Skip to content
Development
Skill

/gsd-secure-phase

Use to re-verify the threat mitigations of a phase that already shipped, or when the user asks to audit SECURITY.md. Audits an existing SECURITY.md, runs from a PLAN.md threat model, or exits if the phase never ran.

From plugin
coco
386200 skills53 agents41 commands
Install
$ npx -y skills add coco-research/coco --skill gsd-secure-phase --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/gsd-secure-phase

Context preview

The summary Claude sees to decide when to auto-load this skill.

Use to re-verify the threat mitigations of a phase that already shipped, or when the user asks to audit SECURITY.md. Audits an existing SECURITY.md, runs from a PLAN.md threat model, or exits if the phase never ran.

SKILL.md

gsd-secure-phase.SKILL.md
name: gsd-secure-phase
description: "Use to re-verify the threat mitigations of a phase that already shipped, or when the user asks to audit SECURITY.md. Audits an existing SECURITY.md, runs from a PLAN.md threat model, or exits if the phase never ran."
argument-hint: "[phase number]"
allowed-tools:
  - Read
  - Write
  - Edit
  - Bash
  - Glob
  - Grep
  - Task
  - AskUserQuestion

<objective> Verify threat mitigations for a completed phase. Three states:

  • (A) SECURITY.md exists — audit and verify mitigations
  • (B) No SECURITY.md, PLAN.md with threat model exists — run from artifacts
  • (C) Phase not executed — exit with guidance

Output: updated SECURITY.md. </objective>

<execution_context> @$HOME/.claude/get-shit-done/workflows/secure-phase.md </execution_context>

<context> Phase: $ARGUMENTS — optional, defaults to last completed phase. </context>

<process> Execute @$HOME/.claude/get-shit-done/workflows/secure-phase.md. Preserve all workflow gates. </process>

Ships withcoco

CoCo Super Intelligence is the orchestration layer that turns Claude Code, Cursor, or Codex into an engineering department: a routed advisory board, 226 skills, 386 commands, persistent state. Local. Open-core — MIT core; Super Intelligence is proprietary, own-use.

Get the whole plugin

Other skills on coco.