Files
msd-core/gsd-core/bin/shared/config-schema.manifest.json
Tom Boucher f7e902f1cf feat(#52): add agent_skills_security.trusted_global_roots allowlist for global skills (#754)
* feat(#52): add agent_skills_security.trusted_global_roots allowlist

Opt-in allowlist so a global: agent skill whose SKILL.md realpath resolves
outside the default global skills base (e.g. ~/.claude/skills) is accepted
when its real target lies under a user-declared trusted root. Default [] is
byte-identical to prior behavior; the symlink-escape guard is preserved and
simply re-applied against each declared root.

- src/security.cts: loadTrustedGlobalRoots — tilde-expand (~ and ~/), reject
  project-relative and dangerously broad roots (filesystem/UNC root, homedir),
  realpath-canonicalize each root every run and drop non-existent ones.
- src/init.cts: on base-check failure the guard consults the trusted roots
  (hoisted out of the loop); emits a stderr NOTE when a skill is accepted via
  a trusted root so the widened boundary is visible.
- src/core.cts: thread agent_skills_security through loadConfig.
- config-schema.manifest.json: allow the new key path.
- docs/CONFIGURATION.md: document the option and its security model.
- tests/agent-skills.test.cjs: unit + end-to-end CLI coverage (regression,
  feature, negative, broad-root hardening, stderr NOTE).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs(#52): add changeset fragment for trusted_global_roots (#754)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-07 01:06:41 -04:00

