diff --git a/agents/gsd-security-auditor.md b/agents/gsd-security-auditor.md index 836cfffeb..f045461d2 100644 --- a/agents/gsd-security-auditor.md +++ b/agents/gsd-security-auditor.md @@ -14,7 +14,7 @@ color: "#EF4444" GSD security auditor. Spawned by /gsd:secure-phase to verify that threat mitigations declared in PLAN.md are present in implemented code. -Does NOT scan blindly for new vulnerabilities. Verifies each threat in `` by its declared disposition (mitigate / accept / transfer). Reports gaps. Writes SECURITY.md. +Does NOT scan blindly for new vulnerabilities. Verifies each threat in `` by its declared disposition (mitigate / accept / transfer). Reports gaps. Writes SECURITY.md. **Mandatory Initial Read:** If prompt contains ``, load ALL listed files before any action. @@ -32,7 +32,7 @@ Read ALL files from ``. Extract: -For each threat in ``, determine verification method by disposition: +For each threat in ``, determine verification method by disposition: | Disposition | Verification Method | |-------------|---------------------| diff --git a/get-shit-done/workflows/verify-work.md b/get-shit-done/workflows/verify-work.md index 0c40cde47..57e23dc86 100644 --- a/get-shit-done/workflows/verify-work.md +++ b/get-shit-done/workflows/verify-work.md @@ -394,7 +394,13 @@ All tests passed. Ready to continue. - `/gsd:ui-review {phase}` — visual quality audit (if frontend files were modified) ``` -If `SECURITY_CFG` is `false` OR `SECURITY_FILE` exists (i.e., `threats_open: 0` or review already run): +If `SECURITY_CFG` is `true` AND `SECURITY_FILE` exists: check frontmatter `threats_open`. If > 0: +``` +⚠ Security gate: {threats_open} threats open + /gsd:secure-phase {phase} — resolve before advancing +``` + +If `SECURITY_CFG` is `false` OR (`SECURITY_FILE` exists AND `threats_open` is `0`): ``` All tests passed. Ready to continue.