gsd-secure-phase

Automate retroactive verification of threat mitigations for completed project phases.

Updated Apr 22, 2025
One-click install
npx skills add https://github.com/mcampbellr/.dotfiles --skill gsd-secure-phase-mcampbellr
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gsd-secure-phase
Source: https://github.com/mcampbellr/.dotfiles/tree/main/claude/.claude/skills/gsd-secure-phase
Command: npx skills add https://github.com/mcampbellr/.dotfiles --skill gsd-secure-phase-mcampbellr

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Automates the verification of threat mitigations after completing a project phase, ensuring security protocols are in place.

Core Features & Use Cases

  • Security Audit: Checks if necessary security measures are in place after phase completion.
  • Automated Threat Analysis: Evaluates mitigations using artifacts or documentation, if required.
  • Exit with Guidance: If the phase has not been executed or issues found, guides on how to proceed.
  • Update Security Record: Provides output on SECURITY.md reflecting the phase status and necessary changes.

Quick Start

Verify the security measures for phase 5 with !gsd-secure-phase 5.

Frequently Asked Questions about gsd-secure-phase

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I verify threat mitigations after completing a project phase?

To verify threat mitigations for phase completion, you can automate a security audit that evaluates project documentation and artifacts to confirm security measures are in place. This generates a security status report and guidance for any unresolved issues.

What is retroactive security verification for project phases?

Retroactive security verification is an automated threat analysis process that checks completed project phases against documentation and artifacts. It ensures security protocols were properly executed and provides guidance if issues are found.

Do I need workflow documentation to perform a security audit on a completed phase?

Yes, you need access to workflow documentation and artifacts to perform an automated security audit. The verification process relies on evaluating these artifacts to check if necessary security measures are in place after phase completion.

Can I update SECURITY.md automatically after completing a phase audit?

Yes, an automated security audit can provide output to update your SECURITY.md file. This reflects the current phase status, verifies threat mitigations, and documents any necessary changes or unresolved security issues.

What happens if a phase has not been executed or security issues are found during verification?

If the phase has not been executed or security issues are found during verification, the audit exits with guidance. It provides specific instructions on how to proceed with resolving the identified threat mitigation gaps.