Files
msd-core/tests/agent-size-baseline.json
Tom Boucher b5ce72f729 fix(#2119): single SECURITY.md writer — auditor is return-only (#2154)
* fix(2119): single SECURITY.md writer — auditor is return-only

The gsd-security-auditor held Write/Edit and was instructed to write
SECURITY.md (no <N>- prefix, no template frontmatter), while the
orchestrator's Step 6 also wrote the correct padded <N>-SECURITY.md
from templates/SECURITY.md. Two writers, two naming conventions, two
shapes — the auditor's unprefixed file was invisible to the workflow's
*-SECURITY.md glob detector and unparseable for the threats_open gate.

Fix (option 1 from the issue): make the auditor return-only.
- Remove Write/Edit from auditor's tools
- Rewrite all 'Write SECURITY.md' instructions to 'Return structured
  verdict' with threats_open count
- Add explicit constraint in workflow Step 5 spawn prompt
- Update existing test (was asserting Write in tools — now asserts absence)
- Add new regression test for single-writer contract
- Update docs/AGENTS.md stale Tools/Produces rows
- Regenerate golden fixtures + agent size baseline

* docs(changeset): backfill PR number (#2154)

* chore(#2119): regenerate pi/qwen golden fixtures after next merge

The single-writer change edits gsd-core/workflows/secure-phase.md and
agents/gsd-security-auditor.md; pi.json (added on next) and qwen.json (merge
straggler) were the only runtime fixtures still holding pre-change hashes for
those files. All other runtimes already reflect the change. Regenerated via
the sanctioned gen-golden-install-parity script.

* merge origin/next — regenerate goldens + baseline for merged state

* fix slash-command syntax: /gsd-secure-phase → /gsd:secure-phase (#2154 CI fix)
2026-07-13 00:47:15 -04:00

37 lines
1.1 KiB
JSON

{
"gsd-advisor-researcher.md": 4727,
"gsd-ai-researcher.md": 5943,
"gsd-assumptions-analyzer.md": 4646,
"gsd-code-fixer.md": 36640,
"gsd-code-reviewer.md": 16870,
"gsd-codebase-mapper.md": 21485,
"gsd-debug-session-manager.md": 14203,
"gsd-debugger.md": 51354,
"gsd-doc-classifier.md": 11717,
"gsd-doc-synthesizer.md": 13154,
"gsd-doc-verifier.md": 12403,
"gsd-doc-writer.md": 38924,
"gsd-domain-researcher.md": 7032,
"gsd-eval-auditor.md": 12496,
"gsd-eval-planner.md": 7008,
"gsd-executor.md": 43607,
"gsd-framework-selector.md": 6778,
"gsd-integration-checker.md": 15238,
"gsd-intel-updater.md": 18166,
"gsd-mempalace-curator.md": 4325,
"gsd-nyquist-auditor.md": 7345,
"gsd-pattern-mapper.md": 12487,
"gsd-phase-researcher.md": 40866,
"gsd-plan-checker.md": 44780,
"gsd-planner.md": 48191,
"gsd-project-researcher.md": 22242,
"gsd-research-synthesizer.md": 13847,
"gsd-roadmapper.md": 22273,
"gsd-security-auditor.md": 9431,
"gsd-ui-auditor.md": 17249,
"gsd-ui-checker.md": 14118,
"gsd-ui-researcher.md": 19557,
"gsd-user-profiler.md": 8516,
"gsd-verifier.md": 49147
}