Files
msd-core/tests/fixtures/install-tree/codex.json
Tom Boucher c5e0371775 feat(#1951): reversibility tagging — gate one-way-door decisions (#2471)
* test(#1951): add failing-first tests for reversibility tagging

Red phase for issue #1951 (reversibility tagging: classify decisions by
undo cost, gate one-way doors behind a checkpoint:decision).

Tests assert, per the issue's acceptance criteria:
- discuss-phase CONTEXT.md template records a **Reversibility:** field with
  a rationale on captured decisions, and states it is optional
- gsd-planner @-references planner-reversibility.md and stays under the
  49152-char agent cap (LARGE_CAP, tests/agent-size-budget.test.cjs)
- a one-way rating inserts a checkpoint:decision before the dependent task;
  reversible inserts none; costly is flagged but never blocks
- the taxonomy defaults to reversible when unsure (checkpoint-fatigue guard)
  and inserting a checkpoint implies autonomous: false
- docs/reference/plan-md.md documents <reversibility> as optional with all
  three ratings
- --no-reversibility-gates parses to REVERSIBILITY_GATES=false, is injected
  into the planner prompt, and is advertised in the command argument-hint
  and help full mode (argument-hint parity)
- the override suppresses the gate but still persists the rating
- cmdVerifyPlanStructure accepts every rating and the absent case
  (additive-validator guarantee, behavioral via runGsdTools)
- parity: thinking-models-planning.md #4 adopts the canonical three-level
  taxonomy and the binary REVERSIBLE/IRREVERSIBLE vocabulary is gone
- no content loss from the planner extraction made to fit under the cap

Prose-contract assertions are Red until the implementation lands. The
behavioral validator assertions pass immediately — regression guards
proving the validator already accepts unknown optional tags.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1951): reversibility tagging — gate one-way-door decisions

Classify planning decisions by what undoing them would cost, and give a
one-way door a human beat before the agent walks through it (issue #1951,
The Pragmatic Programmer Topic 15 'Reversibility'; Bezos's one-way/two-way
door framing).

Acceptance criteria met:
- discuss-phase records an optional reversibility rating with a rationale
  on <decisions> entries in the phase CONTEXT.md template. Unrated
  decisions are treated as reversible, so existing phases are unaffected.
- a one-way rating makes gsd-planner insert a checkpoint:decision before
  the task that implements the decision, reusing the existing checkpoint
  mechanism -- no new checkpoint machinery.
- reversible ratings trigger no checkpoint; costly ratings are flagged in
  the plan but never block.
- the rating persists on the task as the optional <reversibility rating=>
  element. cmdVerifyPlanStructure accepts every rating and the absent
  case; the structural validator does not reject unknown optional tags.
- --no-reversibility-gates (REVERSIBILITY_GATES=false) suppresses
  checkpoint insertion for intentionally-unattended runs while still
  recording ratings -- the override changes what stops the run, not what
  the plan remembers.

Single taxonomy, not two: references/thinking-models-planning.md #4
already shipped a binary REVERSIBLE/IRREVERSIBLE classification and is
loaded by both gsd-planner and gsd-plan-checker. It is rewritten onto the
canonical three-level vocabulary and now points at planner-reversibility.md
as the taxonomy owner, with a parity test that fails if the surfaces
diverge (DEFECT.GENERATIVE-FIX-DIVERGENCE).

agents/gsd-planner.md sat 47 chars under the 49152 LARGE_CAP, so the
checkpoint DO/DON'T guidance was relocated verbatim into
planner-antipatterns.md -- already @-referenced from the same section for
the same topic, so the planner still loads it and nothing was dropped. A
test guards the relocation against content loss.

Files: gsd-core/references/planner-reversibility.md (NEW, canonical
taxonomy + emission rules + anti-patterns), gsd-planner.md, plan-phase
workflow/command/help (flag wiring + parity), plan-md.md schema,
discuss-phase context template, CONTEXT.md glossary, INVENTORY + manifest,
size baselines, install goldens, plugin skills regen, changeset.

Closes #1951

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1951): address orthogonal review findings

Two isolated reviewers (correctness + security), neither of which authored
the change. Every finding fixed:

Security — the rationale is untrusted input (ADR-1577). It originates in
conversation and flows CONTEXT.md -> planner -> PLAN.md -> executor, each
hop an LLM reading the previous hop's output, with no validation on the
path. planner-reversibility.md and the discuss-phase template now state
it is data and never instructions, and name the </reversibility>
early-termination hazard explicitly -- a rationale that closes its own
element injects sibling structure the executor reads as real tasks.
Four tests guard it.

