Files
msd-core/docs/INVENTORY.md
Behruz Nassre Esfahani d04e287fa9 fix(#2365): stop api-coverage detector false-positiving non-API phases (#2397)
* fix(#2365): stop the api-coverage detector false-positiving non-API phases

detectApiIntegration fired on any integration verb co-occurring anywhere on a
line with any API noun, treated / as a word boundary (so a first-party Next.js
src/app/api/... route path matched the noun "api"), and read any capitalized
word before API/SDK/REST/GraphQL as a service name behind a fixed stopword
denylist (so threat-model prose like "Resolver-only API" fired). Because the
verify:pre seal gate is BLOCKING, a phase touching no external API could not
reach UAT without fabricating a coverage matrix.

The compound rule now requires the verb and noun to share one clause (sentence
punctuation and table-cell walls end a clause) within a bounded word gap.
Non-prose spans are excluded before matching: fenced code (already), inline
code spans (new stripInlineCode in the markdown-sectionizer seam), and
path-shaped tokens. The <Service> API surface rule requires proper-noun
position — a clause-initial capitalized word is ordinary English and needs
dependency evidence (URL / package reference) on the same line — and rejects
compound modifiers ("Resolver-only", lowercase after the hyphen).

A phase that integrates no external API now has a first-class, reasoned way to
say so: a COVERAGE.md containing "No external API integration: <reason>"
satisfies the gate (declaration + rows is contradictory and blocks). The
true-positive path is pinned by regression tests: every default-vocabulary
positive still fires, including the widest word-gap pairing and the
surface-rule-only shape.

Fixes #2365

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(#2365): tighten api-coverage detector per Codex review (round 2)

Applies the Codex review findings on the initial #2365 fix:

- S-1: a COVERAGE.md "no external API integration" declaration is the human
  override for a fallible detector, so it must PASS even when detection still
  fires — but the contradiction is now SURFACED in the gate output (overridden
  signal count + terms) instead of passing silently.
- S-2: verb/noun pairing is now a term-group nearest-pair merge walk over
  precomputed word ordinals (computeWordStarts / minWordGap), not a match×match
  cross product — a hostile line repeating one pair thousands of times stays
  linear instead of going quadratic.
- FN-4: package-shaped inline-code spans (`stripe-sdk`, `@stripe/stripe-js`)
  are kept as noun/dependency evidence rather than being fully masked, so a
  genuine dependency reference inside code ticks still corroborates.
- C-1: the <Service> API surface rule now scans every candidate in every
  clause; a rejected first candidate no longer shadows a later genuine service.
- Cross-clause binding: a verb may bind a noun in the immediately following
  clause only when its own clause names a service object, within a tight gap —
  admits "Integrate Stripe, exposing its endpoints …" without re-admitting the
  unrelated-clauses false-positive class.
- Internal-descriptor negative evidence ("internal Payments API",
  "the internal endpoint") never pairs; URL/scheme matching generalized beyond
  http(s).

All 5 acceptance criteria still hold: the three reported false positives are
clean and "integrate the Stripe API" still fires. Built .cjs committed
alongside the .cts. tsc + eslint (incl. no-adhoc-markdown-parsing) +
lint:regression-names clean; affected suites 256/256 green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(#2365): retune api-coverage detector fail-closed per Codex review (round 3)

Codex's second-round review found the round-2 tightening had over-corrected into
FAIL-OPEN false negatives — realistic external-API prose that the BLOCKING seal
gate silently let through (the catastrophic class, since a missed API surface is
worse than a dismissable false positive). Retuned the detector to be explicitly
fail-closed: lean toward detecting, and let the one-line COVERAGE.md "no external
API integration" declaration dismiss the residual false positives.

Fail-open false negatives fixed (all now detect):
- F1 clause-initial `<Service> API` with a plain follower ("Stripe API for
  payment processing") — dropped the follower-allowlist / corroboration gate on
  clause-initial surfaces; a service that is not a stopword, descriptor, or
  compound modifier is a real name from any clause position.
- F2 scheme-less external host ("api.stripe.com/v1") — a dotted host with an
  alphabetic final label now contributes its API nouns; a first-party route
  path (no dotted host) still does not.
- F3 vendor's first-party SDK ("Integrate Shopify's first-party SDK") — the
  compound path no longer filters nouns on "internal"/"first-party" (Codex: the
  qualifier can describe the vendor's own API, not the consuming project's).
- F4 long single integration clause — removed the word-gap cap entirely: it
  could not separate a 21-word genuine clause from an 18-word internal one, so
  the clause boundary is now the whole relationship test.
- F5 lowercase cross-clause service — cross-clause binding no longer requires a
  capitalized "service object".

New false positives fixed (all now clean):
- F6 a URL token that swallowed a trailing clause comma, merging two clauses —
  trailing clause punctuation is kept literal so the split survives.
- F7 a capitalized internal component authorizing cross-clause binding — the new
  gate requires a dependent elaboration, not a new coordinate clause opened by a
  conjunction ("…, then document…").
- F8 a protocol name read as a service ("REST API", "GraphQL API") — protocol
  and locality descriptors are rejected in the `<Service>` position.

- Finding 9: the inline-code-span scanner was O(n^2) on pathological backtick
  runs; rewritten to linear via a per-length run cursor (2 MB: 4.15 s -> ~6 ms),
  semantics preserved (148 sectionizer tests unchanged).

Net simplification: the fail-closed model removed the round-2 minWordGap /
groupByTerm / follower / corroboration machinery (350 insertions vs 445
deletions across the touched files). Under fail-closed, three round-2 negative
tests now correctly detect (integration verb + "internal"-qualified noun, and
the distant-same-clause case); none were trek-e acceptance FPs.

Verified: 1491/1491 unit tests pass; tsc + eslint (incl. no-adhoc-markdown-
parsing) + lint:regression-names clean; all 8 review findings reproduced as
regression tests, both directions. Built .cjs committed alongside the .cts.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(#2365): resolve round-3 Codex review findings (fail-closed, round 4)

Codex's round-3 adversarial review found the fail-closed retune had introduced
new holes in both directions. Resolved:

Fail-open false negatives (now detect):
- External host addressing a PATH ("graph.microsoft.com/v1.0/me") is itself an
  integration surface and contributes an endpoint noun even when the host names
  no vocabulary word. A bare domain link with no path ("https://example.com")
  stays a non-signal, so "Integrate … from example.com, document …" is still
  clean.
- Locality qualification ("internal", "private") no longer leaks across a
  sentence or clause boundary: only plain spaces may separate the descriptor
  from the service, so "The cache is private. Stripe API …" now detects.
- Cross-clause binding: the fragile head-word cap (which could not tell a
  genuine "Connect … to Stripe payments, exposing its endpoints" from an
  unrelated "Integrate … from URL, document …" — both 4 words after the verb)
  is replaced by a participial-continuation rule: a verb binds a noun in the
  next clause only when that clause begins with an "-ing" elaboration. This
  fixes the 4-word-head false negative AND the false positive below at once.

False positives (now clean):
- Cross-clause no longer binds a finite continuation regardless of separator:
  "Wire the settings form. Document endpoint props." / "…; document …" /
  "…, document …" are separate actions, not elaborations.

Perf (quadratic → linear):
- The trailing-punctuation peel is a backward char scan instead of an
  unanchored `[…]+$` regex (16k chars: 156 ms → ~1 ms).
- SERVICE_SURFACE_API_RE bounds the service-name length {1,40} so a hostile
  "A-A-…-x" run cannot drive O(n^2) backtracking (16k: 385 ms → ~3 ms).

Consumer fail-open (blocking gate):
- readPhaseScope now distinguishes "no plans" from a plan that EXISTS but is
  unreadable. On a read error the gate BLOCKS ("could not read the phase
  scope …") instead of silently certifying no-integration from partial scope —
  an unreadable plan could be the one describing the integration.

Documented fail-closed tradeoffs, now pinned with tests so they are not
"fixed" back into a fail-open: a clause-initial capitalized common word before
"API" ("Payment API", "Search API") reads as a service name; a long clause
pairs a verb with a distant noun; and a CommonMark inline code span that wraps
a newline is matched within-line only. Codex judged these acceptable because
the COVERAGE.md declaration is a cheap override.

One documented limitation remains out of scope: "Integrate Stripe, and
authenticate requests with its API" (a coordinate finite clause whose noun
refers back by pronoun) needs coreference resolution, beyond a lexical detector.

Verified: 379/379 affected + command-router tests pass (+14 new regression
tests covering every round-3 finding, both directions); tsc + eslint
(no-adhoc-markdown-parsing) + lint:regression-names clean. Built .cjs committed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(#2365): simplify to robust core — remove whack-a-mole heuristics (round 5)

Round-4 review confirmed the detector's two most complex features generate
findings in both directions no matter how they are tuned, because they need a
vendor dictionary + coreference the issue rules out in principle. Per the
operator's "ship the robust core" decision, both are removed and their gaps are
documented rather than chased further:

- Cross-clause binding DELETED (allowsCrossClause / participle rule). It caused
  a fail-open on finite continuations ("Integrate Stripe; use its OAuth
  endpoints" — missed) and a false positive on "-ing"-SPELLED nouns ("…, billing
  endpoint terminology…" — wrongly fired). Detection is now same-clause only.
- URL-path-as-evidence REVERTED. Treating every path-bearing URL as an endpoint
  fired on ordinary asset/link URLs ("…/theme.css", "…?next=/x", a docs/repo
  link) and recreated routine UI-phase false positives. An external URL is
  evidence only when it NAMES an API vocabulary word ("api.stripe.com/v1").

Two fail-open cases are now DOCUMENTED limitations, pinned by tests so a future
maintainer does not re-add the heuristics that caused the false positives above:
a service named only in a clause separate from its API noun, and a bare external
host that names no vocabulary word. Both are cheaply covered by the COVERAGE.md
declaration and rare in real phase prose ("integrate the X API").

Also fixed from the round-4 review:
- Qualification now survives markdown emphasis ("The **internal** Payments API"
  stays clean) while still not crossing a sentence/clause boundary.
- readPhaseScope fail-closes on a REAL read failure (EACCES/EIO) enumerating the
  phase directory or reading the roadmap fallback — not only per-plan-file
  failures; a missing directory/section remains a legitimate no-op. The
  declaration-override path surfaces scope_read_error so an incomplete-scope
  override stays visible.
- SERVICE_SURFACE_API_RE length-bound comment no longer overclaims.

