-done/references/ui-brand.md
|
|
</required_reading>
|
|
|
|
<available_agent_types>
|
|
Valid GSD subagent types (use exact names — do not fall back to 'general-purpose'):
|
|
- gsd-security-auditor — Verifies threat mitigation coverage
|
|
</available_agent_types>
|
|
|
|
<process>
|
|
|
|
## 0. Initialize
|
|
|
|
```bash
|
|
INIT=$(gsd-sdk query init.phase-op "${PHASE_ARG}")
|
|
if [[ "$INIT" == @file:* ]]; then INIT=$(cat "${INIT#@file:}"); fi
|
|
AGENT_SKILLS_AUDITOR=$(gsd-sdk query agent-skills gsd-security-auditor 2>/dev/null)
|
|
```
|
|
|
|
Parse: `phase_dir`, `phase_number`, `phase_name`, `phase_slug`, `padded_phase`.
|
|
|
|
```bash
|
|
AUDITOR_MODEL=$(gsd-sdk query resolve-model gsd-security-auditor --raw)
|
|
SECURITY_CFG=$(gsd-sdk query config-get workflow.security_enforcement --raw 2>/dev/null || echo "true")
|
|
```
|
|
|
|
If `SECURITY_CFG` is `false`: exit with "Security enforcement disabled. Enable via /gsd-settings."
|
|
|
|
Display banner: `GSD > SECURE PHASE {N}: {name}`
|
|
|
|
## 1. Detect Input State
|
|
|
|
```bash
|
|
SECURITY_FILE=$(ls "${PHASE_DIR}"/*-SECURITY.md 2>/dev/null | head -1)
|
|
PLAN_FILES=$(ls "${PHASE_DIR}"/*-PLAN.md 2>/dev/null)
|
|
SUMMARY_FILES=$(ls "${PHASE_DIR}"/*-SUMMARY.md 2>/dev/null)
|
|
```
|
|
|
|
- **State A** (`SECURITY_FILE` non-empty): Audit existing
|
|
- **State B** (`SECURITY_FILE` empty, `PLAN_FILES` and `SUMMARY_FILES` non-empty): Run from artifacts
|
|
- **State C** (`SUMMARY_FILES` empty): Exit — "Phase {N} not executed. Run /gsd-execute-phase {N} first."
|
|
|
|
## 2. Discovery
|
|
|
|
### 2a. Read Phase Artifacts
|
|
|
|
Read PLAN.md — extract `<threat_model>` block: trust boundaries, STRIDE register (`threat_id`, `category`, `component`, `disposition`, `mitigation_plan`).
|
|
|
|
### 2b. Read Summary Threat Flags
|
|
|
|
Read SUMMARY.md — extract `## Threat Flags` entries.
|
|
|
|
### 2c. Build Threat Register
|
|
|
|
Per threat: `{ threat_id, category, component, disposition, mitigation_pattern, files_to_check }`
|
|
|
|
## 3. Threat Classification
|
|
|
|
Classify each threat:
|
|
|
|
| Status | Criteria |
|
|
|--------|----------|
|
|
| CLOSED | mitigation found OR accepted risk documented in SECURITY.md OR transfer documented |
|
|
| OPEN | none of the above |
|
|
|
|
Build: `{ threat_id, category, component, disposition, status, evidence }`
|
|
|
|
If `threats_open: 0` → skip to Step 6 directly.
|
|
|
|
## 4. Present Threat Plan
|
|
|
|
|
|
**Text mode (`workflow.text_mode: true` in config or `--text` flag):** Set `TEXT_MODE=true` if `--text` is present in `$ARGUMENTS` OR `text_mode` from init JSON is `true`. When TEXT_MODE is active, replace every `AskUserQuestion` call with a plain-text numbered list and ask the user to type their choice number. This is required for non-Claude runtimes (OpenAI Codex, Gemini CLI, etc.) where `AskUserQuestion` is not available.