Correctness 1 — nothing machine-enforced the feature's own promise: a task
rated one-way with no preceding checkpoint:decision validated as fully
clean, so a planner error silently reopened the gap this feature exists to
close. cmdVerifyPlanStructure now warns on an ungated one-way rating. A
warning, not an error: <reversibility> stays additive and the plan stays
valid. Four tests cover ungated (warns), gated (silent), still-valid, and
reversible/costly never flagged.

Correctness 2 — pass-always test. The --no-reversibility-gates parse test
substring-matched the whole workflow file, and plan-phase.md prose mentions
both tokens in one sentence, so it passed with the bash conditional
deleted: it was testing the documentation, not the parser. Now scoped to
the fenced bash blocks and matched as one physical line, with a negative
control confirming prose alone cannot satisfy it.

Correctness 3 — costly had no itemized emission rule, only one-way did, so
two agents could diverge on whether to tag costly at all.

Correctness 4 — template convention break: the example ratings were bare
while every sibling field uses [...] to signal substitution, inviting an
LLM to copy one-way/costly forward as boilerplate. Now bracketed.

Correctness 5 — latent false-green: .includes('reversible') also matches
inside irreversible/irreversibility, which appear in anti-pattern
prose, so a surface that dropped the real taxonomy entry would still pass.
Now word-boundary matched.

ADR-857 phase-6 ceiling — the first gsd-test run caught plan-phase.md
1216 bytes over its frozen 94519 ceiling (it had 49 bytes of headroom on
next). The ceiling may only rise for privileged host machinery, and
reversibility gating is optional-feature logic, so the wiring was slimmed
to its minimum and the explanatory prose moved to the reference files the
planner already loads. plan-phase.md is now 94400 bytes -- 119 under the
ceiling and 70 bytes SMALLER than on next, so the host loop shrank while
gaining the feature, which is what phase 6 ratchets toward. The tracer
contract (tests/tracer-bullet.test.cjs) is unchanged.

Lint — fixed an unnecessary non-null assertion in verify.cts and a
CRLF-fragile bare \n regex in the new test (DEFECT.WINDOWS-CRLF-TEST-
PORTABILITY, the #1658/#1668/#2206/#2449/#2450 class).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1951): checkpoint fixture must carry the common task elements

The gated-one-way fixture built a checkpoint:decision task from the
abbreviated skeleton in gsd-planner.md, which shows only the
checkpoint-specific elements (<decision>/<context>/<resume-signal>).
cmdVerifyPlanStructure requires <name> and <action> on EVERY task
regardless of type, so the fixture failed validation for reasons that had
nothing to do with reversibility:

  errors: ["Task missing <name> element", "Task 'unnamed' missing <action>"]

Caught by gsd-test on 14d14a39 (2 failures, both this fixture).

The canonical shape is in tests/verify.test.cjs:266 — a checkpoint task
carries <name>/<files>/<action>/<verify> like any other. Fixture corrected
to match. Verified behaviorally against the real gsd-tools CLI across all
four cases: gated one-way (valid, silent), ungated one-way (valid, warns),
costly (valid, silent), absent (valid, silent).

Not a product defect: the validator's every-task contract is intentional
and pre-existing, and docs/reference/plan-md.md scopes its required-element
list to type=auto/tracer only because those are the elements a planner must
author, not because checkpoints are exempt from <name>.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(#1951): backfill changeset pr number to 2471

* fix(#1951): CodeQL incomplete-sanitization + prompt-injection scan collision

Both CI failures were real defects in code this PR added, not false
positives.

CodeQL js/incomplete-sanitization (high), reversibility-tagging.test.cjs:46 —
the namesRating helper built its regex with `rating.replace(/[-]/g, '\\-')`,
which escapes the hyphen but not backslash, so the escape was incomplete.
It was also unnecessary: `-` carries no special meaning outside a character
class. Replaced with a complete metacharacter escape (backslash included).
Word-boundary behavior verified unchanged across all three ratings — notably
that "irreversible" prose still does not satisfy a "reversible" match, which
is the false-green this helper exists to prevent.

