gsd-secure-phase

Audit security documentation and threat models to verify mitigations for completed project phases.

1|Updated Apr 4, 2026
One-click install
npx skills add https://github.com/nnexai/git-stacks --skill gsd-secure-phase-nnexai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: gsd-secure-phase
Source: https://github.com/nnexai/git-stacks/tree/main/.codex/skills/gsd-secure-phase
Command: npx skills add https://github.com/nnexai/git-stacks --skill gsd-secure-phase-nnexai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the gap in security oversight by retroactively auditing and verifying threat mitigations for completed project phases, ensuring that security requirements were not bypassed or overlooked.

Core Features & Use Cases

  • Automated Audit: Scans for existing security documentation and threat models to validate phase integrity.
  • Workflow Integration: Coordinates with GSD-compliant agent workflows to perform deep-dive verification of security controls.
  • Use Case: Use this after completing a development sprint to ensure all identified threats were properly mitigated and documented in the project's security logs.

Quick Start

Invoke the gsd-secure-phase skill by typing the command followed by the specific phase name you wish to audit.

Frequently Asked Questions about gsd-secure-phase

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I retroactively verify threat mitigations for a completed development sprint?

To retroactively verify threat mitigations for completed project phases, you can audit security documentation and threat models to validate phase integrity and ensure security requirements were not bypassed. This automates the scanning process.

What is retroactive security compliance and artifact validation in software development?

Retroactive security compliance involves auditing completed project phases to verify that identified threats were properly mitigated and documented in security logs. Artifact validation ensures threat models accurately reflect implemented controls.

Do I need GSD workflow agents to perform a phase threat audit?

Yes, executing multi-step verification processes for phase threat audits requires integration with GSD-compliant workflow agents. These agents coordinate the deep-dive verification of security controls and generate updated security reports.

How do I audit security documentation to validate phase integrity?

You audit security documentation by scanning existing threat models and security logs to validate phase integrity. This verifies that all identified threats were properly mitigated during the development lifecycle.

When should I run a retroactive threat mitigation verification in DevSecOps?

You should run retroactive threat mitigation verification after completing a development sprint or project phase. This ensures all identified threats were properly mitigated before moving to the next lifecycle stage.