Tom Boucher
b37c487325
feat(security): package legitimacy gate against slopsquatting (#3215)
* feat(security): package legitimacy gate against slopsquatting (#2827)
GSD's research → plan → execute pipeline had no install-time legitimacy
gate: a hallucinated package name that passes `npm view` could flow all
the way to `gsd-executor` running `npm install <malicious-pkg>` with no
human checkpoint. This PR closes that gap.
Changes:
- gsd-phase-researcher: runs slopcheck on every recommended package;
emits `## Package Legitimacy Audit` table; strips [SLOP] packages;
ecosystem-specific verification (pip/npm/cargo); WebSearch-sourced
packages tagged [ASSUMED]; ctx7 fallback uses `command -v` guard
instead of `npx --yes`
- gsd-planner: injects `checkpoint:human-verify` before [ASSUMED]/[SUS]
installs; adds T-{phase}-SC STRIDE row to <threat_model> template;
ctx7 fallback also uses `command -v` guard
- gsd-executor: RULE 3 excludes package installs from auto-fix; failed
installs surface as checkpoints, never silent substitutions
- tests/package-legitimacy-gate.test.cjs: 24 structural assertions
covering the full gate (node:test + node:assert, no raw .includes())
- docs: USER-GUIDE, COMMANDS, ARCHITECTURE updated with gate description
- .changeset: Security fragment for v1.51 release notes
Closes #2827
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* docs: expand Package Legitimacy Gate documentation
Add full user-facing depth to the gate docs across USER-GUIDE,
COMMANDS, and ARCHITECTURE:
- USER-GUIDE: rewrite gate section with concrete RESEARCH.md/PLAN.md
examples, slopcheck verdict table, [ASSUMED] WebSearch tagging
explanation, slopcheck-unavailable troubleshooting, and graceful
degradation behavior
- COMMANDS.md: expand /gsd-plan-phase gate note with verdict bullets;
add install-failure checkpoint behavior to /gsd-execute-phase
- ARCHITECTURE.md: expand gate section with threat model rationale,
layer table, claim provenance integration, ecosystem coverage, and
graceful degradation semantics
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(security): harden package legitimacy checkpoint semantics
* fix(planner): satisfy size gates and tighten package gate wording
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-08 09:08:06 -04:00
..
2026-04-10 21:29:37 -04:00
2026-04-12 17:56:19 -04:00
2026-03-21 00:21:17 -04:00
2026-05-02 17:23:44 -04:00
2026-04-20 18:20:08 -04:00
2026-05-05 13:19:10 -04:00
2026-05-06 15:00:08 -04:00
2026-04-27 12:31:43 -04:00
2026-04-20 18:09:02 -04:00
2026-04-17 17:12:02 -05:00
2026-04-20 18:20:08 -04:00
2026-04-18 12:10:22 -04:00
2026-04-12 17:56:19 -04:00
2026-04-20 18:20:08 -04:00
2026-04-12 17:56:19 -04:00
2026-05-08 09:08:06 -04:00
2026-04-10 10:49:00 -04:00
2026-04-20 18:20:08 -04:00
2026-05-08 09:06:37 -04:00
2026-04-20 18:20:08 -04:00
2026-04-16 17:15:29 -04:00
2026-05-08 09:08:06 -04:00
2026-05-04 23:18:41 -04:00
2026-05-08 09:08:06 -04:00
2026-04-22 12:04:13 -04:00
2026-04-27 12:31:43 -04:00
2026-05-04 23:18:41 -04:00
2026-04-20 18:20:08 -04:00
2026-04-20 18:20:08 -04:00
2026-04-17 09:26:49 -04:00
2026-04-27 12:31:43 -04:00
2026-04-03 11:28:18 -04:00
2026-05-06 21:51:38 -04:00