Prompt injection scan — the checkpoint fixture used the human-verification
child element inside <verify>. That tag name is a fake-instruction-boundary
pattern in scripts/prompt-injection-scan.sh, and the scan runs over changed
files, so copying the shape from tests/verify.test.cjs (unflagged only
because it is not in this diff) tripped the gate. Switched to the documented
plain-prose <verify> form.

The first attempt at that fix failed the same gate a second time: the
comment explaining the collision quoted the offending tag literally. The
comment now names it in prose instead — the scanner does not care whether a
match is code or commentary, which is the whole point of the
DEFECT.PROMPT-INJECTION-SCAN-COLLISION note in CLAUDE.md.

Verified locally before push: scan reports 0 findings across 57 changed
files, eslint clean, and both fixtures still validate as designed (gated
one-way silent, ungated one-way warns, neither errors).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1951): record measured cost and halve gsd-tools spawns

The Windows shard 1/3 job timeout was traced to the sharding layer, not to
this PR's assertions — see #2472. Two contributing factors were this file's
own, and are fixed here.

1. tests/test-timings.json had no entry for reversibility-tagging.test.cjs,
   so scripts/run-tests.cjs weighted it at the table's median fallback
   (~315ms) for LPT chunk packing. It actually measures 5595ms — an 18x
   under-weight. Recorded the measured value from the green gsd-test run
   (max across the node22/node24 lanes, per gen-test-timings.cjs's
   convention). Only this one entry: a full regen churns 634 entries of
   run-to-run drift, and the table is explicitly advisory and un-gated, so
   a 637-line diff does not belong in a feature PR.

2. Each verifyPlan() spawns gsd-tools, which dominates this file's cost.
   Spawns cut from 9 to 6 with no coverage lost:
   - the ungated-one-way warning and its stays-valid assertion now share
     one plan instead of building the same plan twice;
   - the reversible/costly never-flagged-as-ungated test was strictly
     subsumed by the additive suite, which already runs those two ratings
     ungated and asserts no /reversibilit/ warning at all — and the gate
     warning's text contains both "reversibility" and "one-way", so the
     broader assertion catches it. It only re-spawned gsd-tools twice to
     prove the same thing.

Both are symptom fixes. The shard imbalance itself (19/11/10 minutes
against a 20-minute cap, from a cost-blind round-robin partition that also
reshuffles downstream files whenever one is inserted) is tracked in #2472.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1951): checkpoint fixture adopts the #2444 type-branched contract

Surfaced by rebasing onto next, which gained #2444 (branch plan-structure
validation on task type=checkpoint:*) while this PR was in review.

cmdVerifyPlanStructure no longer applies one required-element set to every
task. A checkpoint:decision now requires <name> + <resume-signal> +
<decision> + <options>, and is exempt from the <action>/<verify>/<done>/
<files> set that auto and tracer tasks carry. The gated-one-way fixture
predated that split and failed on the new requirement:

  errors: ["Task 'Task 0: Confirm the on-disk format' missing <options>"]

Fixture rewritten to mirror the checkpoint:decision contract exactly — real
<options> with two <option> children — rather than padding it with fields
checkpoints no longer need. That also drops the plain-prose <verify> the
earlier revision carried purely to dodge the prompt-injection scan; a
checkpoint task has no <verify> requirement at all, so the workaround is
moot.

Verified against the real gsd-tools CLI across all four cases: gated one-way
(valid, silent), ungated one-way (valid, warns), costly (valid, silent),
absent (valid, silent).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-21 10:44:55 -04:00