Net: the detector is same-clause verb+noun + `<Service> API` surface, with
path/code/inline masking and a fail-closed posture. All five acceptance criteria
hold. 1573/1573 unit tests pass; tsc + eslint (no-adhoc-markdown-parsing) +
lint:regression-names clean. Built .cjs committed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(#2365): close roadmap-fallback fail-open + stale JSDoc (round-5 review)

The round-5 sanity review confirmed the detector simplification is sound (all
acceptance positives fire, all required negatives clean) and flagged one real
blocker plus a nit:

- Blocker: readPhaseScope's roadmap fallback could still silently pass an
  UNREADABLE roadmap. getRoadmapPhaseWithFallback gated on fs.existsSync(), which
  returns false on EACCES/EIO too — so an unreadable ROADMAP.md read as "absent",
  no exception reached isRealReadFailure, and the blocking gate certified empty
  scope. Fixed at the source: read the roadmap directly and honor the function's
  OWN documented contract — null only on ENOENT (genuinely absent), otherwise
  throw. Both existing callers already wrap it in try/catch expecting that throw,
  and readPhaseScope now fail-closes (blocks) via its roadmap catch. Verified by
  a new e2e test (unreadable roadmap fallback → block).

- Nit: the detectApiIntegration JSDoc still described the removed cross-clause
  participial binding and "every external hostname counts" — corrected to the
  actual same-clause-only behavior and the names-a-vocab-word URL rule.

Verified: full unit suite green; tsc + eslint + lint:regression-names clean.
Built .cjs committed (roadmap.cjs is gitignored/rebuilt, per repo convention).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore(#2365): backfill changeset PR number (#2397)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* chore(#2365): sync generated capability-registry + recapture install goldens

CI surfaced two generated-artifact staleness issues (all failing test shards +
lint-tests traced to these, not to a logic defect):

- gsd-core/bin/lib/capability-registry.cjs was stale: the initial fix edited the
  ai-integration `api-coverage-plan-pre.md` fragment (added the "No external API
  integration" declaration section) but did not regenerate the registry, which
  embeds an inline copy of that fragment. Regenerated via
  `gen-capability-registry.cjs --write` — the diff is exactly the fragment text
  sync. Fixes `lint:generated-sync` and the "committed registry is in sync" +
  "registry integration" tests.

- The 18 golden-install-parity fixtures were stale by exactly one hash line each
  — `gsd-core/references/api-coverage.md`, which this PR edits and which is a
  hashed installed artifact. Recaptured with `UPDATE_GOLDEN=1`; the diff is that
  single hash per runtime and nothing else. Fixes the `golden parity — *` tests.

No source or behavior change — generated artifacts only.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(#2365): flip representative-corpus manifest to assert the fixed behavior

The #2371 representative corpus (merged into next after this branch was cut) is a
known-bug tripwire: it asserts each fixture's currentBuggyOutput so the test
fails loudly the moment #2365 is fixed, at which point — per its own contract in
representative-corpus.test.cjs — the fixer removes currentBuggyOutput so the
assertion checks expectedDetected instead.

This is that moment. Removed currentBuggyOutput from the three detector fixtures
(nextjs-route-path, unrelated-verb-noun, threat-model-prose); the corpus now
asserts detected:false, which the fail-closed same-clause detector satisfies.
Notes updated to describe the fix rather than the bug. The #2366 matrix corpus
is left untouched — that tripwire belongs to its own PR (#2374).

Corpus test: 7/7 pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(#2365): skip chmod-000 fail-closed e2e tests on Windows

The three fail-closed gate tests induce an unreadable plan / directory / roadmap
with chmod 000, but Windows does not enforce POSIX mode bits — readFileSync
still succeeds, so the gate never reaches the read-error path and the assertion
fails on the windows-latest CI leg. The fail-closed LOGIC is platform-
independent (readError → block) and is fully exercised on the macOS/Linux legs;
only the method of inducing EACCES is POSIX-specific. Guard the three tests to
skip on win32 as well as root, mirroring golden-install-parity's win32 skip.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(#2365): address trek-e review — glossary, clock-seam, IO injection, bounds

Review response to PR #2397 (trek-e, CHANGES_REQUESTED). Fix logic unchanged;
this closes the test/process-hygiene findings.

Major:
- CONTEXT.md "Markdown Sectionizer" glossary now lists the two exports this fix
  relies on, `stripInlineCode` and `scanInlineCodeSpans` (glossary is a PR gate).
- Replaced the banned wall-clock assertion in the "hostile repeated-term line"
  test (Clock Seams rule — no elapsed-time asserts) with a deterministic
  signal-count assertion, which also directly verifies the term-dedup that keeps
  pairing linear (one signal for a 10k-pair line, not thousands).
- Rewrote the three fail-closed read-failure tests: instead of chmod 0o000
  (a no-op under root / on Windows, the pattern the repo's IO-failure convention
  avoids) they now exercise the newly-exported `readPhaseScope` in-process and
  inject the failure by monkeypatching fs.readFileSync/readdirSync to throw,
  restoring in finally. Deterministic and platform-independent (no skip needed),
  and they add the ENOENT-is-absence case that the chmod tests couldn't express.

Minor:
- Added limit / limit+1 boundary tests for SERVICE_SURFACE_API_RE's {1,40}
  service-name bound, QUALIFIER_LOOKBACK's 24-char window, and REASON_MAX_LEN
  (200) on the declaration reason.
- Added a fast-check property that fuzzes the tokenizer / clause splitter /
  masking (scanLineTokens, splitClauses, collectTermMatches) with adversarial
  tokens (slashes, backticks, URLs, clause punctuation) and asserts the detector
  is total (never throws), shape-stable, holds detected <=> signals, and is
  deterministic.

readPhaseScope is exported for the in-process tests. Verified: 125 detector +
19 gate tests pass; tsc + eslint + generated-sync (glossary/registry) +
lint-regression-test-names + lint-test-file-count clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-19 14:59:25 -04:00

80 KiB
Raw Blame History

GSD Shipped Surface Inventory

Authoritative roster of every shipped GSD surface: commands, agents, workflows, references, CLI modules, and hooks. Where the broad docs (AGENTS.md, COMMANDS.md, ARCHITECTURE.md, CLI-TOOLS.md) diverge from the filesystem, treat this file and the repository tree itself as the source of truth.

How To Use This File

  • The machine-readable roster lives in docs/INVENTORY-MANIFEST.json (regenerated by scripts/gen-inventory-manifest.cjs --write). For live counts, run ls agents/gsd-*.md | wc -l etc. against the checkout.
  • This file enumerates every shipped surface across all six families (agents, commands, workflows, references, CLI modules, hooks). Broad docs may render narrative or curated subsets; when they disagree with the filesystem, this file and the directory listings are authoritative.
  • New surfaces should land here first, then propagate to the broad docs. The drift-control tests in tests/inventory-manifest-sync.test.cjs, tests/commands-doc-parity.test.cjs, tests/agents-doc-parity.test.cjs, tests/cli-modules-doc-parity.test.cjs, tests/hooks-doc-parity.test.cjs, and tests/command-count-sync.test.cjs anchor the roster contents against the filesystem.

This is the authoritative roster of every shipped GSD Core surface. See the docs index to navigate by topic.


Agents

Full roster at agents/gsd-*.md. The "Primary doc" column flags whether docs/AGENTS.md carries a full role card (primary), a short stub in the "Advanced and Specialized Agents" section (advanced stub), or no coverage (inventory only).

Agent Role (one line) Spawned by Primary doc
gsd-project-researcher Researches domain ecosystem before roadmap creation (stack, features, architecture, pitfalls). /gsd-new-project, /gsd-new-milestone primary
gsd-phase-researcher Researches implementation approach for a specific phase before planning. /gsd-plan-phase primary
gsd-ui-researcher Produces UI design contracts for frontend phases. /gsd-ui-phase primary
gsd-assumptions-analyzer Produces evidence-backed assumptions for discuss-phase (assumptions mode). discuss-phase-assumptions workflow primary
gsd-advisor-researcher Researches a single gray-area decision during discuss-phase advisor mode. discuss-phase workflow (advisor mode) primary
gsd-research-synthesizer Combines parallel researcher outputs into a unified SUMMARY.md. /gsd-new-project primary
gsd-planner Creates executable phase plans with task breakdown and goal-backward verification. /gsd-plan-phase, /gsd-quick primary
gsd-roadmapper Creates project roadmaps with phase breakdown and requirement mapping. /gsd-new-project primary
gsd-executor Executes GSD plans with atomic commits and deviation handling. /gsd-execute-phase, /gsd-quick primary
gsd-plan-checker Verifies plans will achieve phase goals (8 verification dimensions). /gsd-plan-phase (verification loop) primary
gsd-integration-checker Verifies cross-phase integration and end-to-end flows. /gsd-audit-milestone primary
gsd-ui-checker Validates UI-SPEC.md design contracts against quality dimensions. /gsd-ui-phase (validation loop) primary
gsd-verifier Verifies phase goal achievement through goal-backward analysis. /gsd-execute-phase primary
gsd-nyquist-auditor Fills Nyquist validation gaps by generating tests. /gsd-validate-phase primary
gsd-ui-auditor Retroactive 6-pillar visual audit of implemented frontend code. /gsd-ui-review primary
gsd-codebase-mapper Explores codebase and writes structured analysis documents. /gsd-map-codebase primary
gsd-debugger Investigates bugs using scientific method with persistent state. /gsd-debug, /gsd-verify-work primary
gsd-user-profiler Scores developer behavior across 8 dimensions. /gsd-profile-user primary
gsd-doc-writer Writes and updates project documentation. /gsd-docs-update primary
gsd-doc-verifier Verifies factual claims in generated documentation. /gsd-docs-update primary
gsd-security-auditor Verifies threat mitigations from PLAN.md threat model. /gsd-secure-phase primary
gsd-pattern-mapper Maps new files to closest existing analogs; writes PATTERNS.md for the planner. /gsd-plan-phase (between research and planning) advanced stub
gsd-debug-session-manager Runs the full /gsd-debug checkpoint-and-continuation loop in isolated context so main stays lean. /gsd-debug advanced stub
gsd-code-reviewer Reviews source files for bugs, security issues, and code-quality problems; produces REVIEW.md. /gsd-code-review advanced stub
gsd-code-fixer Applies fixes to REVIEW.md findings with atomic per-fix commits; produces REVIEW-FIX.md. /gsd-code-review --fix advanced stub
gsd-ai-researcher Researches a chosen AI framework's official docs into implementation-ready guidance (AI-SPEC.md §3–§4b). /gsd-ai-integration-phase advanced stub
gsd-domain-researcher Surfaces domain-expert evaluation criteria and failure modes for an AI system (AI-SPEC.md §1b). /gsd-ai-integration-phase advanced stub
gsd-eval-planner Designs structured evaluation strategy for an AI phase (AI-SPEC.md §5–§7). /gsd-ai-integration-phase advanced stub
gsd-eval-auditor Retroactive audit of an AI phase's evaluation coverage; produces EVAL-REVIEW.md (COVERED/PARTIAL/MISSING). /gsd-eval-review advanced stub
gsd-framework-selector ≤6-question interactive decision matrix that scores and recommends an AI/LLM framework. /gsd-ai-integration-phase advanced stub
gsd-intel-updater Writes structured intel files (.planning/intel/*.json) used as a queryable codebase knowledge base. /gsd-map-codebase --query advanced stub
gsd-doc-classifier Classifies a single planning document as ADR, PRD, SPEC, DOC, or UNKNOWN; spawned in parallel to process the doc corpus. /gsd-ingest-docs advanced stub
gsd-doc-synthesizer Synthesizes classified planning docs into a single consolidated context with precedence rules, cycle detection, and three-bucket conflicts report. /gsd-ingest-docs advanced stub
gsd-mempalace-curator Ship-time MemPalace curation — diary entry, cross-project tunnel proposals, wing-scoped sync pruning, and extract-learnings → KG mirroring with provenance. MemPalace capability at ship:post advanced stub

Coverage note. docs/AGENTS.md gives full role cards for the primary agents plus concise stubs for the advanced agents. The Agent Tool Permissions Summary in that file covers only the primary agents; the advanced agents' tool lists are captured in their per-agent frontmatter in agents/gsd-*.md.