193 lines
6.3 KiB
JSON

{
"_comment": "Canonical schema manifest for valid config key paths. This manifest is the single CJS source of truth for valid config keys; dynamicKeyPatterns source strings are recompiled to RegExp at runtime by config-schema.cjs. runtimeStateKeys mirrors RUNTIME_STATE_KEYS.",
"validKeys": [
"mode",
"granularity",
"parallelization",
"commit_docs",
"model_profile",
"search_gitignored",
"brave_search",
"firecrawl",
"exa_search",
"workflow.research",
"workflow.plan_check",
"workflow.verifier",
"workflow.nyquist_validation",
"workflow.ai_integration_phase",
"workflow.ui_phase",
"workflow.ui_safety_gate",
"workflow.auto_advance",
"workflow.node_repair",
"workflow.node_repair_budget",
"workflow.tdd_mode",
"workflow.human_verify_mode",
"workflow.text_mode",
"workflow.research_before_questions",
"workflow.discuss_mode",
"workflow.skip_discuss",
"workflow.auto_prune_state",
"workflow.use_worktrees",
"workflow.worktree_skip_hooks",
"workflow.code_review",
"workflow.code_review_depth",
"workflow.code_review_command",
"workflow.pattern_mapper",
"workflow.plan_bounce",
"workflow.plan_bounce_script",
"workflow.plan_bounce_passes",
"workflow.plan_chunked",
"workflow.plan_review_convergence",
"workflow.post_planning_gaps",
"workflow.security_enforcement",
"workflow.security_asvs_level",
"workflow.security_block_on",
"workflow.drift_threshold",
"workflow.drift_action",
"code_quality.fallow.enabled",
"code_quality.fallow.scope",
"code_quality.fallow.profile",
"code_quality.fallow.mcp",
"ship.pr_body_sections",
"git.branching_strategy",
"git.base_branch",
"git.create_tag",
"git.phase_branch_template",
"git.milestone_branch_template",
"git.quick_branch_template",
"planning.commit_docs",
"planning.search_gitignored",
"planning.sub_repos",
"review.ollama_host",
"review.lm_studio_host",
"review.llama_cpp_host",
"review.default_reviewers",
"review.max_prompt_tokens",
"review.max_prompt_tokens_per_reviewer",
"workflow.cross_ai_execution",
"workflow.cross_ai_command",
"workflow.cross_ai_timeout",
"workflow.subagent_timeout",
"executor.stall_detect_interval_minutes",
"executor.stall_threshold_minutes",
"workflow.inline_plan_threshold",
"hooks.context_warnings",
"hooks.workflow_guard",
"workflow.context_coverage_gate",
"statusline.show_last_command",
"statusline.context_position",
"workflow.ui_review",
"workflow.max_discuss_passes",
"features.thinking_partner",
"context",
"features.global_learnings",
"learnings.max_inject",
"project_code",
"phase_id_convention",
"phase_naming",
"manager.flags.discuss",
"manager.flags.plan",
"manager.flags.execute",
"response_language",
"context_window",
"intel.enabled",
"graphify.enabled",
"graphify.build_timeout",
"graphify.auto_update",
"claude_md_path",
"claude_md_assembly.mode",
"runtime",
"resolve_model_ids",
"effort.default",
"fast_mode.enabled",
"plan_review.source_grounding",
"plan_review.source_grounding_authority",
"model_policy.provider",
"model_policy.budget",
"model_policy.high",
"model_policy.medium",
"model_policy.low",
"agent_skills_security.trusted_global_roots"
],
"runtimeStateKeys": [
"workflow._auto_chain_active"
],
"dynamicKeyPatterns": [
{
"topLevel": "agent_skills",
"source": "^agent_skills\\.[a-zA-Z0-9_-]+$",
"description": "agent_skills.<agent-type>"
},
{
"topLevel": "review",
"source": "^review\\.models\\.[a-zA-Z0-9_-]+$",
"description": "review.models.<cli-name>"
},
{
"topLevel": "features",
"source": "^features\\.[a-zA-Z0-9_]+$",
"description": "features.<feature_name>"
},
{
"topLevel": "claude_md_assembly",
"source": "^claude_md_assembly\\.blocks\\.[a-zA-Z0-9_]+$",
"description": "claude_md_assembly.blocks.<section>"
},
{
"topLevel": "model_profile_overrides",
"source": "^model_profile_overrides\\.[a-zA-Z0-9_-]+\\.(opus|sonnet|haiku)$",
"description": "model_profile_overrides.<runtime>.<opus|sonnet|haiku>"
},
{
"topLevel": "models",
"source": "^models\\.(planning|discuss|research|execution|verification|completion)$",
"description": "models.<planning|discuss|research|execution|verification|completion>"
},
{
"topLevel": "granularities",
"source": "^granularities\\.(planning|discuss|research|execution|verification|completion)$",
"description": "granularities.<planning|discuss|research|execution|verification|completion>"
},
{
"topLevel": "dynamic_routing",
"source": "^dynamic_routing\\.(enabled|escalate_on_failure|max_escalations|tier_models\\.(light|standard|heavy))$",
"description": "dynamic_routing.<enabled|escalate_on_failure|max_escalations|tier_models.<light|standard|heavy>>"
},
{
"topLevel": "model_overrides",
"source": "^model_overrides\\.[a-zA-Z0-9_-]+$",
"description": "model_overrides.<agent-id>"
},
{
"topLevel": "effort",
"source": "^effort\\.routing_tier_defaults\\.(light|standard|heavy)$",
"description": "effort.routing_tier_defaults.<light|standard|heavy>"
},
{
"topLevel": "effort",
"source": "^effort\\.agent_overrides\\.[a-zA-Z0-9_-]+$",
"description": "effort.agent_overrides.<agent-id>"
},
{
"topLevel": "fast_mode",
"source": "^fast_mode\\.routing_tier_defaults\\.(light|standard|heavy)$",
"description": "fast_mode.routing_tier_defaults.<light|standard|heavy>"
},
{
"topLevel": "fast_mode",
"source": "^fast_mode\\.agent_overrides\\.[a-zA-Z0-9_-]+$",
"description": "fast_mode.agent_overrides.<agent-id>"
},
{
"topLevel": "review",
"source": "^review\\.max_prompt_tokens_per_reviewer\\.[a-zA-Z0-9_-]+$",
"description": "review.max_prompt_tokens_per_reviewer.<reviewer-slug>"
},
{
"topLevel": "model_policy",
"source": "^model_policy\\.runtime_tiers\\.[a-zA-Z0-9_-]+\\.(opus|sonnet|haiku)$",
"description": "model_policy.runtime_tiers.<runtime>.<opus|sonnet|haiku>"
}
]
}