449 lines
19 KiB
JSON

[
".agents/skills/gsd-add-tests/SKILL.md",
".agents/skills/gsd-ai-integration-phase/SKILL.md",
".agents/skills/gsd-audit-fix/SKILL.md",
".agents/skills/gsd-audit-milestone/SKILL.md",
".agents/skills/gsd-audit-uat/SKILL.md",
".agents/skills/gsd-autonomous/SKILL.md",
".agents/skills/gsd-capture/SKILL.md",
".agents/skills/gsd-cleanup/SKILL.md",
".agents/skills/gsd-code-review/SKILL.md",
".agents/skills/gsd-complete-milestone/SKILL.md",
".agents/skills/gsd-config/SKILL.md",
".agents/skills/gsd-debug/SKILL.md",
".agents/skills/gsd-discuss-phase/SKILL.md",
".agents/skills/gsd-docs-update/SKILL.md",
".agents/skills/gsd-eval-review/SKILL.md",
".agents/skills/gsd-execute-phase/SKILL.md",
".agents/skills/gsd-explore/SKILL.md",
".agents/skills/gsd-extract-learnings/SKILL.md",
".agents/skills/gsd-fast/SKILL.md",
".agents/skills/gsd-forensics/SKILL.md",
".agents/skills/gsd-graphify/SKILL.md",
".agents/skills/gsd-health/SKILL.md",
".agents/skills/gsd-help/SKILL.md",
".agents/skills/gsd-import/SKILL.md",
".agents/skills/gsd-inbox/SKILL.md",
".agents/skills/gsd-ingest-docs/SKILL.md",
".agents/skills/gsd-manager/SKILL.md",
".agents/skills/gsd-map-codebase/SKILL.md",
".agents/skills/gsd-mempalace-capture/SKILL.md",
".agents/skills/gsd-mempalace-recall/SKILL.md",
".agents/skills/gsd-milestone-summary/SKILL.md",
".agents/skills/gsd-mvp-phase/SKILL.md",
".agents/skills/gsd-new-milestone/SKILL.md",
".agents/skills/gsd-new-project/SKILL.md",
".agents/skills/gsd-next/SKILL.md",
".agents/skills/gsd-ns-context/SKILL.md",
".agents/skills/gsd-ns-ideate/SKILL.md",
".agents/skills/gsd-ns-manage/SKILL.md",
".agents/skills/gsd-ns-project/SKILL.md",
".agents/skills/gsd-ns-review/SKILL.md",
".agents/skills/gsd-ns-workflow/SKILL.md",
".agents/skills/gsd-onboard/SKILL.md",
".agents/skills/gsd-pause-work/SKILL.md",
".agents/skills/gsd-phase/SKILL.md",
".agents/skills/gsd-plan-phase/SKILL.md",
".agents/skills/gsd-plan-review-convergence/SKILL.md",
".agents/skills/gsd-pr-branch/SKILL.md",
".agents/skills/gsd-profile-user/SKILL.md",
".agents/skills/gsd-progress/SKILL.md",
".agents/skills/gsd-quick/SKILL.md",
".agents/skills/gsd-resume-work/SKILL.md",
".agents/skills/gsd-review-backlog/SKILL.md",
".agents/skills/gsd-review/SKILL.md",
".agents/skills/gsd-secure-phase/SKILL.md",
".agents/skills/gsd-settings/SKILL.md",
".agents/skills/gsd-ship/SKILL.md",
".agents/skills/gsd-sketch/SKILL.md",
".agents/skills/gsd-spec-phase/SKILL.md",
".agents/skills/gsd-spike/SKILL.md",
".agents/skills/gsd-stats/SKILL.md",
".agents/skills/gsd-surface/SKILL.md",
".agents/skills/gsd-thread/SKILL.md",
".agents/skills/gsd-ui-phase/SKILL.md",
".agents/skills/gsd-ui-review/SKILL.md",
".agents/skills/gsd-ultraplan-phase/SKILL.md",
".agents/skills/gsd-undo/SKILL.md",
".agents/skills/gsd-update/SKILL.md",
".agents/skills/gsd-validate-phase/SKILL.md",
".agents/skills/gsd-verify-work/SKILL.md",
".agents/skills/gsd-workspace/SKILL.md",
".agents/skills/gsd-workstreams/SKILL.md",
".gsd-profile",
".gsd/defaults.json",
"agents/gsd-advisor-researcher.md",
"agents/gsd-advisor-researcher.toml",
"agents/gsd-ai-researcher.md",
"agents/gsd-ai-researcher.toml",
"agents/gsd-assumptions-analyzer.md",
"agents/gsd-assumptions-analyzer.toml",
"agents/gsd-code-fixer.md",
"agents/gsd-code-fixer.toml",
"agents/gsd-code-reviewer.md",
"agents/gsd-code-reviewer.toml",
"agents/gsd-codebase-mapper.md",
"agents/gsd-codebase-mapper.toml",
"agents/gsd-debug-session-manager.md",
"agents/gsd-debug-session-manager.toml",
"agents/gsd-debugger.md",
"agents/gsd-debugger.toml",
"agents/gsd-doc-classifier.md",
"agents/gsd-doc-classifier.toml",
"agents/gsd-doc-synthesizer.md",
"agents/gsd-doc-synthesizer.toml",