Commands

Full roster at commands/gsd/*.md. The groupings below mirror docs/COMMANDS.md section order; each row carries the command name, a one-line role derived from the command's frontmatter description:, and a link to the source file. tests/command-count-sync.test.cjs locks the count against the filesystem.

Namespace Meta-Skills

These six routers are descriptor-only entries that the model picks first; the body of each contains a routing table that points at the correct concrete sub-skill. They exist to keep the eager skill-listing token cost low while the full surface remains reachable. See #2792 for the rationale; the routing tables target the post-#2790 consolidated surface.

Command Role Source
/gsd-workflow Phase pipeline router — discuss / plan / execute / verify / phase / progress / next. commands/gsd/ns-workflow.md
/gsd-project Project lifecycle router — milestones, audits, summary. commands/gsd/ns-project.md
/gsd-quality Quality-gate router — code review, debug, audit, security, eval, ui. commands/gsd/ns-review.md
/gsd-context Codebase-intelligence router — map, graphify, docs, learnings. commands/gsd/ns-context.md
/gsd-manage Management router — config, workspace, workstreams, thread, update, ship, inbox. commands/gsd/ns-manage.md
/gsd-ideate Exploration & capture router — explore, sketch, spike, spec, capture. commands/gsd/ns-ideate.md

Core Workflow

Command Role Source
/gsd-new-project Initialize a new project with deep context gathering and PROJECT.md. commands/gsd/new-project.md
/gsd-onboard Guide existing codebase onboarding through mapping, docs ingest, project setup, and onboarding summary. commands/gsd/onboard.md
/gsd-workspace Manage GSD workspaces — create (--new), list (--list), or remove (--remove) isolated workspace environments. commands/gsd/workspace.md
/gsd-discuss-phase Gather phase context through adaptive questioning before planning. commands/gsd/discuss-phase.md
/gsd-mvp-phase Plan a phase as a vertical MVP slice — user story, SPIDR splitting, then plan-phase. commands/gsd/mvp-phase.md
/gsd-spec-phase Socratic spec refinement producing a SPEC.md with falsifiable requirements. commands/gsd/spec-phase.md
/gsd-ui-phase Generate UI design contract (UI-SPEC.md) for frontend phases. commands/gsd/ui-phase.md
/gsd-ai-integration-phase Generate AI design contract (AI-SPEC.md) via framework selection, research, and eval planning. commands/gsd/ai-integration-phase.md
/gsd-plan-phase Create detailed phase plan (PLAN.md) with verification loop. commands/gsd/plan-phase.md
/gsd-plan-review-convergence Cross-AI plan convergence loop — replan with review feedback until no HIGH concerns or actionable non-HIGH findings remain (max 3 cycles). commands/gsd/plan-review-convergence.md
/gsd-ultraplan-phase [BETA] Offload plan phase to Claude Code's ultraplan cloud — drafts remotely, review in browser, import back via /gsd-import. Claude Code only. commands/gsd/ultraplan-phase.md
/gsd-spike Rapidly spike an idea with throwaway experiments; use --wrap-up to package findings as a persistent skill. commands/gsd/spike.md
/gsd-sketch Rapidly sketch UI/design ideas using throwaway HTML mockups; use --wrap-up to package findings. commands/gsd/sketch.md
/gsd-execute-phase Execute all plans in a phase with wave-based parallelization. commands/gsd/execute-phase.md
/gsd-verify-work Validate built features through conversational UAT with auto-diagnosis. commands/gsd/verify-work.md
/gsd-ship Create PR, run review, and prepare for merge after verification. commands/gsd/ship.md
/gsd-fast Execute a trivial task inline — no subagents, no planning overhead. commands/gsd/fast.md
/gsd-quick Execute a quick task with GSD guarantees (atomic commits, state tracking) but skip optional agents. commands/gsd/quick.md
/gsd-ui-review Retroactive 6-pillar visual audit of implemented frontend code. commands/gsd/ui-review.md
/gsd-code-review Review source files changed during a phase for bugs, security, and code-quality problems; use --fix to auto-apply findings. commands/gsd/code-review.md
/gsd-eval-review Retroactively audit an executed AI phase's evaluation coverage; produces EVAL-REVIEW.md. commands/gsd/eval-review.md

Phase & Milestone Management

Command Role Source
/gsd-phase CRUD for phases — add (default), insert (--insert), remove (--remove), or edit (--edit) phases in ROADMAP.md. commands/gsd/phase.md
/gsd-add-tests Generate tests for a completed phase based on UAT criteria and implementation. commands/gsd/add-tests.md
/gsd-validate-phase Retroactively audit and fill Nyquist validation gaps for a completed phase. commands/gsd/validate-phase.md
/gsd-secure-phase Retroactively verify threat mitigations for a completed phase. commands/gsd/secure-phase.md
/gsd-audit-milestone Audit milestone completion against original intent before archiving. commands/gsd/audit-milestone.md
/gsd-audit-uat Cross-phase audit of all outstanding UAT and verification items. commands/gsd/audit-uat.md
/gsd-audit-fix Autonomous audit-to-fix pipeline — find issues, classify, fix, test, commit. commands/gsd/audit-fix.md
/gsd-complete-milestone Archive completed milestone and prepare for next version. commands/gsd/complete-milestone.md
/gsd-new-milestone Start a new milestone cycle — update PROJECT.md and route to requirements. commands/gsd/new-milestone.md
/gsd-milestone-summary Generate a comprehensive project summary from milestone artifacts. commands/gsd/milestone-summary.md
/gsd-cleanup Archive accumulated phase directories from completed milestones. commands/gsd/cleanup.md
/gsd-manager Interactive command center for managing multiple phases from one terminal. commands/gsd/manager.md
/gsd-workstreams Manage parallel workstreams — list, create, switch, status, progress, complete, resume. commands/gsd/workstreams.md
/gsd-autonomous Run all remaining phases autonomously — discuss → plan → execute per phase. commands/gsd/autonomous.md
/gsd-undo Safe git revert — roll back phase or plan commits using the phase manifest. commands/gsd/undo.md

Session & Navigation

Command Role Source
/gsd:next State-aware smart-entry launcher — reads project state, shows a contextual menu, and dispatches one existing GSD command. commands/gsd/next.md
/gsd-progress Check project progress, show context, and route to next action; use --next to advance automatically or --do to run a freeform task. commands/gsd/progress.md
/gsd-capture Capture ideas, tasks, notes, and seeds — todo (default), --note, --backlog, --seed, or --list pending todos. commands/gsd/capture.md
/gsd-stats Display project statistics — phases, plans, requirements, git metrics, timeline. commands/gsd/stats.md
/gsd-pause-work Create context handoff when pausing work mid-phase. commands/gsd/pause-work.md
/gsd-resume-work Resume work from previous session with full context restoration. commands/gsd/resume-work.md
/gsd-explore Socratic ideation and idea routing — think through ideas before committing. commands/gsd/explore.md
/gsd-review-backlog Review and promote backlog items to active milestone. commands/gsd/review-backlog.md
/gsd-thread Manage persistent context threads for cross-session work. commands/gsd/thread.md

Codebase Intelligence

Command Role Source
/gsd-map-codebase Analyze codebase with parallel mapper agents; use --fast for lightweight scan or --query for intel queries. commands/gsd/map-codebase.md
/gsd-graphify Build, query, and inspect the project knowledge graph in .planning/graphs/. commands/gsd/graphify.md
/gsd-extract-learnings Extract decisions, lessons, patterns, and surprises from completed phase artifacts. commands/gsd/extract-learnings.md
/gsd-mempalace-recall Recall prior decisions, patterns, and surprises from MemPalace into MEMORY-RECALL.md before planning. commands/gsd/mempalace-recall.md
/gsd-mempalace-capture File a phase artifact (CONTEXT/PLAN/SUMMARY) verbatim into MemPalace and mirror decision facts into its temporal KG. commands/gsd/mempalace-capture.md

Review, Debug & Recovery

Command Role Source
/gsd-review Request cross-AI peer review of phase plans from external AI CLIs. commands/gsd/review.md
/gsd-debug Systematic debugging with persistent state across context resets. commands/gsd/debug.md
/gsd-forensics Post-mortem investigation for failed GSD workflows — analyzes git, artifacts, state. commands/gsd/forensics.md
/gsd-health Diagnose planning directory health and optionally repair issues. commands/gsd/health.md
/gsd-import Ingest external plans with conflict detection against project decisions. commands/gsd/import.md
/gsd-inbox Triage and review all open GitHub issues and PRs against project templates. commands/gsd/inbox.md

Docs, Profile & Utilities

Command Role Source
/gsd-docs-update Generate or update project documentation verified against the codebase. commands/gsd/docs-update.md
/gsd-ingest-docs Scan a repo for mixed ADRs/PRDs/SPECs/DOCs and bootstrap or merge the full .planning/ setup with classification, synthesis, and conflicts report. commands/gsd/ingest-docs.md
/gsd-profile-user Generate developer behavioral profile and Claude-discoverable artifacts. commands/gsd/profile-user.md
/gsd-settings Configure GSD workflow toggles and model profile. commands/gsd/settings.md
/gsd-config Configure GSD settings — workflow toggles (default), advanced knobs (--advanced), integrations (--integrations), or model profile (--profile). commands/gsd/config.md
/gsd-pr-branch Create a clean PR branch by filtering out .planning/ commits. commands/gsd/pr-branch.md
/gsd-surface Toggle which skills are surfaced — apply a profile, list, or disable a cluster without reinstall. commands/gsd/surface.md
/gsd-update Update GSD to latest version; use --sync to sync skills across runtimes or --reapply to reapply local patches. commands/gsd/update.md
/gsd-help Show available GSD commands and usage guide. commands/gsd/help.md

Workflows

Full roster at gsd-core/workflows/*.md. Workflows are thin orchestrators that commands reference internally; most are not read directly by end users. Rows below map each workflow file to its role (derived from the <purpose> block) and, where applicable, to the command that invokes it.

