From 810409c363626673ee4f894fc20668af8e564d4a Mon Sep 17 00:00:00 2001 From: Lex Christopherson Date: Thu, 8 Jan 2026 12:23:37 -0600 Subject: [PATCH] feat(plan-phase): add planning principles for security, performance, observability Front-load mindset guidance before process steps: - Secure by design: assume hostile input - Performance by design: assume production load - Observable by design: plan for self-debugging Co-Authored-By: Claude Opus 4.5 --- get-shit-done/workflows/plan-phase.md | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/get-shit-done/workflows/plan-phase.md b/get-shit-done/workflows/plan-phase.md index b4b6b3330..079bc8b33 100644 --- a/get-shit-done/workflows/plan-phase.md +++ b/get-shit-done/workflows/plan-phase.md @@ -33,6 +33,14 @@ Decimal phases enable urgent work insertion without renumbering: Create an executable phase prompt (PLAN.md). PLAN.md IS the prompt that Claude executes - not a document that gets transformed. + +**Secure by design:** Assume hostile input on every boundary. Validate, parameterize, authenticate, fail closed. + +**Performance by design:** Assume production load, not demo conditions. Plan for efficient data access, appropriate caching, minimal round trips. + +**Observable by design:** Plan to debug your own work. Include meaningful error messages, appropriate logging, and clear failure states. + +