gstack/scripts
Abhijeet Mahagaonkar f7bde4391d feat: add stakeholder lens layer V0.5 (opt-in via --lens)
Ships an opt-in stakeholder-lens layer on /review that runs after the
technical Review Army completes. Zero --lens = zero behavior change.

Core framing: a lens is a loss function, an evidence model, a
materiality threshold, and an escalation policy applied to a bounded
evidence set. Not stakeholder impersonation.

Two lenses in this release:
- insider-abuse (READY) — legitimate authority converted to unauthorized
  outcome without attribution, detection, or approval
- enterprise-readiness (DRAFT) — deployability under CISO / procurement /
  operations governance; ships as DRAFT pending its own Go/No-Go eval

Four additional lens specifications ship in DRAFT / DEFERRED status for
future evaluation: incentive-abuse, regulatory-defensibility,
investor-diligence, competitive-durability.

Design guarantees:
- Preserves Review Army unchanged (P1); no touching of review-army.ts,
  review/specialists/, or review/checklist.md
- Independent lens dispatch (Stage A, no tech findings) followed by
  deterministic reconciliation (Stage B) — clean incremental-value
  measurement
- CTO synthesis as a third stage (not another lens): identifies shared
  technical primitives across independently derived lens findings
  without collapsing distinct perspectives
- Evidence clustering (SHARED_EVIDENCE / MULTI_LENS / EVIDENCE_CLUSTER)
  replaces cross-lens 'confirmation'; production exact-match misses are
  not marked NOVEL
- Read-only tool boundary; lens subagents receive a bounded evidence
  bundle, never repository browse tools
- All stakeholder findings default to ASK / INVESTIGATE; autofix_policy
  ask_always on every lens (no stakeholder auto-fix)
- Append-only event log at ~/.gstack/projects/<slug>/lens-events.jsonl
  with stable finding IDs; sensitive-data controls (local-only,
  owner-only permissions, secret-scanned, GBrain opt-in only)
- Per-lens regression harness (9 fixture types per lens) and per-lens
  Go/No-Go criteria for lens graduation to READY

Insider-abuse ships as the Phase 1 validation lens. Enterprise-readiness
remains DRAFT until its own evaluation gate runs. No Phase 1 lens is
claimed as empirically validated in this PR — validation happens
post-merge per REVIEW_LENSES_V0.md Go/No-Go criteria.

