fix: address adversarial review — tag name and verify-work gate

- gsd-security-auditor.md: replace <threat_register> with <threat_model>
  (stale tag name inconsistent with every other file in the PR)
- verify-work.md: parse threats_open from SECURITY.md frontmatter when
  file exists; block if > 0, matching execute-phase.md gate logic

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Bantuson
2026-03-26 08:21:03 +02:00
parent 58c9a8ac6c
commit 9f45682aa3
2 changed files with 9 additions and 3 deletions

View File

@@ -14,7 +14,7 @@ color: "#EF4444"
<role>
GSD security auditor. Spawned by /gsd:secure-phase to verify that threat mitigations declared in PLAN.md are present in implemented code.
Does NOT scan blindly for new vulnerabilities. Verifies each threat in `<threat_register>` by its declared disposition (mitigate / accept / transfer). Reports gaps. Writes SECURITY.md.
Does NOT scan blindly for new vulnerabilities. Verifies each threat in `<threat_model>` by its declared disposition (mitigate / accept / transfer). Reports gaps. Writes SECURITY.md.
**Mandatory Initial Read:** If prompt contains `<files_to_read>`, load ALL listed files before any action.
@@ -32,7 +32,7 @@ Read ALL files from `<files_to_read>`. Extract:
</step>
<step name="analyze_threats">
For each threat in `<threat_register>`, determine verification method by disposition:
For each threat in `<threat_model>`, determine verification method by disposition:
| Disposition | Verification Method |
|-------------|---------------------|

View File

@@ -394,7 +394,13 @@ All tests passed. Ready to continue.
- `/gsd:ui-review {phase}` — visual quality audit (if frontend files were modified)
```
If `SECURITY_CFG` is `false` OR `SECURITY_FILE` exists (i.e., `threats_open: 0` or review already run):
If `SECURITY_CFG` is `true` AND `SECURITY_FILE` exists: check frontmatter `threats_open`. If > 0:
```
⚠ Security gate: {threats_open} threats open
/gsd:secure-phase {phase} — resolve before advancing
```
If `SECURITY_CFG` is `false` OR (`SECURITY_FILE` exists AND `threats_open` is `0`):
```
All tests passed. Ready to continue.