Tom Boucher
62db008570
security: add prompt injection guards, path traversal prevention, and input validation
Defense-in-depth security hardening for a codebase where markdown files become
LLM system prompts. Adds centralized security module, PreToolUse hook for
injection detection, and CI-ready codebase scan.
New files:
- security.cjs: path traversal prevention, prompt injection scanner/sanitizer,
safe JSON parsing, field name validation, shell arg validation
- gsd-prompt-guard.js: PreToolUse hook scans .planning/ writes for injection
- security.test.cjs: 62 unit tests for all security functions
- prompt-injection-scan.test.cjs: CI scan of all agent/workflow/command files
Hardened code paths:
- readTextArgOrFile: path traversal guard (--prd, --text-file)
- cmdStateUpdate/Patch: field name validation prevents regex injection
- cmdCommit: sanitizeForPrompt strips invisible chars from commit messages
- gsd-tools --fields: safeJsonParse wraps unprotected JSON.parse
- cmdFrontmatterGet/Set: null byte rejection
- cmdVerifyPathExists: null byte rejection
- install.js: registers prompt guard hook, updates uninstaller
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-20 11:38:26 -04:00
..
2026-03-20 11:38:26 -04:00
2026-03-20 15:54:58 +01:00
2026-03-20 10:41:42 -04:00
2026-03-20 11:38:26 -04:00
2026-03-20 10:38:57 -04:00
2026-03-19 15:05:20 -04:00
2026-03-15 11:45:14 -06:00
2026-03-19 15:05:20 -04:00
2026-03-17 11:41:44 -04:00
2026-03-16 09:46:00 -06:00
2026-03-19 21:30:41 +05:00
2026-03-20 11:38:26 -04:00
2026-03-20 11:38:26 -04:00
2026-03-16 13:39:34 -06:00
2026-03-19 00:05:05 -05:00
2026-03-19 12:03:58 -04:00