"agents/gsd-doc-verifier.md",
"agents/gsd-doc-verifier.toml",
"agents/gsd-doc-writer.md",
"agents/gsd-doc-writer.toml",
"agents/gsd-domain-researcher.md",
"agents/gsd-domain-researcher.toml",
"agents/gsd-eval-auditor.md",
"agents/gsd-eval-auditor.toml",
"agents/gsd-eval-planner.md",
"agents/gsd-eval-planner.toml",
"agents/gsd-executor.md",
"agents/gsd-executor.toml",
"agents/gsd-framework-selector.md",
"agents/gsd-framework-selector.toml",
"agents/gsd-integration-checker.md",
"agents/gsd-integration-checker.toml",
"agents/gsd-intel-updater.md",
"agents/gsd-intel-updater.toml",
"agents/gsd-mempalace-curator.md",
"agents/gsd-mempalace-curator.toml",
"agents/gsd-nyquist-auditor.md",
"agents/gsd-nyquist-auditor.toml",
"agents/gsd-pattern-mapper.md",
"agents/gsd-pattern-mapper.toml",
"agents/gsd-phase-researcher.md",
"agents/gsd-phase-researcher.toml",
"agents/gsd-plan-checker.md",
"agents/gsd-plan-checker.toml",
"agents/gsd-planner.md",
"agents/gsd-planner.toml",
"agents/gsd-project-researcher.md",
"agents/gsd-project-researcher.toml",
"agents/gsd-research-synthesizer.md",
"agents/gsd-research-synthesizer.toml",
"agents/gsd-roadmapper.md",
"agents/gsd-roadmapper.toml",
"agents/gsd-security-auditor.md",
"agents/gsd-security-auditor.toml",
"agents/gsd-ui-auditor.md",
"agents/gsd-ui-auditor.toml",
"agents/gsd-ui-checker.md",
"agents/gsd-ui-checker.toml",
"agents/gsd-ui-researcher.md",
"agents/gsd-ui-researcher.toml",
"agents/gsd-user-profiler.md",
"agents/gsd-user-profiler.toml",
"agents/gsd-verifier.md",
"agents/gsd-verifier.toml",
"config.toml",
"gsd-core/.gsd-runtime",
"gsd-core/VERSION",
"gsd-core/bin/check-latest-version.cjs",
"gsd-core/bin/ensure-runtime-build.cjs",
"gsd-core/bin/gsd-tools.cjs",
"gsd-core/bin/gsd_run",
"gsd-core/bin/shared/config-defaults.manifest.json",
"gsd-core/bin/shared/config-schema.manifest.json",
"gsd-core/bin/shared/model-catalog.json",
"gsd-core/bin/shared/runtime-aliases.manifest.json",
"gsd-core/bin/verify-reapply-patches.cjs",
"gsd-core/contexts/dev.md",
"gsd-core/contexts/research.md",
"gsd-core/contexts/review.md",
"gsd-core/references/agent-contracts.md",
"gsd-core/references/agent-skills-bootstrap.md",
"gsd-core/references/ai-evals.md",
"gsd-core/references/ai-frameworks.md",
"gsd-core/references/api-coverage.md",
"gsd-core/references/artifact-types.md",
"gsd-core/references/autonomous-smart-discuss.md",
"gsd-core/references/checkpoints.md",
"gsd-core/references/common-bug-patterns.md",
"gsd-core/references/context-budget.md",
"gsd-core/references/continuation-format.md",
"gsd-core/references/debugger-bug-taxonomy.md",
"gsd-core/references/debugger-fix-acceptance.md",
"gsd-core/references/debugger-philosophy.md",
"gsd-core/references/debugger-prevention.md",
"gsd-core/references/debugger-rca-branching.md",
"gsd-core/references/debugger-repro-hardening.md",
"gsd-core/references/debugger-sbfl.md",
"gsd-core/references/debugger-semantic-recall.md",
"gsd-core/references/decimal-phase-calculation.md",
"gsd-core/references/doc-conflict-engine.md",
"gsd-core/references/domain-probes.md",
"gsd-core/references/edge-probe-fixtures/01-round-half-even/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/01-round-half-even/requirements.json",
"gsd-core/references/edge-probe-fixtures/02-merge-intervals/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/02-merge-intervals/requirements.json",
"gsd-core/references/edge-probe-fixtures/03-truncate-graphemes/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/03-truncate-graphemes/requirements.json",
"gsd-core/references/edge-probe-fixtures/04-money-rounding/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/04-money-rounding/requirements.json",
