From 9f45682aa31ecb11be7cbcc99c07de52b6e714d3 Mon Sep 17 00:00:00 2001 From: Bantuson <152793144+Bantuson@users.noreply.github.com> Date: Thu, 26 Mar 2026 08:21:03 +0200 Subject: [PATCH] =?UTF-8?q?fix:=20address=20adversarial=20review=20?= =?UTF-8?q?=E2=80=94=20tag=20name=20and=20verify-work=20gate?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - gsd-security-auditor.md: replace with (stale tag name inconsistent with every other file in the PR) - verify-work.md: parse threats_open from SECURITY.md frontmatter when file exists; block if > 0, matching execute-phase.md gate logic Co-Authored-By: Claude Sonnet 4.6 --- agents/gsd-security-auditor.md | 4 ++-- get-shit-done/workflows/verify-work.md | 8 +++++++- 2 files changed, 9 insertions(+), 3 deletions(-) diff --git a/agents/gsd-security-auditor.md b/agents/gsd-security-auditor.md index 836cfffeb..f045461d2 100644 --- a/agents/gsd-security-auditor.md +++ b/agents/gsd-security-auditor.md @@ -14,7 +14,7 @@ color: "#EF4444" GSD security auditor. Spawned by /gsd:secure-phase to verify that threat mitigations declared in PLAN.md are present in implemented code. -Does NOT scan blindly for new vulnerabilities. Verifies each threat in `` by its declared disposition (mitigate / accept / transfer). Reports gaps. Writes SECURITY.md. +Does NOT scan blindly for new vulnerabilities. Verifies each threat in `` by its declared disposition (mitigate / accept / transfer). Reports gaps. Writes SECURITY.md. **Mandatory Initial Read:** If prompt contains ``, load ALL listed files before any action. @@ -32,7 +32,7 @@ Read ALL files from ``. Extract: -For each threat in ``, determine verification method by disposition: +For each threat in ``, determine verification method by disposition: | Disposition | Verification Method | |-------------|---------------------| diff --git a/get-shit-done/workflows/verify-work.md b/get-shit-done/workflows/verify-work.md index 0c40cde47..57e23dc86 100644 --- a/get-shit-done/workflows/verify-work.md +++ b/get-shit-done/workflows/verify-work.md @@ -394,7 +394,13 @@ All tests passed. Ready to continue. - `/gsd:ui-review {phase}` — visual quality audit (if frontend files were modified) ``` -If `SECURITY_CFG` is `false` OR `SECURITY_FILE` exists (i.e., `threats_open: 0` or review already run): +If `SECURITY_CFG` is `true` AND `SECURITY_FILE` exists: check frontmatter `threats_open`. If > 0: +``` +⚠ Security gate: {threats_open} threats open + /gsd:secure-phase {phase} — resolve before advancing +``` + +If `SECURITY_CFG` is `false` OR (`SECURITY_FILE` exists AND `threats_open` is `0`): ``` All tests passed. Ready to continue.