Workflow Role Invoked by
add-backlog.md Add a backlog item to ROADMAP.md using 999.x numbering. /gsd-capture --backlog
add-phase.md Add a new integer phase to the end of the current milestone in the roadmap. /gsd-phase (default)
add-tests.md Generate unit and E2E tests for a completed phase based on its artifacts. /gsd-add-tests
add-todo.md Capture an idea or task that surfaces during a session as a structured todo. /gsd-capture (default)
ai-integration-phase.md Orchestrate framework selection → AI research → domain research → eval planning into AI-SPEC.md. /gsd-ai-integration-phase
analyze-dependencies.md Analyze ROADMAP.md phases for file overlap and semantic dependencies; suggest Depends on edges. /gsd-manager --analyze-deps
audit-fix.md Autonomous audit-to-fix pipeline — run audit, parse, classify, fix, test, commit. /gsd-audit-fix
audit-milestone.md Verify milestone met its definition of done by aggregating phase verifications. /gsd-audit-milestone
audit-uat.md Cross-phase audit of UAT and verification files; produces prioritized outstanding-items list. /gsd-audit-uat
autonomous.md Drive milestone phases autonomously — all remaining, a range, or a single phase. /gsd-autonomous
check-todos.md List pending todos, allow selection, load context, and route to the appropriate action. /gsd-capture --list
cleanup.md Archive accumulated phase directories from completed milestones. /gsd-cleanup
code-review-fix.md Auto-fix issues from REVIEW.md via gsd-code-fixer with per-fix atomic commits. /gsd-code-review --fix
code-review.md Review phase source changes via gsd-code-reviewer; produces REVIEW.md. /gsd-code-review
complete-milestone.md Mark a shipped version as complete — MILESTONES.md entry, PROJECT.md evolution, tag. /gsd-complete-milestone
diagnose-issues.md Orchestrate parallel debug agents to investigate UAT gaps and find root causes. /gsd-verify-work (auto-diagnosis)
discovery-phase.md Execute discovery at the appropriate depth level. /gsd-new-project (discovery path)
discuss-phase-assumptions.md Assumptions-mode discuss — extract implementation decisions via codebase-first analysis. /gsd-discuss-phase (when discuss_mode=assumptions)
discuss-phase-power.md Power-user discuss — pre-generate all questions into a JSON state file + HTML UI. /gsd-discuss-phase --power
discuss-phase.md Extract implementation decisions through iterative gray-area discussion. /gsd-discuss-phase
mvp-phase.md Plan a phase as a vertical MVP slice — user story, SPIDR splitting, then plan-phase. /gsd-mvp-phase
do.md Route freeform text from the user to the best matching GSD command. /gsd-progress --do
docs-update.md Generate, update, and verify canonical and hand-written project documentation. /gsd-docs-update
edit-phase.md Edit any field of an existing phase in ROADMAP.md in place, preserving number and position. /gsd-phase --edit
eval-review.md Retroactive audit of an implemented AI phase's evaluation coverage. /gsd-eval-review
execute-phase.md Execute all plans in a phase using wave-based parallel execution. /gsd-execute-phase
execute-plan.md Execute a phase prompt (PLAN.md) and create the outcome summary (SUMMARY.md). execute-phase.md (per-plan subagent)
explore.md Socratic ideation — guide the developer through probing questions. /gsd-explore
debug.md Systematic debugging — subcommand routing, session creation, delegation to gsd-debug-session-manager. /gsd-debug
extract-learnings.md Extract decisions, lessons, patterns, and surprises from completed phase artifacts. /gsd-extract-learnings
fast.md Execute a trivial task inline without subagent overhead. /gsd-fast
forensics.md Forensics investigation of failed workflows — git, artifacts, and state analysis. /gsd-forensics
graduation.md Cluster recurring LEARNINGS.md items across phases and surface HITL promotion candidates. transition.md (graduation_scan step)
health.md Validate .planning/ directory integrity and report actionable issues. /gsd-health
help.md Display the complete GSD Core command reference. /gsd-help
import.md Ingest external plans with conflict detection against existing project decisions. /gsd-import
inbox.md Triage open GitHub issues and PRs against project contribution templates. /gsd-inbox
ingest-docs.md Scan a repo for mixed planning docs; classify, synthesize, and bootstrap or merge into .planning/ with a conflicts report. /gsd-ingest-docs
insert-phase.md Insert a decimal phase for urgent work discovered mid-milestone. /gsd-phase --insert
list-phase-assumptions.md Surface Claude's assumptions about a phase before planning. /gsd-discuss-phase --assumptions
list-seeds.md List and audit captured seeds (read-only), with optional status filter. /gsd-capture --list-seeds
list-workspaces.md List all GSD workspaces found in ~/gsd-workspaces/ with their status. /gsd-workspace --list
manager.md Interactive milestone command center — dashboard, inline discuss, background plan/execute. /gsd-manager
map-codebase.md Orchestrate parallel codebase mapper agents to produce .planning/codebase/ docs. /gsd-map-codebase
milestone-summary.md Milestone summary synthesis — onboarding and review artifact from milestone artifacts. /gsd-milestone-summary
new-milestone.md Start a new milestone cycle — load project context, gather goals, update PROJECT.md/STATE.md. /gsd-new-milestone
new-project.md Unified new-project flow — questioning, research (optional), requirements, roadmap. /gsd-new-project
onboard.md Brownfield onboarding orchestration — map codebase, ingest docs, initialize planning, summarize next step. /gsd-onboard
new-workspace.md Create an isolated workspace with repo worktrees/clones and an independent .planning/. /gsd-workspace --new
next.md Detect current project state and automatically advance to the next logical step. /gsd-progress --next
node-repair.md Autonomous repair operator for failed task verification; invoked by execute-plan. execute-plan.md (recovery)
note.md Zero-friction idea capture — one Write call, one confirmation line. /gsd-capture --note
pause-work.md Create structured .planning/HANDOFF.json and .continue-here.md handoff files. /gsd-pause-work
plan-phase.md Create executable PLAN.md files with integrated research and verification loop. /gsd-plan-phase, /gsd-quick
plan-review-convergence.md Cross-AI plan convergence loop — replan with review feedback until no HIGH concerns or actionable non-HIGH findings remain. /gsd-plan-review-convergence
plant-seed.md Capture a forward-looking idea as a structured seed file with trigger conditions. /gsd-capture --seed
pr-branch.md Create a clean branch for pull requests by filtering .planning/ commits. /gsd-pr-branch
profile-user.md Orchestrate the full developer profiling flow — consent, session scan, profile generation. /gsd-profile-user
progress.md Progress rendering — project context, position, and next-action routing. /gsd-progress
quick.md Quick-task execution with GSD guarantees (atomic commits, state tracking). /gsd-quick
reapply-patches.md Reapply local modifications after a GSD update. /gsd-update --reapply
remove-phase.md Remove a future phase from the roadmap and renumber subsequent phases. /gsd-phase --remove
remove-workspace.md Remove a GSD workspace and clean up worktrees. /gsd-workspace --remove
resume-project.md Resume work — restore full context from STATE.md, HANDOFF.json, and artifacts. /gsd-resume-work
review.md Cross-AI plan review via external CLIs; produces REVIEWS.md. /gsd-review
scan.md Rapid single-focus codebase scan — lightweight alternative to map-codebase. /gsd-map-codebase --fast
secure-phase.md Retroactive threat-mitigation audit for a completed phase. /gsd-secure-phase
session-report.md Session report — token usage, work summary, outcomes. /gsd-pause-work --report
settings.md Configure GSD workflow toggles and model profile. /gsd-settings, /gsd-config --profile
settings-advanced.md Configure GSD power-user knobs — plan bounce, timeouts, branch templates, cross-AI execution, runtime knobs. /gsd-config --advanced
settings-integrations.md Configure third-party API keys (Brave/Firecrawl/Exa), review.models.<cli> CLI routing, and agent_skills.<agent-type> injection with masked (****<last-4>) display. /gsd-config --integrations
ship.md Create PR, run review, and prepare for merge after verification. /gsd-ship
sketch.md Explore design directions through throwaway HTML mockups with 2-3 variants per sketch. /gsd-sketch
sketch-wrap-up.md Curate sketch findings and package them as a persistent sketch-findings-[project] skill. /gsd-sketch --wrap-up
spec-phase.md Socratic spec refinement with ambiguity scoring; produces SPEC.md. /gsd-spec-phase
spike.md Rapid feasibility validation through focused, throwaway experiments. /gsd-spike
spike-wrap-up.md Curate spike findings and package them as a persistent spike-findings-[project] skill. /gsd-spike --wrap-up
stats.md Project statistics rendering — phases, plans, requirements, git metrics. /gsd-stats
sync-skills.md Cross-runtime GSD skill sync — diff and apply gsd-* skill directories across runtime roots. /gsd-update --sync
transition.md Phase-boundary transition workflow — workstream checks, state advancement. execute-phase.md, /gsd-progress --next
ui-phase.md Generate UI-SPEC.md design contract via gsd-ui-researcher. /gsd-ui-phase
ui-review.md Retroactive 6-pillar visual audit via gsd-ui-auditor. /gsd-ui-review
ultraplan-phase.md [BETA] Offload planning to Claude Code's ultraplan cloud; drafts remotely and imports back via /gsd-import. /gsd-ultraplan-phase
undo.md Safe git revert — phase or plan commits using the phase manifest. /gsd-undo
thread.md Create, list, close, or resume persistent context threads for cross-session work. /gsd-thread
update.md Update GSD to latest version with changelog display. /gsd-update
validate-phase.md Retroactively audit and fill Nyquist validation gaps for a completed phase. /gsd-validate-phase
verify-phase.md Verify phase goal achievement through goal-backward analysis. execute-phase.md (post-execution)
verify-work.md Conversational UAT with auto-diagnosis — produces UAT.md and fix plans. /gsd-verify-work

Note: Some workflows have no direct user-facing command (e.g. execute-plan.md, verify-phase.md, transition.md, node-repair.md, diagnose-issues.md) — they are invoked internally by orchestrator workflows. discovery-phase.md is an alternate entry for /gsd-new-project.


References

Full roster at gsd-core/references/*.md. References are shared knowledge documents that workflows and agents @-reference. The groupings below match docs/ARCHITECTURE.md — core, workflow, thinking-model clusters, and the modular planner decomposition.

