Files
msd-core/capabilities/security/capability.json
Jakub Zych a9a7a328e6 refactor: hard-fork GSD -> MSD (Make Software Done)
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00

100 lines
2.3 KiB
JSON

{
"id": "security",
"role": "feature",
"version": "1.14.0",
"title": "Security enforcement",
"description": "Threat mitigation verification and ship-time security blocking for phases with security enforcement enabled.",
"tier": "full",
"requires": [],
"engines": {
"msd": ">=1.6.0"
},
"runtimeCompat": {
"supported": [
"*"
],
"unsupported": []
},
"skills": [
"secure-phase"
],
"agents": [
"msd-security-auditor"
],
"hooks": [],
"config": {
"workflow.security_enforcement": {
"type": "boolean",
"default": true,
"description": "Enable security threat-mitigation verification before phase advancement."
},
"workflow.security_asvs_level": {
"type": "number",
"default": 1,
"description": "OWASP ASVS level used by security review guidance."
},
"workflow.security_block_on": {
"type": "enum",
"values": [
"critical",
"high",
"medium",
"low",
"none"
],
"default": "high",
"description": "Minimum open threat severity that blocks advancement."
}
},
"steps": [
{
"point": "verify:post",
"ref": {
"skill": "secure-phase"
},
"produces": [
"SECURITY.md"
],
"consumes": [
"SUMMARY.md"
],
"when": "workflow.security_enforcement",
"onError": "halt"
}
],
"contributions": [
{
"point": "plan:pre",
"into": "planner",
"fragment": {
"inline": "Each PLAN.md must include a <threat_model> block when security enforcement is active. Use the configured ASVS level and blocking threshold from workflow.security_asvs_level and workflow.security_block_on."
},
"configValues": {
"security_asvs_level": "workflow.security_asvs_level",
"security_block_on": "workflow.security_block_on"
},
"produces": [],
"consumes": [
"CONTEXT.md"
],
"when": "workflow.security_enforcement"
}
],
"gates": [
{
"point": "ship:pre",
"check": {
"predicate": {
"kind": "artifact-frontmatter-equals",
"artifact": "SECURITY.md",
"field": "threats_open",
"equals": 0
}
},
"when": "workflow.security_enforcement",
"blocking": true,
"onError": "halt"
}
]
}