Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD across contents and paths, upstream package/repo coordinates -> @golem15/msd-core and golem15com/msd-core. Deep links into upstream history, sibling upstream packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is. Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line, package/plugin identity, regenerated lockfile, install-tree fixtures, derived registries and benchmark baseline; migration checksum baseline re-locked (MSD keeps its own install state, so no install had applied the old sums); sort-order and regex-escaped expectations in tests adjusted.
33 lines
1.3 KiB
Markdown
33 lines
1.3 KiB
Markdown
---
|
|
id: 60
|
|
title: Security Enforcement
|
|
group: v1.31 Features
|
|
---
|
|
|
|
**Command:** `/msd-secure-phase <N>`
|
|
|
|
**Purpose:** Threat-model-anchored security verification for phase implementations.
|
|
|
|
**Requirements:**
|
|
- REQ-SEC-01: System MUST perform threat-model-anchored verification (not blind scanning)
|
|
- REQ-SEC-02: System MUST support configurable OWASP ASVS verification levels (1-3)
|
|
- REQ-SEC-03: System MUST block phase advancement based on configurable severity threshold
|
|
- REQ-SEC-04: System MUST spawn `msd-security-auditor` agent for analysis
|
|
|
|
**Produces:**
|
|
| Artifact | Description |
|
|
|----------|-------------|
|
|
| Security audit report | Threat-model-anchored findings with severity classification |
|
|
|
|
**Process:**
|
|
1. **Model** — Build threat model from phase implementation context
|
|
2. **Audit** — Spawn `msd-security-auditor` to verify against threat model
|
|
3. **Gate** — Block phase advancement if findings meet or exceed `security_block_on` severity
|
|
|
|
**Config:**
|
|
| Setting | Type | Default | Description |
|
|
|---------|------|---------|-------------|
|
|
| `security_enforcement` | boolean | `true` | Enable threat-model security verification |
|
|
| `security_asvs_level` | number (1-3) | `1` | OWASP ASVS verification level |
|
|
| `security_block_on` | string | `"high"` | Minimum severity to block phase advancement |
|