"gsd-core/references/edge-probe-fixtures/05-list-dedupe/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/05-list-dedupe/requirements.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/expected-coverage.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/requirements.json",
"gsd-core/references/edge-probe-fixtures/06-resolved-mixed/resolutions.json",
"gsd-core/references/edge-probe.md",
"gsd-core/references/execute-mvp-tdd.md",
"gsd-core/references/execute-phase-between-wave-reset.md",
"gsd-core/references/execute-phase-context-guard.md",
"gsd-core/references/execute-phase-quota-recovery.md",
"gsd-core/references/execute-phase-requirement-revert.md",
"gsd-core/references/execute-phase-response-language.md",
"gsd-core/references/execute-phase-wave-guard.md",
"gsd-core/references/executor-examples.md",
"gsd-core/references/few-shot-examples/plan-checker.md",
"gsd-core/references/few-shot-examples/verifier.md",
"gsd-core/references/gate-prompts.md",
"gsd-core/references/gates.md",
"gsd-core/references/git-integration.md",
"gsd-core/references/git-planning-commit.md",
"gsd-core/references/gsd-run-resolver.md",
"gsd-core/references/honest-verifier.md",
"gsd-core/references/ios-scaffold.md",
"gsd-core/references/loop-hook-dispatch.md",
"gsd-core/references/mandatory-initial-read.md",
"gsd-core/references/model-profile-resolution.md",
"gsd-core/references/model-profiles.md",
"gsd-core/references/mvp-concepts.md",
"gsd-core/references/phase-argument-parsing.md",
"gsd-core/references/planner-antipatterns.md",
"gsd-core/references/planner-chunked.md",
"gsd-core/references/planner-gap-closure.md",
"gsd-core/references/planner-graphify-auto-update.md",
"gsd-core/references/planner-guidance.md",
"gsd-core/references/planner-human-verify-mode.md",
"gsd-core/references/planner-interface-context.md",
"gsd-core/references/planner-load-graph-context.md",
"gsd-core/references/planner-mvp-mode.md",
"gsd-core/references/planner-preconditions.md",
"gsd-core/references/planner-reversibility.md",
"gsd-core/references/planner-reviews.md",
"gsd-core/references/planner-revision.md",
"gsd-core/references/planner-source-audit.md",
"gsd-core/references/planning-config.md",
"gsd-core/references/prohibition-probe-fixtures/01-streak-reminder/expected.json",
"gsd-core/references/prohibition-probe-fixtures/02-clean-utility/expected.json",
"gsd-core/references/prohibition-probe-fixtures/03-multi-prohibition/expected.json",
"gsd-core/references/prohibition-probe.md",
"gsd-core/references/project-skills-discovery.md",
"gsd-core/references/questioning.md",
"gsd-core/references/research-documentation-lookup.md",
"gsd-core/references/research-philosophy.md",
"gsd-core/references/research-verification-protocol.md",
"gsd-core/references/reviewer-instances.md",
"gsd-core/references/revision-loop.md",
"gsd-core/references/scout-codebase.md",
"gsd-core/references/security-asvs-levels.md",
"gsd-core/references/skeleton-template.md",
"gsd-core/references/sketch-interactivity.md",
"gsd-core/references/sketch-theme-system.md",
"gsd-core/references/sketch-tooling.md",
"gsd-core/references/sketch-variant-patterns.md",
"gsd-core/references/specless-probe-fallback.md",
"gsd-core/references/spidr-splitting.md",
"gsd-core/references/tdd.md",
"gsd-core/references/thinking-models-debug.md",
"gsd-core/references/thinking-models-execution.md",
"gsd-core/references/thinking-models-planning.md",
"gsd-core/references/thinking-models-research.md",
"gsd-core/references/thinking-models-verification.md",
"gsd-core/references/thinking-partner.md",
"gsd-core/references/ui-brand.md",
"gsd-core/references/ui-consideration-probe.md",
"gsd-core/references/universal-anti-patterns.md",
"gsd-core/references/untrusted-input-boundary.md",
