mirror of
https://github.com/glittercowboy/get-shit-done
synced 2026-04-25 17:25:23 +02:00
* feat(#2529): /gsd-settings-integrations — third-party integrations command Adds /gsd-settings-integrations for configuring API keys, code-review CLI routing, and agent-skill injection. Distinct from /gsd-settings (workflow toggles) because these are connectivity, not pipeline shape. Three sections: - Search Integrations: brave_search / firecrawl / exa_search API keys, plus search_gitignored toggle. - Code Review CLI Routing: review.models.{claude,codex,gemini,opencode} shell-command strings. - Agent Skills Injection: agent_skills.<agent-type> free-text input, validated against [a-zA-Z0-9_-]+. Security: - New secrets.cjs module with ****<last-4> masking convention. - cmdConfigSet now masks value/previousValue in CLI output for secret keys. - Plaintext is written only to .planning/config.json; never echoed to stdout/stderr, never written to audit/log files by this flow. - Slug validators reject path separators, whitespace, shell metacharacters. Tests (tests/settings-integrations.test.cjs — 25 cases): - Artifact presence / frontmatter. - Field round-trips via gsd-tools config-set for all four search keys, review.models.<cli>, agent_skills.<agent-type>. - Config-merge safety: unrelated keys preserved across writes. - Masking: config-set output never contains plaintext sentinel. - Logging containment: plaintext secret sentinel appears only in config.json under .planning/, nowhere else on disk. - Negative: path-traversal, shell-metachar, and empty-slug rejected. - /gsd:settings workflow mentions /gsd:settings-integrations. Docs: - docs/COMMANDS.md: new command entry with security note. - docs/CONFIGURATION.md: integration settings section (keys, routing, skills injection) with masking documentation. - docs/CLI-TOOLS.md: reviewer CLI routing and secret-handling sections. - docs/INVENTORY.md + INVENTORY-MANIFEST.json regenerated. Closes #2529 * fix(#2529): mask secrets in config-get; address CodeRabbit review cmdConfigGet was emitting plaintext for brave_search/firecrawl/exa_search. Apply the same isSecretKey/maskSecret treatment used by config-set so the CLI surface never echoes raw API keys; plaintext still lives only in config.json on disk. Also addresses CodeRabbit review items in the same PR area: - #3127146188: config-get plaintext leak (root fix above) - #3127146211: rename test sentinels to concat-built markers so secret scanners stop flagging the test file. Behavior preserved. - #3127146207: add explicit 'text' language to fenced code blocks (MD040). - nitpick: unify masked-value wording in read_current legend ('****<last-4>' instead of '**** already set'). - nitpick: extend round-trip test to cover search_gitignored toggle. New regression test 'config-get masks secrets and never echoes plaintext' verifies the fix for all three secret keys. * docs(#2529): bump INVENTORY counts post-rebase (commands 84→85, workflows 82→83) * fix(test): bump CLI Modules count 27→28 after rebase onto main (CI #24811455435) PR #2604 was rebased onto main before #2605 (drift.cjs) merged. The pull_request CI runs against the merge ref (refs/pull/2604/merge), which now contains 28 .cjs files in get-shit-done/bin/lib/, but docs/INVENTORY.md headline still said "(27 shipped)". inventory-counts.test.cjs failed with: AssertionError: docs/INVENTORY.md "CLI Modules (27 shipped)" disagrees with get-shit-done/bin/lib/ file count (28) Rebased branch onto current origin/main (picks up drift.cjs row, which was already added by #2605) and bumped the headline to 28. Full suite: 5200/5200 pass.
