Output: updated SECURITY.md.
Gsd Secure Phase
Retroactively verify threat mitigations for a completed phase
Gsd Secure Phase by open-gsd · dfd0b61
npx skillmds@latest add open-gsd/gsd-secure-phase File contents
---name: gsd-secure-phasedescription: Retroactively verify threat mitigations for a completed phase---
<objective>
Verify threat mitigations for a completed phase. Three states:
- (A) SECURITY.md exists — audit and verify mitigations
- (B) No SECURITY.md, PLAN.md with threat model exists — run from artifacts
- (C) Phase not executed — exit with guidance
Output: updated SECURITY.md.
</objective>
<execution_context>
@~/.claude/gsd-core/workflows/secure-phase.md
</execution_context>
<context>
Phase: $ARGUMENTS — optional, defaults to last completed phase.
</context>
<process>
Execute end-to-end.
Preserve all workflow gates.
</process>
open-gsd/gsd-core commit dfd0b61271
Frequently asked questions
Run npx skillmds@latest add open-gsd/gsd-secure-phase in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Retroactively verify threat mitigations for a completed phase It is listed under Security on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Capability flags: docs only. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
open-gsd (@open-gsd) published this skill. Their other Agent Skills are listed on their SkillMD profile.