gsd-headless
Orchestrate GSD (Git Ship Done) projects programmatically via headless CLI. Use when an agent…
Threat-model-driven security review of a change, feature, or subsystem. Runs a STRIDE-style pass over the actual code and produces a filing-ready report with severity, exploit scenario, and remediation. Use when asked to "security review", "threat model", "check for
$ npx -y skills add open-gsd/gsd-pi --skill security-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-reviewContext preview
The summary Claude sees to decide when to auto-load this skill.
Threat-model-driven security review of a change, feature, or subsystem. Runs a STRIDE-style pass over the actual code and produces a filing-ready report with severity, exploit scenario, and remediation. Use when asked to "security review", "threat model", "check for
name: security-review description: Threat-model-driven security review of a change, feature, or subsystem. Runs a STRIDE-style pass over the actual code and produces a filing-ready report with severity, exploit scenario, and remediation. Use when asked to "security review", "threat model", "check for vulnerabilities", "audit for security", "secure this", or before shipping changes touching auth, input handling, data access, or external surfaces.
<objective> Produce a security review that names specific exploit paths through the actual code — not a generic checklist. The deliverable is a prioritized list of findings, each with: where the issue lives, the threat category, a concrete exploit scenario, severity, and a remediation the caller can implement. Read-only: does not modify code. </objective>
<context> gsd-pi's general `review` skill covers security as one of several categories. This skill is the deeper pass — triggered deliberately when security is the primary concern. It complements v1's `/gsd-secure-phase` concept, adapted to the gsd-pi artifact model.
Invocation points:
Do NOT use for:
</context>
<core_principle> **CODE BEFORE CHECKLISTS.** A threat model that doesn't read the code is theater. Find the actual input source, the actual validation (or absence), the actual sink. Cite file:line for every finding.
**THREAT, NOT HYPOTHETICAL.** "SQL injection is possible in theory" is useless. "If an attacker passes `' OR 1=1--` to `getUser(name)` at `src/db/users.ts:42`, the query becomes `SELECT … WHERE name='' OR 1=1--'`, returning every row" is actionable.
**READ-ONLY.** Don't patch while reviewing — you conflate reviewer and author and lose the audit trail. Report, let the user act. </core_principle>
<process>
Identify what to review:
If the scope is vague, ask one round of clarifying questions (1–3 questions). Otherwise proceed.
Before STRIDE: identify every untrusted entry point in the scope:
For each, note: who can reach this surface? (public internet, authenticated user, same-host process, admin-only).
For each attack surface, walk STRIDE:
Use `Agent(subagent_type=Explore)` in parallel if the scope is large — one sub-agent per STRIDE category over the same surface list.
If the scope includes web surfaces, confirm against the top OWASP patterns that STRIDE doesn't cleanly cover:
For each present, find the code path. Same standard: cite file:line.
For each finding, assign:
Severity × Exploitability = priority. Sort findings by priority.
## Security Review — <scope> ### Summary <1–3 sentences — biggest finding and overall posture> ### Findings #### CRITICAL-1: SQL injection in `getUser` **Location:** `src/db/users.ts:42` **Category:** Tampering / Info disclosure (STRIDE) + OWASP A03 Injection **Exploit:** Passing `' OR 1=1--` to the `name` parameter produces the query `SELECT * FROM users WHERE name='' OR 1=1--'`, returning every row. `name` arrives from `POST /api/search` without validation. **Reachability:** Remote unauthenticated (endpoint has no auth). **Remediation:** Use a parameterized query. The codebase's `db.prepare` helper at `src/
GSD Pi is a local-first coding agent for planning, implementing, verifying, and tracking project work from the command line.
Repo: open-gsd/gsd-pi
Orchestrate GSD (Git Ship Done) projects programmatically via headless CLI. Use when an agent…
Audit and improve web accessibility following WCAG 2.1 guidelines. Use when asked to "improve…
Browser automation CLI for AI agents. Use when interacting with websites — navigating pages,…
Design or review an HTTP/REST/GraphQL API for versioning, pagination, error shapes,…
Apply modern web development best practices for security, compatibility, and code quality.…
Ask a quick side question about your current work without derailing the main task. Answers…