Core References

Reference Role
checkpoints.md Checkpoint type definitions and interaction patterns.
gates.md 4 canonical gate types (Confirm, Quality, Safety, Transition) wired into plan-checker and verifier.
model-profiles.md Per-agent model tier assignments.
model-profile-resolution.md Model resolution algorithm documentation.
verification-patterns.md How to verify different artifact types.
verification-overrides.md Per-artifact verification override rules.
planning-config.md Full config schema and behavior.
security-asvs-levels.md OWASP ASVS level definitions for GSD threat modeling — per-level planner disposition rigor and auditor verification depth (L1 opportunistic, L2 standard, L3 comprehensive).
git-integration.md Git commit, branching, and history patterns.
git-planning-commit.md Planning directory commit conventions.
questioning.md Dream-extraction philosophy for project initialization.
tdd.md Test-driven development integration patterns.
ui-brand.md Visual output formatting patterns.
common-bug-patterns.md Common bug patterns for code review and verification.
debugger-philosophy.md Evergreen debugging disciplines loaded by gsd-debugger.
debugger-fix-acceptance.md Multi-signal fix-acceptance guardrail (anti-overfitting) loaded by gsd-debugger.
debugger-sbfl.md Spectrum-based fault localization (Ochiai) pre-filter loaded by gsd-debugger.
debugger-rca-branching.md RCA branching (fishbone + AND-gate) anti-single-cause discipline loaded by gsd-debugger.
debugger-bug-taxonomy.md Bug-taxonomy classification (Bohrbug/Heisenbug/Concurrency) + technique routing table loaded by gsd-debugger.
debugger-repro-hardening.md Regression-test hardening (PBT shrinking + oracle classification + boundary neighbors) loaded by gsd-debugger.
debugger-prevention.md Prevention / blameless-postmortem output (5-Whys + why-not-caught + recurrence guard) loaded by gsd-debugger.
debugger-semantic-recall.md Semantic knowledge-base recall via MemPalace (keyword-fallback) loaded by gsd-debugger.
mandatory-initial-read.md Shared required-reading boilerplate injected into agent prompts.
agent-skills-bootstrap.md Shared agent_skills self-load contract (query + Read + dedup guard) injected into all 22 consumer agents.
project-skills-discovery.md Shared project-skills-discovery boilerplate injected into agent prompts.
research-documentation-lookup.md Shared documentation-lookup protocol (Context7 MCP + guarded CLI fallback) injected into all researcher agents.
research-philosophy.md Shared research philosophy (training-as-hypothesis, honest reporting, investigation-not-confirmation) injected into researcher agents.
research-verification-protocol.md Shared research verification protocol (4 pitfalls + pre-submission checklist) injected into researcher agents.

Workflow References

Reference Role
agent-contracts.md Formal interface between orchestrators and agents.
context-budget.md Context window budget allocation rules.
execute-phase-context-guard.md Context exhaustion guard step for execute-phase wave loop — workflow.context_guard_mode dispatch table (warn/auto/off) and POOR-tier pause-work trigger (#1452).
execute-phase-requirement-revert.md Gap-report step for execute-phase — reverts this phase's own shared requirement IDs out of Complete in REQUIREMENTS.md before rendering a gaps_found report, scoped to PHASE_REQ_IDS so other phases' rows are untouched (#2388).
continuation-format.md Session continuation/resume format.
domain-probes.md Domain-specific probing questions for discuss-phase.
edge-probe.md Spec-phase edge-completeness probe — 8-category edge taxonomy, shape classification, and the requirements → checks → verifier resolution model (Step 5.5).
prohibition-probe.md Spec-phase prohibition-completeness probe — the two-stage adversarial-recall → precision protocol that surfaces the unwritten must-NOT constraints (values/safety/ethics), with status×verification (test/judgment) tiering and canon-referral breadcrumbs (Step 5.6); second adapter of the probe-core resolution model.
ui-consideration-probe.md UI-phase state-completeness probe — the closed shape-rooted UI-state taxonomy (empty/loading/error/populated/partial/overflow/zero-one-many/long-text), element-cue relevance filter, and {explicit, backstop} tiering; third adapter of the probe-core model (ADR-550 D7), run at ui-phase Step 9.5; the MIXED axis routes open UX (real-time/a11y/i18n-RTL) to domain-probes.md (#1867).
honest-verifier.md Verify-time abstention on non-inferable (backstop) truths — the truth-axis mirror of the prohibition judgment-tier disposition (ADR-550 D4): a backstop truth the verifier can't confirm with explicit evidence abstains → human_needed (reason insufficient_spec), never a silent pass (#1154).
gate-prompts.md Gate/checkpoint prompt templates.
loop-hook-dispatch.md Generic dispatch contract for consuming gsd_run loop render-hooks <point> --raw output in any host-loop workflow — envelope shape, per-kind dispatch rules (contribution/step/gate), and liveness banner.
scout-codebase.md Phase-type→codebase-map selection table for discuss-phase scout step (extracted via the discuss-phase/modes progressive-disclosure split, #717).
revision-loop.md Plan revision iteration patterns.
reviewer-instances.md Custom reviewer instances for /gsd-review (#1517) — same-adapter multi-model review: config shape, resolution rules, invocation, and the REVIEWS.md contract. Lazily loaded by review.md when review.reviewer_instances is configured.
universal-anti-patterns.md Universal anti-patterns to detect and avoid.
worktree-branch-check.md Canonical spawn-time worktree HEAD/base guard (worktree_branch_check): verify-only and fail-closed — per-agent-branch assertion, protected-ref refusal (#2924), and an exact-base assertion that halts with exit 42 on mismatch so the orchestrator (worktree lifecycle owner) performs recovery (#48). Embedded into worktree sub-agent prompts at dispatch.
worktree-path-safety.md Worktree guard suite: HEAD assertion, cwd-drift sentinel (step 0a, #3097), and absolute-path guard (step 0b, #3099) — loaded into executor spawn prompts via <execution_context>.
untrusted-input-boundary.md Shared prompt-injection boundary (#1577) @-included by the 10 research/doc-ingest agents (gsd-project-researcher, gsd-phase-researcher, gsd-ui-researcher, gsd-assumptions-analyzer, gsd-advisor-researcher, gsd-doc-classifier, gsd-doc-synthesizer, gsd-research-synthesizer, gsd-ai-researcher, gsd-domain-researcher): treat fetched/read text as data-not-instructions, self-scan before use (PromptArmor 2507.15219), task-anchor (2504.20472), and fence quoted text with a fresh random delimiter per wrap (PPA 2506.05739). Prompt-level defense-in-depth (2503.00061); the hook scanner is a separate pattern pre-filter.
artifact-types.md Planning artifact type definitions.
phase-argument-parsing.md Phase argument parsing conventions.
decimal-phase-calculation.md Decimal sub-phase numbering rules.
workstream-flag.md Workstream active-pointer conventions (--ws).
user-profiling.md User behavioral profiling detection heuristics.
thinking-partner.md Conditional thinking-partner activation at decision points.
autonomous-smart-discuss.md Smart-discuss logic for autonomous mode.
ios-scaffold.md iOS application scaffolding patterns.
ai-evals.md AI evaluation design reference for /gsd-ai-integration-phase.
api-coverage.md API-coverage gate reference (full-coverage-by-default) for the ai-integration capability's verify:pre blocking gate (#1562) — matrix format, trigger, tuning, detector CLI.
ai-frameworks.md AI framework decision-matrix reference for gsd-framework-selector.
executor-examples.md Worked examples for the gsd-executor agent.
doc-conflict-engine.md Shared conflict-detection contract for ingest/import workflows.
execute-mvp-tdd.md Runtime gate semantics for execute-phase under MVP+TDD — pre-task failing-test verification, end-of-phase blocking review.
mvp-concepts.md Cross-reference index for the six MVP-related reference files; maps each file to its purpose and which workflow loads it.
verify-mvp-mode.md UAT framing rules for MVP-mode phases — user-flow-first ordering, deferred technical checks, user-story-format guard.

Sketch References

References consumed by the /gsd-sketch workflow and its wrap-up companion.

Reference Role
sketch-interactivity.md Rules for making HTML sketches feel interactive and alive.
sketch-theme-system.md Shared CSS theme variable system for cross-sketch consistency.
sketch-tooling.md Floating toolbar utilities included in every sketch.
sketch-variant-patterns.md Multi-variant HTML patterns (tabs, side-by-side, overlays).

Thinking-Model References

References for integrating thinking-class models (o3, o4-mini, Gemini 2.5 Pro) into GSD workflows.

Reference Role
thinking-models-debug.md Thinking-model patterns for debug workflows.
thinking-models-execution.md Thinking-model patterns for execution agents.
thinking-models-planning.md Thinking-model patterns for planning agents.
thinking-models-research.md Thinking-model patterns for research agents.
thinking-models-verification.md Thinking-model patterns for verification agents.

Modular Planner Decomposition

The gsd-planner agent is decomposed into a core agent plus reference modules to fit runtime character limits.

Reference Role
planner-antipatterns.md Planner anti-patterns and specificity examples.
planner-chunked.md Chunked mode return formats (## OUTLINE COMPLETE, ## PLAN COMPLETE) for Windows stdio hang mitigation.
planner-gap-closure.md Gap-closure mode behavior (reads VERIFICATION.md, targeted replanning).
planner-guidance.md Expository planner guidance: philosophy, task types/sizing, interface-first ordering, user setup, dependency graph, granularity calibration, and structured-return templates.
planner-reviews.md Cross-AI review integration (reads REVIEWS.md from /gsd-review).
planner-revision.md Plan revision patterns for iterative refinement.
planner-source-audit.md Planner source-audit and authority-limit rules.
planner-mvp-mode.md Vertical-slice planning rules for MVP mode.
planner-preconditions.md Emission rules for the optional <precondition> task element (issue #1949, Design by Contract): when to emit, the three cases (user_setup / prior-phase artifact / env-var), format, anti-patterns, and the contract triad mapping.
planner-human-verify-mode.md Rules for workflow.human_verify_mode = end-of-phase: suppress checkpoint:human-verify task emission and route deferred items via <verify><human-check>.
planner-graphify-auto-update.md How load_graph_context surfaces .last-build-status.json auto-update state (running / failed / stale head) alongside the existing staleness annotation. Opt-in via graphify.auto_update (#3347).
planner-interface-context.md Interface context rules for executors — how to extract key interfaces/types/exports from existing code and document new interfaces that downstream plans will consume.
planner-load-graph-context.md Planner's load_graph_context step: knowledge-graph freshness + dependency-context query via the gsd_run launcher (extracted from gsd-planner.md).
skeleton-template.md SKELETON.md template emitted for new-project Walking Skeleton (Phase 1 + --mvp).
user-story-template.md User story format for MVP planning — "As a / I want to / So that" structured fields.
specless-probe-fallback.md Spec-less probe fallback protocol — gate (toggle + per-section absence via the shared spec-section helper), the deterministic edge probe (mirrors spec-phase 5.5), the in-planner prohibition recall, and the must_haves authoring lift; consumed by plan-phase step 7.95 when a phase SPEC omits ## Edge Coverage / ## Prohibitions (ADR-857 Phase 6).
spidr-splitting.md SPIDR splitting decomposition rules for handling large user stories in MVP mode.

Subdirectory: gsd-core/references/few-shot-examples/ contains additional few-shot examples (plan-checker.md, verifier.md) that are referenced from specific agents. These are not among the top-level references.


CLI Modules

Full listing: gsd-core/bin/lib/*.cjs.