308 lines
7.6 KiB
JSON
308 lines
7.6 KiB
JSON
{
|
|
"generated": "2026-04-22",
|
|
"families": {
|
|
"agents": [
|
|
"gsd-advisor-researcher",
|
|
"gsd-ai-researcher",
|
|
"gsd-assumptions-analyzer",
|
|
"gsd-code-fixer",
|
|
"gsd-code-reviewer",
|
|
"gsd-codebase-mapper",
|
|
"gsd-debug-session-manager",
|
|
"gsd-debugger",
|
|
"gsd-doc-classifier",
|
|
"gsd-doc-synthesizer",
|
|
"gsd-doc-verifier",
|
|
"gsd-doc-writer",
|
|
"gsd-domain-researcher",
|
|
"gsd-eval-auditor",
|
|
"gsd-eval-planner",
|
|
"gsd-executor",
|
|
"gsd-framework-selector",
|
|
"gsd-integration-checker",
|
|
"gsd-intel-updater",
|
|
"gsd-nyquist-auditor",
|
|
"gsd-pattern-mapper",
|
|
"gsd-phase-researcher",
|
|
"gsd-plan-checker",
|
|
"gsd-planner",
|
|
"gsd-project-researcher",
|
|
"gsd-research-synthesizer",
|
|
"gsd-roadmapper",
|
|
"gsd-security-auditor",
|
|
"gsd-ui-auditor",
|
|
"gsd-ui-checker",
|
|
"gsd-ui-researcher",
|
|
"gsd-user-profiler",
|
|
"gsd-verifier"
|
|
],
|
|
"commands": [
|
|
"/gsd-add-backlog",
|
|
"/gsd-add-phase",
|
|
"/gsd-add-tests",
|
|
"/gsd-add-todo",
|
|
"/gsd-ai-integration-phase",
|
|
"/gsd-analyze-dependencies",
|
|
"/gsd-audit-fix",
|
|
"/gsd-audit-milestone",
|
|
"/gsd-audit-uat",
|
|
"/gsd-autonomous",
|
|
"/gsd-check-todos",
|
|
"/gsd-cleanup",
|
|
"/gsd-code-review",
|
|
"/gsd-code-review-fix",
|
|
"/gsd-complete-milestone",
|
|
"/gsd-debug",
|
|
"/gsd-discuss-phase",
|
|
"/gsd-do",
|
|
"/gsd-docs-update",
|
|
"/gsd-eval-review",
|
|
"/gsd-execute-phase",
|
|
"/gsd-explore",
|
|
"/gsd-extract_learnings",
|
|
"/gsd-fast",
|
|
"/gsd-forensics",
|
|
"/gsd-from-gsd2",
|
|
"/gsd-graphify",
|
|
"/gsd-health",
|
|
"/gsd-help",
|
|
"/gsd-import",
|
|
"/gsd-inbox",
|
|
"/gsd-ingest-docs",
|
|
"/gsd-insert-phase",
|
|
"/gsd-intel",
|
|
"/gsd-join-discord",
|
|
"/gsd-list-phase-assumptions",
|
|
"/gsd-list-workspaces",
|
|
"/gsd-manager",
|
|
"/gsd-map-codebase",
|
|
"/gsd-milestone-summary",
|
|
"/gsd-new-milestone",
|
|
"/gsd-new-project",
|
|
"/gsd-new-workspace",
|
|
"/gsd-next",
|
|
"/gsd-note",
|
|
"/gsd-pause-work",
|
|
"/gsd-plan-milestone-gaps",
|
|
"/gsd-plan-phase",
|
|
"/gsd-plan-review-convergence",
|
|
"/gsd-plant-seed",
|
|
"/gsd-pr-branch",
|
|
"/gsd-profile-user",
|
|
"/gsd-progress",
|
|
"/gsd-quick",
|
|
"/gsd-reapply-patches",
|
|
"/gsd-remove-phase",
|
|
"/gsd-remove-workspace",
|
|
"/gsd-research-phase",
|
|
"/gsd-resume-work",
|
|
"/gsd-review",
|
|
"/gsd-review-backlog",
|
|
"/gsd-scan",
|
|
"/gsd-secure-phase",
|
|
"/gsd-session-report",
|
|
"/gsd-set-profile",
|
|
"/gsd-settings",
|
|
"/gsd-settings-advanced",
|
|
"/gsd-settings-integrations",
|
|
"/gsd-ship",
|
|
"/gsd-sketch",
|
|
"/gsd-sketch-wrap-up",
|
|
"/gsd-spec-phase",
|
|
"/gsd-spike",
|
|
"/gsd-spike-wrap-up",
|
|
"/gsd-stats",
|
|
"/gsd-sync-skills",
|
|
"/gsd-thread",
|
|
"/gsd-ui-phase",
|
|
"/gsd-ui-review",
|
|
"/gsd-ultraplan-phase",
|
|
"/gsd-undo",
|
|
"/gsd-update",
|
|
"/gsd-validate-phase",
|
|
"/gsd-verify-work",
|
|
"/gsd-workstreams"
|
|
],
|
|
"workflows": [
|
|
"add-phase.md",
|
|
"add-tests.md",
|
|
"add-todo.md",
|
|
"ai-integration-phase.md",
|
|
"analyze-dependencies.md",
|
|
"audit-fix.md",
|
|
"audit-milestone.md",
|
|
"audit-uat.md",
|
|
"autonomous.md",
|
|
"check-todos.md",
|
|
"cleanup.md",
|
|
"code-review-fix.md",
|
|
"code-review.md",
|
|
"complete-milestone.md",
|
|
"diagnose-issues.md",
|
|
"discovery-phase.md",
|
|
"discuss-phase-assumptions.md",
|
|
"discuss-phase-power.md",
|
|
"discuss-phase.md",
|
|
"do.md",
|
|
"docs-update.md",
|
|
"eval-review.md",
|
|
"execute-phase.md",
|
|
"execute-plan.md",
|
|
"explore.md",
|
|
"extract_learnings.md",
