Files
msd-core/docs/features/security-enforcement.md
Jakub Zych a9a7a328e6 refactor: hard-fork GSD -> MSD (Make Software Done)
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00

1.3 KiB

id, title, group
id title group
60 Security Enforcement v1.31 Features

Command: /msd-secure-phase <N>

Purpose: Threat-model-anchored security verification for phase implementations.

Requirements:

  • REQ-SEC-01: System MUST perform threat-model-anchored verification (not blind scanning)
  • REQ-SEC-02: System MUST support configurable OWASP ASVS verification levels (1-3)
  • REQ-SEC-03: System MUST block phase advancement based on configurable severity threshold
  • REQ-SEC-04: System MUST spawn msd-security-auditor agent for analysis

Produces:

Artifact Description
Security audit report Threat-model-anchored findings with severity classification

Process:

  1. Model — Build threat model from phase implementation context
  2. Audit — Spawn msd-security-auditor to verify against threat model
  3. Gate — Block phase advancement if findings meet or exceed security_block_on severity

Config:

Setting Type Default Description
security_enforcement boolean true Enable threat-model security verification
security_asvs_level number (1-3) 1 OWASP ASVS verification level
security_block_on string "high" Minimum severity to block phase advancement