- gsd-security-auditor.md: replace <threat_register> with <threat_model> (stale tag name inconsistent with every other file in the PR) - verify-work.md: parse threats_open from SECURITY.md frontmatter when file exists; block if > 0, matching execute-phase.md gate logic Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>