Renames (git mv) with all references updated (ci-test-scope RULES, windows-parity allowlist, test-file-count allowlist, docs in 6 locales): - 5 scanner tests -> *.security.test.cjs — the 'Run security tests' CI step ran zero files since the suite taxonomy landed; it is now honest. - graphify-auto-update -> *.slow.test.cjs (36s, slowest file in the suite; e2e gsd-tools spawns) — runs on full-matrix lanes and push to next. - installer-migration-install-integration -> *.integration.test.cjs (13s; an integration test by its own name). Coverage gate measured after retags: 88.55% lines (gate 70%). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adversarial security fixtures (#3596)
Reusable hostile payloads consumed by
tests/security-prompt-injection.security.test.cjs.
The fixtures here are pure data — they are loaded by the test as input to the production code under test (hooks, validators, sanitizers, CLI). They are not executed and contain no real secrets.
| File | Attack class | Consumed by |
|---|---|---|
context-instruction-override.md |
Fake instruction override + role manipulation | gsd-read-injection-scanner.js, gsd-prompt-guard.js |
plan-fake-system-tags.md |
<system>/<assistant> boundary mimicry |
sanitizeForPrompt, gsd-prompt-guard.js |
roadmap-heredoc-breakout.md |
Heredoc-shaped payload inside a planning doc | gsd-read-injection-scanner.js |
plan-fake-frontmatter.md |
Frontmatter fields that try to override intent | gsd-read-injection-scanner.js |
context-malicious-markdown-link.md |
Markdown links with javascript: and embedded creds |
gsd-read-injection-scanner.js |
context-invisible-unicode.md |
Zero-width chars hiding instructions | gsd-read-injection-scanner.js, sanitizeForPrompt |
The fake-token values used in CLI redaction probes
(ghp_AAAA…, sk-AAAA…) are constructed inline by the test, not stored
here, so an editor or grep that scans this directory does not surface
plausible-looking credentials.