Module Responsibility
active-workstream-store.cjs Workstream source precedence and selection (CLI --ws > GSD_WORKSTREAM env > stored pointer); name validation and environment propagation
adr-parser.cjs ADR decision parser for plan-phase ingest express path; normalizes section synonyms, parses status/decision/scope fences, and enforces status rejection gates
agent-command-router.cjs Thin CJS subcommand router adapter for gsd-tools agent
api-coverage.cjs API-coverage detector + matrix validator (#1562, #2365) — pure detectApiIntegration (fail-closed: same-clause verb+noun signal + <Service> API/SDK surface naming a real service; strips fenced code, inline code, and path-shaped tokens; external hosts count, first-party route paths do not) and validateCoverageMatrix/parseCoverageMatrix/renderCoverageMatrix for the COVERAGE.md artifact (incl. the No external API integration: <reason> declaration); STDIN CLI (echo "$SCOPE" | node .../api-coverage.cjs [--json], exit 0=detected/1=none/2=error); consumed by the ai-integration capability's plan:pre contribution and blocking verify:pre gate (check api-coverage.verify-pre)
artifacts.cjs Canonical artifact registry — known .planning/ root file names; used by gsd-health W019 lint
audit-command-router.cjs ADR-959 capability command router for gsd-tools audit-uat and gsd-tools audit-open — extracted from hardcoded cases in gsd-tools.cjs; dispatches to uat.cjs:cmdAuditUat and audit.cjs:{auditOpenArtifacts,formatAuditReport}; phase 4d-impl-3
audit.cjs Audit dispatch, audit open sessions, audit storage helpers
capability-activation.cjs Capability activation resolver shared by config validation and capability-state consumers — resolves registry-owned config keys from raw runtime config without re-centralizing migrated settings
capability-command-router.cjs ADR-2346 P2 host command router for gsd-tools capability — relocated verbatim from the former 706-line case 'capability': arm in gsd-tools.cjs; dispatched via HOST_COMMAND_ROUTERS in runCommand's default case; wires capability-lifecycle/-trust/-consent/-state/-writer; hand-authored CJS (sibling of ensure-runtime-build.cjs)
capability-consent.cjs User-owned capability consent store (#1459) — bounded, non-throwing JSON store at ${GSD_HOME||homedir()}/.gsd/consent.json (NEVER under a repo) keyed by ${realpath(projectRoot)} <id>; exports consentStorePath/readConsentStore/hasProjectConsent (matches iff integrity AND disclosureSignature both match)/recordProjectConsent (atomic+durable write)/revokeProjectConsent; the authoritative consent signal that gates PROJECT-scope third-party capability activation so a forged/cloned project ledger no longer activates anything until the user consents on THIS machine
capability-lock.cjs Shared cross-process lock primitive (#1459 finding 4) — the SINGLE hardened lockfile protocol used by BOTH capability-lifecycle (.gsd/capabilities/.lock) and capability-consent (.consent.lock); exports acquireLock(lockPath, opts?)/releaseLock(handle) with pid + process-start-time liveness identity, a hard deadman, and token+inode owner-safe release — NEVER stale-steals a verified-live same-host holder, reclaims only a provably-dead/unverifiable holder, never deadlocks; opts.maxAttempts/opts.waitForFresh let the consent store serialize genuinely-contended writers; _setLockProbes/_resetLockProbes are test seams
capability-ledger.cjs Per-runtime install ledger (ADR-1244 D4) — atomic read/write of .gsd-capabilities.json recording { id, version, source, integrity, files[], sharedEdits[] } per installed capability; exports readLedger/writeLedger/recordInstall/removeEntry/reconcile (orphan detection)/readSmallRegularFile (utf8) + readSmallRegularFileBuffer (raw bytes, the byte-exact consent-hash reader, #1459 finding 1); atomic commit point and reconciliation basis for Phase-4 upgrade/remove
capability-lifecycle.cjs Capability lifecycle orchestration (ADR-1244 Phase 4, D5+D6) — composes the source resolver + ledger + trust gate into installCapability/upgradeCapability/removeCapability/reconcileCapabilities; ledger write is the commit point; upgrade is atomic stage-then-swap (old set aside, new swapped in, ledger committed, backup dropped) with deterministic crash recovery (reconcileCapabilities rolls forward/back to a fully-old-or-fully-new state); remove surgically strips only marker-stamped (_gsdCapability) shared-config entries, preserving user hand-edits; never executes capability code
capability-loader.cjs Runtime Capability Registry overlay (ADR-1244 D2) — loadRegistry({ includeInstalled }) composes the frozen first-party registry with a validated installed overlay read from $GSD_HOME/.gsd/capabilities/<id>/ (global) and <projectRoot>/.gsd/capabilities/<id>/ (project); first-party-wins on id/skill/agent/config collisions, reserved-namespace rejection, load-time engines.gsd re-gate (skip-with-warning), and gate-kind fail-open via _overlay.blockedGates — a loud warning (stderr + envelope warnings) naming the load failure and gsd capability remove <id> remediation; no gate injected (#2009); composes through the canonical buildRegistry so derived views never drift
capability-registry.cjs Generated central Capability Registry — role-partitioned index of all co-located capability declarations (capabilities/<id>/capability.json); emitted by scripts/gen-capability-registry.cjs --write (ADR-894 §5)
capability-source.cjs Capability source resolver (ADR-1244 D3) — resolveCapabilitySource(spec, opts) fetches and stages a capability from local path, git (https/ssh/git transports only), npm pack (no lifecycle scripts), tarball (sha512 integrity verify before extraction), or registry (stub); tar-slip/symlink rejection; atomic staging to $GSD_HOME/.gsd/capabilities/<id>/; no capability code executes during install
capability-state.cjs Unified capability-state resolver (ADR-857 phase 4b/6) — composes install profile, runtime surface, and config activation into one per-capability view consumed by workflow hook rendering; exports pure resolveCapabilityState, reusable resolveCapabilityRuntimeState, and I/O handler cmdCapabilityState; command surface: gsd-tools capability state [--config-dir <path>] emitting { runtimeConfigDir, capabilities[] }
capability-trust.cjs Capability trust gate (ADR-1244 Phase 4, D5 + compatibility half of D6) — PURE policy module: discloseExecutableSurfaces (hooks/command modules/mcpServers), evaluateInstallTrust (compose source policy + reserved-namespace + engines gate + disclosure → allowed/requiresConsent/blockReasons), evaluateSourceAllowed (strict_known_registries: permissive/lockdown/host-allowlist), checkEngines (engines.gsd hard gate + compatVersions graceful-downgrade), executableSetChanged (auto-update re-consent trigger); no sandbox — see docs/explanation/capability-trust-model.md
capability-validator.cjs Shared runtime-callable capability validator (ADR-1244 D2) — extracted from scripts/gen-capability-registry.cjs so the build-time generator and the runtime overlay loader share ONE validation implementation (generative-parity guarded); exports validateCapability/validateCrossCapability/validateVersionEnvelope/validateConsumesGlobal/… plus the closed-vocabulary sets and SEMVER_RE
capability-writer.cjs Capability State Writer (ADR-1213) — write-side inverse of the resolver; projects desired per-capability enabled/gates onto surface + config substrates, then re-resolves (assert-and-report); exports setCapabilityState and I/O handler cmdCapabilitySet; command surface: gsd-tools capability set <id> [--on|--off] [--gate <key>=<true|false>]
check-command-router.cjs Thin CJS subcommand router adapter for gsd-tools check
cli-exit.cjs ExitError class and runMain() helper — CLI entrypoints throw ExitError instead of calling process.exit(); runMain() translates the outcome into process.exitCode so output flushes cleanly
cjs-command-router-adapter.cjs Shared compatibility adapter for manifest-backed CJS command-family routers
clock.cjs Injectable clock seam (now/sleep) for deterministic lock testing
clusters.cjs Skill cluster definitions for the runtime surface module (ADR-0011 Phase 2)
code-review-flags.cjs Typed flag parser for /gsd:code-review; exports parseCodeReviewFlags(argv) (→ { fix, all, auto, depth, files }) and resolveCodeReviewWorkflow(flags) (→ 'code-review.md' | 'code-review-fix.md'); canonical dispatch seam for --fix/--all/--auto routing
command-aliases.cjs Alias/subcommand metadata for manifest-backed family routers
command-arg-projection.cjs Typed flag and positional argument projection helpers shared across command-family routers
command-roster.cjs Read-only discovery of canonical commands/gsd/*.md command stems for runtime artifact conversion and namespace rewrites
command-routing-hub.cjs Pure-result dispatch hub that centralizes mode decision (SDK vs CJS), error taxonomy, and no-throw contract for all command-family routers (#3788)
commands.cjs Misc CLI commands (slug, timestamp, todos, scaffolding, stats)
config-loader.cjs Project config loading — defaults merge, legacy-key migration, workstream overlay, unknown-key/profile-override validation (extracted from core.cjs, ADR-857)
config-schema.cjs Single source of truth for VALID_CONFIG_KEYS and dynamic key patterns; imported by both the validator and the config-schema-docs parity test
config-types.cjs TypeScript type definitions for the model_policy config block — ModelPolicyConfig, TierEntry, RuntimeTiers; compiled from src/config-types.cts at publish time (ADR-457)
config.cjs config.json read/write, section initialization; imports validator from config-schema.cjs
configuration.cjs Configuration Module — legacy-key normalization, defaults merge, and explicit on-disk migration; pure normalization primitives consumed by config-loader.cjs and config-schema.cjs (loadConfig extracted to config-loader per ADR-857 #885)
context-utilization.cjs Pure classifier for gsd-health --context — turns (tokensUsed, contextWindow) into a { percent, state } triage result against the 60%/70% fracture-point thresholds (#2792)
core-utils.cjs Shared low-level utilities — POSIX path normalization, sub-repo/subdirectory scanning, phase file stats, slug/one-liner/plan-id helpers, time-ago (extracted from core.cjs, ADR-857)
core.cjs Shared utilities and runtime fallbacks; compatibility re-exports for planning-workspace and I/O (io.cjs) helpers
coverage.cjs Deterministic SUMMARY coverage: block parser/validator/classifier for gsd-tools uat classify-coverage; routes deliverables to auto-pass vs human-UAT with a fail-safe default (#1602)
decisions.cjs Parses CONTEXT.md <decisions> blocks; accepts numeric (D-42) and alphanumeric (D-INFRA-01) IDs; returns {id, text, category, tags, trackable}
docs.cjs Docs-update workflow init, Markdown scanning, monorepo detection
drift.cjs Post-execute codebase structural drift detector (#2003): classifies file changes into new-dir/barrel/migration/route categories and round-trips last_mapped_commit frontmatter
edge-probe.cjs Spec-completeness edge probe (compiled from src/edge-probe.cts, gitignored) — the first adapter of the probe-core resolution model (ADR-550 Decision 7): shape classification, applicable-category relevance filter, edge proposal, and the {explicit, backstop} verification validators; delegates merge/rollup/CLI to probe-core; exports classifyShape, applicableCategories, proposeEdges, analyzeCoverage, validateResolution, TAXONOMY (#550)
eval-command-router.cjs Routes the eval.score verb (compiled from src/eval-command-router.cts, gitignored) — thin dispatcher into the eval scoring module (#1579)
eval.cjs Deterministic eval scoring (compiled from src/eval.cts, gitignored) — computeEvalScore (coverage0.6 + infra0.4, bands 80/60/40) + cmdEvalScore CLI domain guard; moves the gsd-eval-auditor's weighted arithmetic out of the prompt into code (#10 / #1579)
fallow-runner.cjs Fallow audit adapter for /gsd-code-review: binary resolution (PATH then node_modules/.bin), actionable missing-binary errors, and structural findings normalization
federated-config.cjs Defensive merge of capability-declared config slices into the loadConfig return value — ADR-857 phase 3b; exports mergeFederatedConfig({ configSchema, isCentralKey, userConfig }) → { values, validKeys, warnings }; live for migrated Capability keys that are atomically removed from the central config schema
frontmatter.cjs YAML frontmatter CRUD operations
gap-checker.cjs Post-planning gap analysis (#2493): unified REQUIREMENTS.md + CONTEXT.md decisions vs PLAN.md coverage report (gsd-tools gap-analysis)
git-base-branch.cjs Single base-branch resolver (gsd_run query git.base-branch) with full precedence ladder: config override → origin/HEAD symref → git remote show origin → local branch presence → "main". Eliminates per-workflow duplicated bash detection (#1146)
graphify.cjs Knowledge-graph build/query/status/diff for /gsd-graphify
graphify-command-router.cjs ADR-959 capability command router for gsd-tools graphify — dispatches build/query/status/diff subcommands; first real capability command cutover (phase 4d-impl-2)
gsd2-import.cjs External-plan ingest for /gsd-import --from-gsd2
host-integration.cjs Host-Integration Interface (ADR-1239 Phase A) — negotiated capability contract over the six host-integration points; negotiateHostCapabilities fail-closes on undeclared/unknown/undocumented values, typed degradation ladder, host-capability profiles; the 8 runtime.hostIntegration axes are validated in capability-validator.cjs and sourced per-CLI in docs/reference/host-integration-capability-matrix.md
init-command-router.cjs Thin CJS subcommand router adapter for gsd-tools init
init.cjs Compound context loading for each workflow type
install-effort-resolver.cjs Install-time effort resolution — readGsdEffectiveEffortConfig (merges ~/.gsd/defaults.json + project .planning/config.json) + resolveInstallTimeEffort, extracted from bin/install.js (#2071) so gsd-tools effort sync can require it from the shipped runtime instead of the never-copied package-root installer; install.js imports them back (single source)
install-engine.cjs Runtime-artifact install engine — installRuntimeArtifacts/uninstallRuntimeArtifacts/installOpencodeFamilySkills + their helpers, extracted from bin/install.js (ADR-1239 Phase B, #1679); install.js imports them back and injects getCommitAttribution
install-profiles.cjs Install profile allowlist + skill staging for --minimal install (#2762); single source of truth for which gsd-* skills/agents land in runtime config dirs
installer-migration-authoring.cjs Installer migration authoring guardrails for record metadata, explicit scopes, ownership evidence, and runtime contract citations
installer-migration-report.cjs Installer migration report projection and blocked-action guard for install/update integration
installer-migrations.cjs Installer migration planning, artifact classification, install-state persistence, journaled apply, and rollback helpers
intel.cjs Codebase intel store backing /gsd-map-codebase --query and gsd-intel-updater