"gsd-core/references/user-profiling.md",
"gsd-core/references/user-story-template.md",
"gsd-core/references/verification-overrides.md",
"gsd-core/references/verification-patterns.md",
"gsd-core/references/verify-mvp-mode.md",
"gsd-core/references/workstream-flag.md",
"gsd-core/references/worktree-branch-check.md",
"gsd-core/references/worktree-path-safety.md",
"gsd-core/templates/AI-SPEC.md",
"gsd-core/templates/DEBUG.md",
"gsd-core/templates/README.md",
"gsd-core/templates/SECURITY.md",
"gsd-core/templates/UAT.md",
"gsd-core/templates/UI-SPEC.md",
"gsd-core/templates/VALIDATION.md",
"gsd-core/templates/claude-md.md",
"gsd-core/templates/codebase/architecture.md",
"gsd-core/templates/codebase/concerns.md",
"gsd-core/templates/codebase/conventions.md",
"gsd-core/templates/codebase/integrations.md",
"gsd-core/templates/codebase/stack.md",
"gsd-core/templates/codebase/structure.md",
"gsd-core/templates/codebase/testing.md",
"gsd-core/templates/config.json",
"gsd-core/templates/context.md",
"gsd-core/templates/continue-here.md",
"gsd-core/templates/copilot-instructions.md",
"gsd-core/templates/debug-subagent-prompt.md",
"gsd-core/templates/dev-preferences.md",
"gsd-core/templates/discovery.md",
"gsd-core/templates/discussion-log.md",
"gsd-core/templates/milestone-archive.md",
"gsd-core/templates/milestone.md",
"gsd-core/templates/phase-prompt.md",
"gsd-core/templates/planner-subagent-prompt.md",
"gsd-core/templates/project.md",
"gsd-core/templates/requirements.md",
"gsd-core/templates/research-project/ARCHITECTURE.md",
"gsd-core/templates/research-project/FEATURES.md",
"gsd-core/templates/research-project/PITFALLS.md",
"gsd-core/templates/research-project/STACK.md",
"gsd-core/templates/research-project/SUMMARY.md",
"gsd-core/templates/research.md",
"gsd-core/templates/retrospective.md",
"gsd-core/templates/roadmap.md",
"gsd-core/templates/spec.md",
"gsd-core/templates/state.md",
"gsd-core/templates/summary-complex.md",
"gsd-core/templates/summary-minimal.md",
"gsd-core/templates/summary-standard.md",
"gsd-core/templates/summary.md",
"gsd-core/templates/user-profile.md",
"gsd-core/templates/user-setup.md",
"gsd-core/templates/verification-report.md",
"gsd-core/workflows/_runtime-launcher.snippet.sh",
"gsd-core/workflows/add-backlog.md",
"gsd-core/workflows/add-phase.md",
"gsd-core/workflows/add-tests.md",
"gsd-core/workflows/add-todo.md",
"gsd-core/workflows/ai-integration-phase.md",
"gsd-core/workflows/analyze-dependencies.md",
"gsd-core/workflows/audit-fix.md",
"gsd-core/workflows/audit-milestone.md",
"gsd-core/workflows/audit-uat.md",
"gsd-core/workflows/autonomous.md",
"gsd-core/workflows/check-todos.md",
"gsd-core/workflows/cleanup.md",
"gsd-core/workflows/code-review-fix.md",
"gsd-core/workflows/code-review.md",
"gsd-core/workflows/complete-milestone.md",
"gsd-core/workflows/debug.md",
"gsd-core/workflows/diagnose-issues.md",
"gsd-core/workflows/discovery-phase.md",
"gsd-core/workflows/discuss-phase-assumptions.md",
"gsd-core/workflows/discuss-phase-power.md",
"gsd-core/workflows/discuss-phase.md",
"gsd-core/workflows/discuss-phase/modes/advisor.md",
"gsd-core/workflows/discuss-phase/modes/all.md",
"gsd-core/workflows/discuss-phase/modes/analyze.md",
"gsd-core/workflows/discuss-phase/modes/auto.md",
"gsd-core/workflows/discuss-phase/modes/batch.md",
"gsd-core/workflows/discuss-phase/modes/chain.md",
"gsd-core/workflows/discuss-phase/modes/default.md",
"gsd-core/workflows/discuss-phase/modes/power.md",
"gsd-core/workflows/discuss-phase/modes/text.md",
"gsd-core/workflows/discuss-phase/templates/checkpoint.json",
"gsd-core/workflows/discuss-phase/templates/context.md",
"gsd-core/workflows/discuss-phase/templates/discussion-log.md",
