/security-flow-model-and-select
Phase 4 Model and Select of security-flow
> /plugin marketplace add griddynamics/rosetta > /plugin install rosetta@rosetta
How it fires
How this command gets triggered: by you, by Claude, or both.
- Fires itselfClaude auto-loads it when your prompt matches the work.
- You can call itInvoke it directly when you want it.
- Slash command
/security-flow-model-and-select
Context preview
What this command does when you run it.
Phase 4 Model and Select of security-flow
Command definition
security-flow-model-and-select.mdname: security-flow-model-and-select
description: "Phase 4 Model and Select of security-flow"
disable-model-invocation: true
user-invocable: false
alwaysApply: false
tags: ["security", "workflow-phase"]
baseSchema: docs/schemas/phase.md
<security_flow_model_and_select>
<description_and_purpose> Map attack surface to complete, contextual, authorized security coverage. </description_and_purpose>
<workflow_context> Phase 4. Broad/full reviews require a threat model before inspection. </workflow_context>
<phase_steps> 1. Model attack surface 2. Map applicable areas 3. Select verified tools 4. Define evidence contracts </phase_steps>
<design_coverage step="4.1" subagent="architect" role="Security architect mapping threats to contextual coverage" subagent_required_model="claude-opus-4-8, gpt-5.5-high, gemini-3.1-pro-high, gpt-5.6-sol">
1. USE SKILL `subagent-directives`. 2. USE SKILL `security` for its threat-model contract. 3. Inspect approved source/context only. 4. Identify assets, actors, entry points, trust boundaries, data flows, dependencies, and abuse cases. 5. Map each applicable area to threats and planned evidence. 6. For full review, include every applicable, available, authorized activity/tool. 7. Record exclusions with evidence and residual risk. 8. Verify each proposed tool's operational contract. 9. Update `security-flow-state.md`.
</design_coverage>
<validation_checklist>
- Threats trace to planned areas.
- Every area is included or justified.
- Tool facts are verified and dated.
- Plan stays inside approval.
</validation_checklist>
</security_flow_model_and_select>
Read more
name: security-flow-model-and-select description: "Phase 4 Model and Select of security-flow" disable-model-invocation: true user-invocable: false alwaysApply: false tags: ["security", "workflow-phase"] baseSchema: docs/schemas/phase.md
<security_flow_model_and_select>
<description_and_purpose> Map attack surface to complete, contextual, authorized security coverage. </description_and_purpose>
<workflow_context> Phase 4. Broad/full reviews require a threat model before inspection. </workflow_context>
<phase_steps> 1. Model attack surface 2. Map applicable areas 3. Select verified tools 4. Define evidence contracts </phase_steps>
<design_coverage step="4.1" subagent="architect" role="Security architect mapping threats to contextual coverage" subagent_required_model="claude-opus-4-8, gpt-5.5-high, gemini-3.1-pro-high, gpt-5.6-sol">
1. USE SKILL `subagent-directives`. 2. USE SKILL `security` for its threat-model contract. 3. Inspect approved source/context only. 4. Identify assets, actors, entry points, trust boundaries, data flows, dependencies, and abuse cases. 5. Map each applicable area to threats and planned evidence. 6. For full review, include every applicable, available, authorized activity/tool. 7. Record exclusions with evidence and residual risk. 8. Verify each proposed tool's operational contract. 9. Update `security-flow-state.md`.
</design_coverage>
<validation_checklist>
- Threats trace to planned areas.
- Every area is included or justified.
- Tool facts are verified and dated.
- Plan stays inside approval.
</validation_checklist>
</security_flow_model_and_select>
Repo: griddynamics/rosetta
Other commands on rosetta.
- /adhoc-flow
Workflow for the rest of tasks: lightweight documentation, build, track, synchronize, etc.
Open command - /api-aqa-flow-api-spec-analysis
Phase 2 API Spec Analysis of api-aqa-flow
Open command - /api-aqa-flow-data-collection
Phase 1 Data Collection of api-aqa-flow
Open command - /api-aqa-flow-execution-and-report-analysis
Phase 6 Execution & Report Analysis of api-aqa-flow (USER INTERACTION REQUIRED)
Open command - /api-aqa-flow-gap-and-requirements-clarification
Phase 3 Gap & Requirements Clarification of api-aqa-flow (USER INTERACTION REQUIRED)
Open command - /api-aqa-flow-project-config-loading
Phase 0 Project Config Loading of api-aqa-flow (USER INTERACTION CONDITIONALLY REQUIRED)
Open command