intel-command-router.cjs ADR-959 capability command router for gsd-tools intel — extracted from the case 'intel': arm in gsd-tools.cjs; dispatches query/status/diff/snapshot/patch-meta/validate/extract-exports/update/api-surface subcommands; preserves timeAgo transform on status.files[*].updated_at in non-raw mode; phase 4d-impl-4 (last first-party cutover)
io.cjs CLI I/O primitives — output/error emission, JSON-error mode, and large-payload temp-file spillover (extracted from core.cjs, ADR-857)
learnings.cjs Cross-phase learnings extraction for /gsd-extract-learnings
legacy-cleanup.cjs Detect and remove leftover get-shit-done-cc artifacts; exports planLegacyCleanup (pure scan) and applyLegacyCleanup (thin IO applier) that root out stale files from the old package across every GSD-managed runtime config directory (#607)
loop-host-contract.cjs Generated Loop Host Contract — 12 loop points, per-step agent roles, and core artifacts for the five-step pipeline (discuss/plan/execute/verify/ship); emitted by scripts/gen-loop-host-contract.cjs --write (ADR-894 §3); consumed by gen-capability-registry.cjs
loop-resolver.cjs Loop Extension Point resolver — ADR-857 phase 3c/6 registry-consuming query; given a canonical loop point, filters byLoopPoint by resolved Capability State plus config activation (when key traversal with prototype-pollution guard), returns { point, activeHooks, rendered } envelope; resolveLoopHooks and renderLoopHooks are pure (no I/O); command surface: gsd-tools loop render-hooks <point> [--config-dir <path>]
markdown-sectionizer.cjs Canonical markdown-structure parsing seam (ADR-1372, epic #1372) — pure, Node built-ins only; exports stripFencedCode (CommonMark-correct fence stripper, CRLF-safe), stripInlineCode (per-line CommonMark inline-code-span stripper, #2365), tokenizeHeadings (ATX headings outside fenced blocks), collectSections/collectSection (line-by-line section collection with bodyStart/bodyEnd offsets), iterateBullets (dash/checkbox/numbered markers), extractTaggedBlocks (inner text of <tag>…</tag> blocks, caller decides fence-stripping), replaceSection (pure character-offset body splice for read-modify-write callers), and withSection (resolve a section by heading/predicate and run an edit callback against ONLY its body, splicing the result back — ADR-2143 §4 bounded mutation); foundation for T0–T7 migration tiers retiring 8+ ad-hoc parsers
markdown-table.cjs Canonical GFM table model + TABLE_SCHEMAS registry seam (ADR-2143, epic #2143) — pure, Node built-ins only; exports parseMarkdownTable(sectionText) → Result<MarkdownTable> (parses the first GFM pipe table, typed parse errors for ragged/malformed rows rather than silent coercion), MarkdownTable ({columns, rows}, rows addressed by column name), Result<T> ({ok:true,value}|{ok:false,reason} — distinct from command-routing-hub's dispatch Result), TABLE_SCHEMAS (canonical column-header variants for RoadmapProgress/RequirementsTraceability/QuickTasks/Security tables), and matchTableSchema(columns) → {id,label}|null (resolves parsed headers back to a canonical schema); consumed by phase-lifecycle.cts's deriveProgressFromRoadmap (fixes #2137, the 5-column milestone-grouped Progress table)
milestone.cjs Milestone archival, requirements marking
model-catalog.cjs CJS adapter over the shared model catalog JSON; exports canonical runtime tier defaults, agent profile maps, alias maps, and routing metadata for all CLI consumers
model-profiles.cjs Backward-compatible profile helpers derived from model-catalog.cjs; no longer owns its own model table
model-resolver.cjs Model/effort resolution policy — resolves model, tier, granularity, effort, and fast-mode for an agent from config + model profiles/catalog (extracted from core.cjs, ADR-857)
package-identity.cjs Generated single source for GSD's published-package coordinates (npm name, bin name, repo slug, changelog URL, manual-install command), derived from package.json; read by the update worker, check-latest-version, and installer (#498)
package-legitimacy.cjs Registry-API package legitimacy verdicts (OK/SUS/SLOP) from npm/PyPI/crates, slopcheck optional
phase-command-router.cjs Thin CJS subcommand router adapter for gsd-tools phase
phase-id.cjs Pure phase-id parsing/matching helpers — normalize, token match, milestone/phase-dir id parsing, phase-markdown regex builders (extracted from core.cjs, ADR-857)
phase-lifecycle.cjs Pure-computation phase lifecycle helpers extracted from the phase-lifecycle SDK handler
phase-locator.cjs Phase-directory search/location — active + archived phase-dir discovery, phase-id matching against the filesystem (extracted from core.cjs, ADR-857)
phase.cjs Phase directory operations, decimal numbering, plan indexing
phases-command-router.cjs Thin CJS subcommand router adapter for gsd-tools phases
plan-scan.cjs Canonical phase-plan scanner for detecting plan and summary files in flat and nested layouts (k014)
planning-workspace.cjs Planning path/workstream seam (planningDir, planningPaths, active-workstream routing, .planning/.lock orchestration)
project-root.cjs Resolves a project root from a starting directory using four heuristics (own .planning/ guard, sub_repos config, multiRepo flag, .git heuristic)
profile-output.cjs Profile rendering, USER-PROFILE.md and dev-preferences.md generation
profile-pipeline-command-router.cjs ADR-959 capability command router for the profile-pipeline command family — dispatches scan-sessions, extract-messages, profile-sample (pipeline phase) and write-profile, profile-questionnaire, generate-dev-preferences, generate-claude-profile, generate-claude-md (output phase); phase 6 cutover
profile-pipeline.cjs User behavioral profiling data pipeline, session file scanning
prompt-budget.cjs Pure token-budget accounting for review prompts — estimates tokens, applies deterministic trim priority (head-shrink PROJECT.md, proportional plan truncation, drop context/research/requirements, hard-fail guard), returns structured metadata for review.max_prompt_tokens (#3081)
research-provider.cjs Research provider waterfall, confidence tiers, and planResearch (cache-hits + fetch plan)
research-store.cjs Content-addressed research cache: sha256 keys, per-source TTL staleness, two-tier (user ~/.gsd / project .planning) store
probe-core.cjs Generic spec-phase probe resolution model (compiled from src/probe-core.cts, gitignored; ADR-550 Decision 7) — the status×verification re-cut (status: resolved/dismissed/unresolved × per-probe verification), validateResolution/validateRequirement, analyzeCoverage(items, resolutions?, validators) merge/rollup/orphan-reject, the byVerification rollup, and the runProbeCli I/O scaffold; the shared seam consumed by edge-probe (and the prohibition probe #644); exports VALID_STATUS, validateResolution, validateRequirement, analyzeCoverage, runProbeCli (#550)
prohibition-enforcement.cjs Deterministic test-tier prohibition PRODUCER/gate (compiled from src/prohibition-enforcement.cts, gitignored; #1259, ADR-550 D5d "heavy half") — locates the wired mechanical check (node-test or lint-rule), confirms it is fail-first, runs it via an injectable runner, builds typed enforcementEvidence, and emits the dispositionForProhibition verdict; a passing wired check disposes green, a missing/failing/non-fail-first check hard-gates (flagged, non-green) in both interactive and autonomous modes; exports runProhibitionEnforcement, routeProhibitionEnforcement; CLI surface gsd_run check prohibition-enforcement <request.json>
review-reviewer-selection.cjs Reviewer selection/normalization helpers for /gsd-review default reviewer policy and precedence
roadmap-command-router.cjs Thin CJS subcommand router adapter for gsd-tools roadmap
roadmap-parser.cjs ROADMAP.md parsing — milestone slicing, current-milestone extraction, phase/milestone lookups, milestone-phase filter (extracted from core.cjs, ADR-857)
roadmap-upgrade.cjs Migration tool for converting legacy Phase N entries to milestone-prefixed Phase M-NN convention; computeMigrationPlan + applyMigration with dry-run default and atomic rollback
roadmap.cjs ROADMAP.md parsing, phase extraction, plan progress
runtime-artifact-conversion.cjs Runtime artifact conversion module — projects Claude-authored commands, agents, and skills into runtime-specific artifact bodies while preserving installer compatibility exports
runtime-artifact-install-plan.cjs Runtime artifact install plan module — stages pre-resolved layout kinds, applies runtime body rewrites, and returns copy-plan items plus cleanup obligations
runtime-artifact-layout.cjs Runtime artifact layout module — resolves the artifact directory shapes (commands, agents, skills) for each supported runtime; single source of truth for per-runtime artifact placement (#3663)
runtime-config-adapter-registry.cjs Explicit runtime config adapter registry — resolves per-runtime config-mutation install intent (install surface, shared-settings gate, finish-phase permission writer); see ADR-58.
runtime-hooks-surface.cjs Runtime hooks surface module — standalone hook-surface writer functions extracted from bin/install.js (ADR-857 phase 5f-1); owns Cline/Cursor/Copilot/Codex hook artifact generation and reconciliation.
runtime-name-policy.cjs Runtime name normalization policy — canonical token sanitization for runtime identifiers used in path construction and display
runtime-homes.cjs Canonical runtime → global config/skills directory mapping; first-class support for all 15 runtimes including Hermes nested layout and Cline rules-based exclusion (#3126)
runtime-slash.cjs Runtime-aware slash-command formatter — single source of truth for emitting /gsd-<cmd> (skills-based runtimes) and $gsd-<cmd> (codex) in user-facing output and persisted artifacts (#3584)
schema-detect.cjs Schema-drift detection for ORM patterns (Prisma, Drizzle, Supabase, TypeORM, Payload); exports detectSchemaFiles, detectSchemaOrm, checkSchemaDrift, SCHEMA_PATTERNS, ORM_INFO
secrets.cjs Secret-config masking convention (****<last-4>) for integration keys; exports SECRET_CONFIG_KEYS, isSecretKey, maskSecret, maskIfSecret
semver-compare.cjs Shared semver comparison policy helpers (compareSemverCore, stable-triplet validation, normalized tuple parsing) consumed by update-check hooks, statusline dev-install detection, and changeset extract range logic (#10)
security.cjs Path traversal prevention, prompt injection detection, safe JSON/shell helpers
shell-command-projection.cjs Runtime-aware shell command projection for managed hook serialization: decides PowerShell call-operator usage by runtime/platform and normalizes Windows script path tokens
spec-section.cjs SPEC section-status helper (compiled from src/spec-section.cts, gitignored) — the single source of truth for the canonical SPEC headings (suffix-tolerant) and markdown-table row counting; specSectionStatus/countSectionDataRows decide per-section "supplied" for plan-phase's spec-less probe fallback, replacing ad-hoc awk (contract pinned by tests/spec-section.test.cjs)
state-command-router.cjs Thin CJS subcommand router adapter for gsd-tools state
state.cjs STATE.md parsing, updating, progression, metrics
state-document.cjs Pure STATE.md field extraction, replacement, status normalization, and progress calculation transforms
surface.cjs Runtime surface module — manages the runtime enable/disable surface state independently of the install-time profile marker (ADR-0011 Phase 2)
task-command-router.cjs Thin CJS subcommand router adapter for gsd-tools task
template.cjs Template selection and filling with variable substitution
normalize-test-command.cjs Normalizes a resolved test command to a one-shot form so a watch-mode runner (vitest/jest) cannot hang a verification gate (#1857); shared by all four test-command gates (regression, post-merge, audit-fix, verify-phase)
uat.cjs UAT file parsing, verification debt tracking, audit-uat support
uat-predicate.cjs UAT-passed predicate — markdown-aware evaluation of HUMAN-UAT results; returns pass only when all required checks pass; ignores false-positive contexts (frontmatter, fenced code, blockquotes, HTML comments)
ui-consideration-probe.cjs Spec-completeness UI-consideration probe (compiled from src/ui-consideration-probe.cts, gitignored) — the third adapter of the probe-core resolution model (ADR-550 Decision 7): element-kind classification, applicable-category relevance filter, consideration proposal, proposeElements/autoResolve (propose-then-confirm + the --auto never-dismiss floor), and the {explicit, backstop} validators; delegates merge/rollup/CLI to probe-core; exports classifyElement, applicableCategories, proposeConsiderations, proposeElements, autoResolve, analyzeCoverage, UI_TAXONOMY (#1867)
ui-safety-gate.cjs Shell-free word-boundary UI token detector (#3706, #3718); reads phase-section text from stdin, exits 0 (UI found) or 1 (no UI); also deployed to gsd-core/bin/lib/ so the GSD installer ships it to $RUNTIME_DIR (#448)
update-context.cjs Pure install-context resolver for /gsd:update — runtime/scope/config-dir/version detection (LOCAL/GLOBAL/UNKNOWN) ported from update.md bash; backs gsd-tools update-context (#498)
validate-command-router.cjs Thin CJS subcommand router adapter for gsd-tools validate
validate.cjs Pure phase variant normalization helpers (phaseVariants, buildRoadmapPhaseVariants, buildNotStartedPhaseVariants) used by verify.cjs for W006/W007 checks; no I/O, no async
verification-command-router.cjs Thin CJS subcommand router adapter for gsd-tools verification
verification.cjs Verification-status routing — consolidates pass/gaps_found/human_needed status from phase verifier-emitted VERIFICATION.md frontmatter (#651)
verify-command-router.cjs Thin CJS subcommand router adapter for gsd-tools verify
verify.cjs Plan structure, phase completeness, reference, commit validation
workstream-inventory-builder.cjs Pure workstream inventory projection builder
workstream-inventory.cjs Shared workstream inventory projection: state fields, phase/plan/summary counts, roadmap phase count, and active marker — thin orchestrator that delegates pure projection to workstream-inventory-builder.cjs
workstream-name-policy.cjs Canonical workstream name validation (isValidActiveWorkstreamName, hasInvalidPathSegment, validateWorkstreamName) and slug normalization (toWorkstreamSlug)
workstream.cjs Workstream CRUD, migration, session-scoped active pointer
worktree-base-ref.cjs Worktree base-ref drift detection and degrade decision (evaluateWorktreeBaseDegrade) plus no-clobber worktree.baseRef settings management for the base-check/set-baseref subcommands (#683)
worktree-safety.cjs Worktree-root resolution and non-destructive prune policy decisions; owns W017 health-check logic
write-set.cjs Shared fail-loud Result<T> ({ok:true,value}|{ok:false,reason}) and per-surface write-set contracts (ADR-2143, epic #2143) — WriteOutcome ({surface,applied}), WriteSet (WriteOutcome[]), and writeSetComplete(ws) (true only when the set is non-empty AND every surface applied, never an OR-into-one-flag); markdown-table.cjs re-exports Result from here so existing importers are unaffected; consumed by milestone.cts's requirements mark-complete handler to report a structured per-surface (checkbox/traceability) write-set alongside its existing fields (fixes the structural half of #2140)