"gsd-core/workflows/do.md",
"gsd-core/workflows/docs-update.md",
"gsd-core/workflows/edit-phase.md",
"gsd-core/workflows/eval-review.md",
"gsd-core/workflows/execute-phase.md",
"gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md",
"gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md",
"gsd-core/workflows/execute-phase/steps/post-merge-gate.md",
"gsd-core/workflows/execute-phase/steps/regression-gate.md",
"gsd-core/workflows/execute-phase/steps/worktree-recovery-policy.md",
"gsd-core/workflows/execute-plan.md",
"gsd-core/workflows/explore.md",
"gsd-core/workflows/extract-learnings.md",
"gsd-core/workflows/fast.md",
"gsd-core/workflows/forensics.md",
"gsd-core/workflows/graduation.md",
"gsd-core/workflows/health.md",
"gsd-core/workflows/help.md",
"gsd-core/workflows/help/modes/brief.md",
"gsd-core/workflows/help/modes/default.md",
"gsd-core/workflows/help/modes/full.md",
"gsd-core/workflows/help/modes/topic.md",
"gsd-core/workflows/import.md",
"gsd-core/workflows/inbox.md",
"gsd-core/workflows/ingest-docs.md",
"gsd-core/workflows/insert-phase.md",
"gsd-core/workflows/list-phase-assumptions.md",
"gsd-core/workflows/list-seeds.md",
"gsd-core/workflows/list-workspaces.md",
"gsd-core/workflows/manager.md",
"gsd-core/workflows/map-codebase.md",
"gsd-core/workflows/milestone-summary.md",
"gsd-core/workflows/mvp-phase.md",
"gsd-core/workflows/new-milestone.md",
"gsd-core/workflows/new-project.md",
"gsd-core/workflows/new-workspace.md",
"gsd-core/workflows/next.md",
"gsd-core/workflows/node-repair.md",
"gsd-core/workflows/note.md",
"gsd-core/workflows/onboard.md",
"gsd-core/workflows/pause-work.md",
"gsd-core/workflows/plan-milestone-gaps.md",
"gsd-core/workflows/plan-phase.md",
"gsd-core/workflows/plan-phase/steps/closed-phase-gate.md",
"gsd-core/workflows/plan-phase/steps/prd-express-path.md",
"gsd-core/workflows/plan-phase/steps/windows-troubleshooting.md",
"gsd-core/workflows/plan-review-convergence.md",
"gsd-core/workflows/plant-seed.md",
"gsd-core/workflows/pr-branch.md",
"gsd-core/workflows/profile-user.md",
"gsd-core/workflows/progress.md",
"gsd-core/workflows/quick.md",
"gsd-core/workflows/reapply-patches.md",
"gsd-core/workflows/remove-phase.md",
"gsd-core/workflows/remove-workspace.md",
"gsd-core/workflows/resume-project.md",
"gsd-core/workflows/review.md",
"gsd-core/workflows/scan.md",
"gsd-core/workflows/secure-phase.md",
"gsd-core/workflows/session-report.md",
"gsd-core/workflows/settings-advanced.md",
"gsd-core/workflows/settings-integrations.md",
"gsd-core/workflows/settings.md",
"gsd-core/workflows/ship.md",
"gsd-core/workflows/sketch-wrap-up.md",
"gsd-core/workflows/sketch.md",
"gsd-core/workflows/smart-entry.md",
"gsd-core/workflows/spec-phase.md",
"gsd-core/workflows/spike-wrap-up.md",
"gsd-core/workflows/spike.md",
"gsd-core/workflows/stats.md",
"gsd-core/workflows/sync-skills.md",
"gsd-core/workflows/thread.md",
"gsd-core/workflows/transition.md",
"gsd-core/workflows/ui-phase.md",
"gsd-core/workflows/ui-review.md",
"gsd-core/workflows/ultraplan-phase.md",
"gsd-core/workflows/undo.md",
"gsd-core/workflows/update.md",
"gsd-core/workflows/validate-phase.md",
"gsd-core/workflows/verify-phase.md",
"gsd-core/workflows/verify-work.md",
"hooks/gsd-check-update.js",
"hooks/gsd-context-monitor.js",
"scripts/changeset/README.md",
"scripts/changeset/cli.cjs",
"scripts/changeset/github-release-notes.cjs",
"scripts/changeset/lint.cjs",
"scripts/changeset/new.cjs",
"scripts/changeset/parse.cjs",
"scripts/changeset/render.cjs",
"scripts/changeset/serialize.cjs",
"scripts/fix-slash-commands.cjs",
"scripts/gen-capability-registry.cjs",
"scripts/gen-loop-host-contract.cjs",
"scripts/lib/allowlist-ratchet.cjs",
"scripts/lib/cli-exit.cjs"
]