Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD across contents and paths, upstream package/repo coordinates -> @golem15/msd-core and golem15com/msd-core. Deep links into upstream history, sibling upstream packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is. Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line, package/plugin identity, regenerated lockfile, install-tree fixtures, derived registries and benchmark baseline; migration checksum baseline re-locked (MSD keeps its own install state, so no install had applied the old sums); sort-order and regex-escaped expectations in tests adjusted.
1.3 KiB
1.3 KiB
id, title, group
| id | title | group |
|---|---|---|
| 60 | Security Enforcement | v1.31 Features |
Command: /msd-secure-phase <N>
Purpose: Threat-model-anchored security verification for phase implementations.
Requirements:
- REQ-SEC-01: System MUST perform threat-model-anchored verification (not blind scanning)
- REQ-SEC-02: System MUST support configurable OWASP ASVS verification levels (1-3)
- REQ-SEC-03: System MUST block phase advancement based on configurable severity threshold
- REQ-SEC-04: System MUST spawn
msd-security-auditoragent for analysis
Produces:
| Artifact | Description |
|---|---|
| Security audit report | Threat-model-anchored findings with severity classification |
Process:
- Model — Build threat model from phase implementation context
- Audit — Spawn
msd-security-auditorto verify against threat model - Gate — Block phase advancement if findings meet or exceed
security_block_onseverity
Config:
| Setting | Type | Default | Description |
|---|---|---|---|
security_enforcement |
boolean | true |
Enable threat-model security verification |
security_asvs_level |
number (1-3) | 1 |
OWASP ASVS verification level |
security_block_on |
string | "high" |
Minimum severity to block phase advancement |