* test(3596): adversarial security/prompt-injection abuse suite
Adds `tests/security-prompt-injection.test.cjs` and a fixtures
directory at `tests/fixtures/adversarial/security/` covering the
attack classes enumerated in #3596:
- Command substitution / backticks / heredoc payloads in workstream
names — sentinel-file probes prove no shell is spawned, slugifier
neutralises the input.
- Path traversal through `--ws` and slash-bearing workstream names —
rejected with structured `--json-errors` payload, no stack trace,
no filesystem mutation outside the project root.
- Fake `<system>` / `[SYSTEM]` / `<<SYS>>` / `[INST]` boundary tags —
sanitizeForPrompt neutralises every form; structural negative
property locked across all six styles in one place.
- Zero-width / bidi-override codepoints — stripped per the documented
codepoint set; asserted via codePoint inspection, not regex
literals.
- Hostile read of CONTEXT.md / PLAN.md / ROADMAP.md fixtures —
`gsd-read-injection-scanner.js` surfaces the advisory; excluded
paths and non-Read tools stay silent; malformed JSON does not
crash the hook.
- Hostile write of `.planning/` files — `gsd-prompt-guard.js` emits
a `PreToolUse` advisory; non-Write/Edit tools stay silent.
- Fake `ghp_*` / `sk-*` env tokens — never echoed in CLI stdout or
stderr under hostile inputs; covered under
`// allow-test-rule: structural-regression-guard` because the only
way to assert byte-level absence is `.includes(token)` against the
captured streams.
- `validatePath`, `validateShellArg`, `validatePhaseNumber`,
`validateFieldName` — focused negative-input contract pins.
Pinned behavior gaps (documented, NOT fixed in this PR):
- `<instructions>` is intentionally whitelisted by both the scanner
and the sanitiser (GSD's own prompt scaffolding). Two REGRESSION
GUARD tests lock that contract.
- The current `scanForInjection` does NOT flag malicious markdown
links (javascript:/data:/embedded-credentials URLs). PINNED with
negative-proof so any future scope extension fails the assertion
and forces a deliberate update to the acceptance map.
- `prompt-builder.ts` does not yet wrap plan/context markdown in an
"untrusted data" envelope. That seam lives on the TS side and is
covered by `sdk/src/prompt-builder.test.ts`; out of scope for a
CJS test file. Mentioned in the file header.
Verification:
- `node --test tests/security-prompt-injection.test.cjs` → 73 tests
pass.
- `node scripts/lint-no-source-grep.cjs` → 0 violations across
546 test files (one `allow-test-rule: structural-regression-guard`
annotation on this file for the token-absence assertions).
- `node scripts/run-tests.cjs` → 9730 tests pass, 0 fail.
Refs #3596
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* fix(3596): allow adversarial fixtures in scan + harden graphify status parse
* fix(3596): skip adversarial security fixtures in secret scan
---------
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>