docs/CLI-TOOLS.md may describe a subset of these modules; when it disagrees with the filesystem, this table and the directory listing are authoritative.


Hooks

Full listing: hooks/.

Hook Event Purpose
gsd-statusline.js statusLine Displays model, task, directory, context usage
gsd-context-monitor.js PostToolUse / AfterTool Injects agent-facing context warnings at 35%/25% remaining
gsd-check-update.js SessionStart Background check for new GSD versions
gsd-check-update-worker.js (worker) Background worker helper for check-update
gsd-update-banner.js SessionStart Opt-in banner surfacing update availability when GSD statusline isn't used (PR #2795)
gsd-cursor-session-start.js Cursor sessionStart Cursor-native context injection at session start (issue #777)
gsd-cursor-post-tool.js Cursor postToolUse Cursor-native STATE.md update monitor after tool calls (issue #777)
gsd-cursor-pre-tool.js Cursor preToolUse Cursor-native write-path guard for .planning/ (ADR-1239 / #2089)
gsd-cursor-stop.js Cursor stop Cursor-native verify-work reminder on agent stop (ADR-1239 / #2089)
gsd-cursor-subagent-start.js Cursor subagentStart Cursor-native subagent context injection (ADR-1239 / #2089)
gsd-cursor-subagent-stop.js Cursor subagentStop Cursor-native subagent completion reminder (ADR-1239 / #2089)
gsd-windsurf-pre-write.js Windsurf/Cascade pre_write_code Blocking (exit-code-2) write-path guard — blocks a write resolving to a different git root than cwd, or inside .git/ internals (ADR-1239 / #2100)
gsd-windsurf-pre-command.js Windsurf/Cascade pre_run_command Blocking (exit-code-2) destructive-command guard — conservative deny-list (rm -rf root/home wipes, force-push to a protected branch) (ADR-1239 / #2100)
gsd-prompt-guard.js PreToolUse Scans .planning/ writes for prompt-injection patterns (advisory)
gsd-workflow-guard.js PreToolUse Detects file edits outside GSD workflow context (advisory, opt-in)
gsd-read-guard.js PreToolUse Advisory guard preventing Edit/Write on unread files
gsd-read-injection-scanner.js PostToolUse Scans tool Read results for prompt-injection patterns (v1.36+, PR #2201)
gsd-worktree-path-guard.js PreToolUse Hard-blocks Edit/Write/MultiEdit with absolute paths outside the worktree root (PR #579, #260)
gsd-config-reload.js FileChanged Hot-reloads GSD config context when .planning/config.json changes mid-session (#770)
gsd-ensure-canonical-path.js SessionStart Symlinks ~/.claude/gsd-core/{bin,contexts,references,templates,workflows} to the plugin's bundled tree so @~/.claude/gsd-core/... includes resolve in marketplace plugin installs; no-op in classic installs, self-heals after claude plugin update (#997)
gsd-session-state.sh PostToolUse Session-state tracking for shell-based runtimes
gsd-validate-commit.sh PostToolUse Commit validation for conventional-commit enforcement
gsd-phase-boundary.sh PostToolUse Phase-boundary detection for workflow transitions
gsd-graphify-update.sh PostToolUse Auto-rebuild knowledge graph after main HEAD advances (opt-in, default off — #3347)

Maintenance

  • When a new command, agent, workflow, reference, CLI module, or hook ships, update the corresponding section here before the release is cut.
  • The drift-guard tests under tests/ (see "How To Use This File" above) assert that every shipped file is enumerated in this inventory. A new file without a matching row here will fail CI.
  • When the filesystem diverges from docs/ARCHITECTURE.md counts or from curated-subset docs (e.g. docs/AGENTS.md's primary roster), this file is the source of truth.