Includes:
- review/lenses/{shared-behavior, registry, insider-abuse, enterprise-readiness,
  incentive-abuse, regulatory-defensibility, investor-diligence,
  competitive-durability}.md
- scripts/lenses/{bundle, events, parser, reconcile, registry, routing,
  synthesis, types, yaml-subset, index}.ts
- scripts/resolvers/lens-layer.ts + gen-skill-docs wiring in
  scripts/gen-skill-docs.ts and scripts/resolvers/index.ts
- bin/gstack-lens-{bundle, event, parse, reconcile, registry, route,
  stats, synthesis-validate}
- hosts/claude/agents/{gstack-cto-synthesizer, gstack-lens-output-validator,
  gstack-lens-reviewer}.md
- test/fixtures/lens-regression/{insider-abuse, enterprise-readiness}/cases.json
- test/lens-{registry, bundle, events, layer-resolver, regression-fixtures}.test.ts
- docs/designs/REVIEW_LENSES_V0.md + docs/{product-context, lens-policy}.yaml.example
- setup and bin/gstack-uninstall wired for lens artifacts
2026-07-31 03:17:44 -07:00
..
app feat: GStack Browser — double-click AI browser with anti-bot stealth (#695) 2026-04-04 10:17:05 -07:00
host-adapters feat: declarative multi-host platform + OpenCode, Slate, Cursor, OpenClaw (v0.15.5.0) (#793) 2026-04-04 15:32:20 -07:00
lenses feat: add stakeholder lens layer V0.5 (opt-in via --lens) 2026-07-31 03:17:44 -07:00
resolvers feat: add stakeholder lens layer V0.5 (opt-in via --lens) 2026-07-31 03:17:44 -07:00
analytics.ts
…
archetypes.ts feat: gstack v1 — simpler prompts + real LOC receipts (v1.0.0.0) (#1039) 2026-04-18 15:05:42 +08:00
brain-cache-spec.ts v1.52.1.0 feat: brain-aware planning — 5 skills read structured gbrain context before asking (#1742) 2026-05-29 08:35:00 -07:00
build-app.sh v1.41.1.0 fix wave: 7 HIGH bugs from external audit + regression tests (PR #1169 follow-up) (#1592) 2026-05-20 06:56:41 -07:00
build.sh v1.42.0.0 Daegu wave: 23 community-filed bugs + PTY classifier enforcement (24 bisect commits) (#1594) 2026-05-20 07:35:01 -07:00
capture-baseline.ts v1.46.0.0 feat: gstack v2 foundation — catalog tokens drop 56%, eval-first floor covers all 51 skills (#1712) 2026-05-26 16:50:03 -07:00
compare-pr-version.ts v1.16.0.0 feat: tunnel allowlist 17→26 + canDispatchOverTunnel pure function (#1253) 2026-04-28 00:57:28 -07:00
declared-annotation.ts v1.52.0.0 feat(plan-tune): explicit consent + first-run setup wizard for contributors (#1741) 2026-05-28 18:21:09 -07:00
detect-bump.ts v1.11.0.0 feat(ship): workspace-aware version allocation (#1168) 2026-04-23 23:03:27 -07:00
dev-skill.ts v1.57.9.0 feat: source-clean gbrain render (dev-setup --out-dir + machine-wide gbrain-refresh) (#1951) 2026-06-09 22:29:23 -07:00
discover-skills.ts v1.54.0.0 feat: carve /ship into skeleton + on-demand sections (-59% always-loaded) (#1806) 2026-05-30 12:09:10 -07:00
eval-compare.ts
…
eval-list.ts fix(eval): validate eval list limit 2026-07-14 12:56:08 -07:00
eval-select.ts
…
eval-summary.ts
…
eval-watch.ts
…
garry-output-comparison.ts fix: remove hardcoded author emails from throughput script 2026-04-18 15:36:50 +08:00
gen-llms-txt.ts v1.28.0.0 feat: browse --headed/--proxy/--navigate + gstack/llms.txt + webdriver-only stealth (#1363) 2026-05-07 20:14:59 -07:00
gen-skill-docs.ts feat: add stakeholder lens layer V0.5 (opt-in via --lens) 2026-07-31 03:17:44 -07:00
gstack-schema-pack.ts v1.52.1.0 feat: brain-aware planning — 5 skills read structured gbrain context before asking (#1742) 2026-05-29 08:35:00 -07:00
host-config-export.ts fix(hosts): validate suppressed resolver names 2026-07-14 12:56:10 -07:00
host-config.ts fix(hosts): validate suppressed resolver names 2026-07-14 12:56:10 -07:00
jargon-list.json feat: gstack v1 — simpler prompts + real LOC receipts (v1.0.0.0) (#1039) 2026-04-18 15:05:42 +08:00
models.ts feat(v1.5.2.0): Opus 4.7 migration — model overlay, voice, routing (#1117) 2026-04-22 01:06:22 -07:00
one-way-doors.ts fix(safety): classify credential actions consistently 2026-07-14 12:56:10 -07:00
preflight-agent-sdk.ts v1.39.2.0 feat: GSTACK_* env-shim for Conductor + gbrain/gstack setup docs (#1534) 2026-05-16 12:32:33 -07:00
proactive-suggestions.json v1.58.5.0 feat: first-run activation scaffold + gstack router front door (#2078) 2026-06-25 09:42:45 -07:00
psychographic-signals.ts v1.52.0.0 feat(plan-tune): explicit consent + first-run setup wizard for contributors (#1741) 2026-05-28 18:21:09 -07:00
question-registry.ts v1.52.0.0 feat(plan-tune): explicit consent + first-run setup wizard for contributors (#1741) 2026-05-28 18:21:09 -07:00
setup-scc.sh feat: gstack v1 — simpler prompts + real LOC receipts (v1.0.0.0) (#1039) 2026-04-18 15:05:42 +08:00
skill-check.ts v1.15.0.0 feat: slim preamble + real-PTY plan-mode E2E harness (#1215) 2026-04-26 13:55:13 -07:00
slop-diff.ts security: tunnel dual-listener + SSRF + envelope + path wave (v1.6.0.0) (#1137) 2026-04-21 21:58:27 -07:00
task-emission-schema.ts v1.38.1.0 fix wave: surrogate-safe page captures (#1440), Implementation Tasks across review skills (#1454), root-level artifact patterns (#1452) (#1504) 2026-05-14 21:46:50 -07:00
test-free-shards.ts v1.24.0.0 feat: cross-platform hardening — curated Windows lane + Bun.which resolver + path-portability helper (#1252) 2026-05-01 07:21:28 -07:00
update-readme-throughput.ts feat: gstack v1 — simpler prompts + real LOC receipts (v1.0.0.0) (#1039) 2026-04-18 15:05:42 +08:00
write-version-files.sh v1.42.0.0 Daegu wave: 23 community-filed bugs + PTY classifier enforcement (24 bisect commits) (#1594) 2026-05-20 07:35:01 -07:00