|
|
"fast.md",
|
|
"forensics.md",
|
|
"graduation.md",
|
|
"health.md",
|
|
"help.md",
|
|
"import.md",
|
|
"inbox.md",
|
|
"ingest-docs.md",
|
|
"insert-phase.md",
|
|
"list-phase-assumptions.md",
|
|
"list-workspaces.md",
|
|
"manager.md",
|
|
"map-codebase.md",
|
|
"milestone-summary.md",
|
|
"new-milestone.md",
|
|
"new-project.md",
|
|
"new-workspace.md",
|
|
"next.md",
|
|
"node-repair.md",
|
|
"note.md",
|
|
"pause-work.md",
|
|
"plan-milestone-gaps.md",
|
|
"plan-phase.md",
|
|
"plan-review-convergence.md",
|
|
"plant-seed.md",
|
|
"pr-branch.md",
|
|
"profile-user.md",
|
|
"progress.md",
|
|
"quick.md",
|
|
"remove-phase.md",
|
|
"remove-workspace.md",
|
|
"research-phase.md",
|
|
"resume-project.md",
|
|
"review.md",
|
|
"scan.md",
|
|
"secure-phase.md",
|
|
"session-report.md",
|
|
"settings-advanced.md",
|
|
"settings-integrations.md",
|
|
"settings.md",
|
|
"ship.md",
|
|
"sketch-wrap-up.md",
|
|
"sketch.md",
|
|
"spec-phase.md",
|
|
"spike-wrap-up.md",
|
|
"spike.md",
|
|
"stats.md",
|
|
"sync-skills.md",
|
|
"transition.md",
|
|
"ui-phase.md",
|
|
"ui-review.md",
|
|
"ultraplan-phase.md",
|
|
"undo.md",
|
|
"update.md",
|
|
"validate-phase.md",
|
|
"verify-phase.md",
|
|
"verify-work.md"
|
|
],
|
|
"references": [
|
|
"agent-contracts.md",
|
|
"ai-evals.md",
|
|
"ai-frameworks.md",
|
|
"artifact-types.md",
|
|
"autonomous-smart-discuss.md",
|
|
"checkpoints.md",
|
|
"common-bug-patterns.md",
|
|
"context-budget.md",
|
|
"continuation-format.md",
|
|
"debugger-philosophy.md",
|
|
"decimal-phase-calculation.md",
|
|
"doc-conflict-engine.md",
|
|
"domain-probes.md",
|
|
"executor-examples.md",
|
|
"gate-prompts.md",
|
|
"gates.md",
|
|
"git-integration.md",
|
|
"git-planning-commit.md",
|
|
"ios-scaffold.md",
|
|
"mandatory-initial-read.md",
|
|
"model-profile-resolution.md",
|
|
"model-profiles.md",
|
|
"phase-argument-parsing.md",
|
|
"planner-antipatterns.md",
|
|
"planner-chunked.md",
|
|
"planner-gap-closure.md",
|
|
"planner-reviews.md",
|
|
"planner-revision.md",
|
|
"planner-source-audit.md",
|
|
"planning-config.md",
|
|
"project-skills-discovery.md",
|
|
"questioning.md",
|
|
"revision-loop.md",
|
|
"sketch-interactivity.md",
|
|
"sketch-theme-system.md",
|
|
"sketch-tooling.md",
|
|
"sketch-variant-patterns.md",
|
|
"tdd.md",
|
|
"thinking-models-debug.md",
|
|
"thinking-models-execution.md",
|
|
"thinking-models-planning.md",
|
|
"thinking-models-research.md",
|
|
"thinking-models-verification.md",
|
|
"thinking-partner.md",
|
|
"ui-brand.md",
|
|
"universal-anti-patterns.md",
|
|
"user-profiling.md",
|
|
"verification-overrides.md",
|
|
"verification-patterns.md",
|
|
"workstream-flag.md"
|
|
],
|
|
"cli_modules": [
|
|
"artifacts.cjs",
|
|
"audit.cjs",
|
|
"commands.cjs",
|
|
"config-schema.cjs",
|
|
"config.cjs",
|
|
"core.cjs",
|
|
"docs.cjs",
|
|
"drift.cjs",
|
|
"frontmatter.cjs",
|
|
"graphify.cjs",
|
|
"gsd2-import.cjs",
|
|
"init.cjs",
|
|
"intel.cjs",
|
|
"learnings.cjs",
|
|
"milestone.cjs",
|
|
"model-profiles.cjs",
|
|
"phase.cjs",
|
|
"profile-output.cjs",
|
|
"profile-pipeline.cjs",
|
|
"roadmap.cjs",
|
|
"schema-detect.cjs",
|
|
"secrets.cjs",
|
|
"security.cjs",
|
|
"state.cjs",
|
|
"template.cjs",
|
|
"uat.cjs",
|
|
"verify.cjs",
|
|
"workstream.cjs"
|
|
],
|
|
"hooks": [
|
|
"gsd-check-update-worker.js",
|
|
"gsd-check-update.js",
|
|
"gsd-context-monitor.js",
|
|
"gsd-phase-boundary.sh",
|
|
"gsd-prompt-guard.js",
|
|
"gsd-read-guard.js",
|
|
"gsd-read-injection-scanner.js",
|
|
"gsd-session-state.sh",
|
|
"gsd-statusline.js",
|
|
"gsd-validate-commit.sh",
|
|
"gsd-workflow-guard.js"
|
|
]
|
|
}
|
|
}
|