Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD across contents and paths, upstream package/repo coordinates -> @golem15/msd-core and golem15com/msd-core. Deep links into upstream history, sibling upstream packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is. Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line, package/plugin identity, regenerated lockfile, install-tree fixtures, derived registries and benchmark baseline; migration checksum baseline re-locked (MSD keeps its own install state, so no install had applied the old sums); sort-order and regex-escaped expectations in tests adjusted.
37 lines
805 B
Markdown
37 lines
805 B
Markdown
---
|
|
name: msd:secure-phase
|
|
description: Retroactively verify threat mitigations for a completed phase
|
|
argument-hint: "[phase number]"
|
|
allowed-tools:
|
|
- Read
|
|
- Write
|
|
- Edit
|
|
- Bash
|
|
- Glob
|
|
- Grep
|
|
- Agent
|
|
- AskUserQuestion
|
|
requires: [phase]
|
|
---
|
|
<objective>
|
|
Verify threat mitigations for a completed phase. Three states:
|
|
- (A) SECURITY.md exists — audit and verify mitigations
|
|
- (B) No SECURITY.md, PLAN.md with threat model exists — run from artifacts
|
|
- (C) Phase not executed — exit with guidance
|
|
|
|
Output: updated SECURITY.md.
|
|
</objective>
|
|
|
|
<execution_context>
|
|
@~/.claude/msd-core/workflows/secure-phase.md
|
|
</execution_context>
|
|
|
|
<context>
|
|
Phase: $ARGUMENTS — optional, defaults to last completed phase.
|
|
</context>
|
|
|
|
<process>
|
|
Execute end-to-end.
|
|
Preserve all workflow gates.
|
|
</process>
|