|
|
Call AskUserQuestion with threat table and options:
|
|
1. "Verify all open threats" → Step 5
|
|
2. "Accept all open — document in accepted risks log" → add to SECURITY.md accepted risks, set all CLOSED, Step 6
|
|
3. "Cancel" → exit
|
|
|
|
## 5. Spawn gsd-security-auditor
|
|
|
|
```
|
|
Task(
|
|
prompt="Read ~/.claude/agents/gsd-security-auditor.md for instructions.\n\n" +
|
|
"<files_to_read>{PLAN, SUMMARY, impl files, SECURITY.md}</files_to_read>" +
|
|
"<threat_register>{threat register}</threat_register>" +
|
|
"<config>asvs_level: {SECURITY_ASVS}, block_on: {SECURITY_BLOCK_ON}</config>" +
|
|
"<constraints>Never modify implementation files. Verify mitigations exist — do not scan for new threats. Escalate implementation gaps.</constraints>" +
|
|
"${AGENT_SKILLS_AUDITOR}",
|
|
subagent_type="gsd-security-auditor",
|
|
model="{AUDITOR_MODEL}",
|
|
description="Verify threat mitigations for Phase {N}"
|
|
)
|
|
```
|
|
|
|
Handle return:
|
|
- `## SECURED` → record closures → Step 6
|
|
- `## OPEN_THREATS` → record closed + open, present user with accept/block choice → Step 6
|
|
- `## ESCALATE` → present to user → Step 6
|
|
|
|
## 6. Write/Update SECURITY.md
|
|
|
|
**State B (create):**
|
|
1. Read template from `~/.claude/get-shit-done/templates/SECURITY.md`
|
|
2. Fill: frontmatter, threat register, accepted risks, audit trail
|
|
3. Write to `${PHASE_DIR}/${PADDED_PHASE}-SECURITY.md`
|
|
|
|
**State A (update):**
|
|
1. Update threat register statuses, append to audit trail:
|
|
|
|
```markdown
|
|
## Security Audit {date}
|
|
| Metric | Count |
|
|
|--------|-------|
|
|
| Threats found | {N} |
|
|
| Closed | {M} |
|
|
| Open | {K} |
|
|
```
|
|
|
|
**ENFORCING GATE:** If `threats_open > 0` after all options exhausted (user did not accept, not all verified closed):
|
|
|
|
```
|
|
GSD > PHASE {N} SECURITY BLOCKED
|
|
{K} threats open — phase advancement blocked until threats_open: 0
|
|
▶ Fix mitigations then re-run: /gsd-secure-phase {N}
|
|
▶ Or document accepted risks in SECURITY.md and re-run.
|
|
```
|
|
|
|
Do NOT emit next-phase routing. Stop here.
|
|
|
|
## 7. Commit
|
|
|
|
```bash
|
|
gsd-sdk query commit "docs(phase-${PHASE}): add/update security threat verification"
|
|
```
|
|
|
|
## 8. Results + Routing
|
|
|
|
**Secured (threats_open: 0):**
|
|
```
|
|
GSD > PHASE {N} THREAT-SECURE
|
|
threats_open: 0 — all threats have dispositions.
|
|
▶ /gsd-validate-phase {N} validate test coverage
|
|
▶ /gsd-verify-work {N} run UAT
|
|
```
|
|
|
|
Display `/clear` reminder.
|
|
|
|
</process>
|
|
|
|
<success_criteria>
|
|
- [ ] Security enforcement checked — exit if false
|
|
- [ ] Input state detected (A/B/C) — state C exits cleanly
|
|
- [ ] PLAN.md threat model parsed, register built
|
|
- [ ] SUMMARY.md threat flags incorporated
|
|
- [ ] threats_open: 0 → skip directly to Step 6
|
|
- [ ] User gate with threat table presented
|
|
- [ ] Auditor spawned with complete context
|
|
- [ ] All three return formats (SECURED/OPEN_THREATS/ESCALATE) handled
|
|
- [ ] SECURITY.md created or updated
|
|
- [ ] threats_open > 0 BLOCKS advancement (no next-phase routing emitted)
|
|
- [ ] Results with routing presented on success
|
|
</success_criteria>
|