Bantuson
2154e6bb07
feat: add security-first enforcement layer with threat-model-anchored verification
Adds /gsd:secure-phase command and gsd-security-auditor agent as a
threat-model-anchored security gate parallel to Nyquist validation.
New files:
- agents/gsd-security-auditor.md — verifies PLAN.md threat mitigations
exist in implemented code; SECURED/OPEN_THREATS/ESCALATE returns
- commands/gsd/secure-phase.md — retroactive command, mirrors validate-phase
- get-shit-done/workflows/secure-phase.md — enforcing gate: threats_open > 0
blocks phase advancement; accepted risks log prevents resurface
- get-shit-done/templates/SECURITY.md — per-phase threat register artifact
Modified:
- config.json — security_enforcement (absent=enabled), security_asvs_level,
security_block_on parallel to nyquist_validation pattern
- VALIDATION.md — Threat Ref + Secure Behavior columns in verification map
- gsd-planner.md — <threat_model> block in PLAN.md format + quality gate
- gsd-executor.md — Rule 2 threat model reference + ## Threat Flags scan
- gsd-phase-researcher.md — ## Security Domain mandatory research section
- plan-phase.md — step 5.55 Security Threat Model Gate
- execute-phase.md — security gate announcement in aggregate step
- verify-work.md — /gsd:secure-phase surfaced in completion routing
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:18:30 +02:00
..
2026-03-19 20:08:30 -05:00
2026-03-21 00:21:17 -04:00
2026-03-14 21:25:02 -06:00
2026-03-23 14:05:33 -04:00
2026-03-25 11:18:30 +02:00
2026-03-14 21:25:02 -06:00
2026-03-14 21:25:02 -06:00
2026-03-25 11:18:30 +02:00
2026-03-20 15:41:28 -04:00
2026-03-25 11:18:30 +02:00
2026-03-20 14:53:46 +05:30
2026-03-14 21:25:02 -06:00
2026-03-22 10:15:57 -04:00
2026-03-25 11:18:30 +02:00
2026-03-15 11:49:07 -06:00
2026-03-15 11:49:07 -06:00
2026-03-20 14:53:46 +05:30
2026-03-16 09:46:00 -06:00
2026-03-23 20:20:15 -04:00