| name | gsd-secure-phase |
| description | Retroactively verify threat mitigations for a completed phase |
<augment_skill_adapter>
A. Skill Invocation
- This skill is invoked when the user mentions
gsd-secure-phase or describes a task matching this skill.
- Treat all user text after the skill mention as
{{GSD_ARGS}}.
- If no arguments are present, treat
{{GSD_ARGS}} as empty.
B. User Prompting
When the workflow needs user input, prompt the user conversationally:
- Present options as a numbered list in your response text
- Ask the user to reply with their choice
- For multi-select, ask for comma-separated numbers
C. Tool Usage
Use these Augment tools when executing GSD workflows:
launch-process for running commands (terminal operations)
str-replace-editor for editing existing files
view for reading files and listing directories
save-file for creating new files
grep for searching code (or use MCP servers for advanced search)
web-search, web-fetch for web queries
add_tasks, view_tasklist, update_tasks for task management
D. Subagent Spawning
When the workflow needs to spawn a subagent:
- Use the built-in subagent spawning capability
- Define agent prompts in
.augment/agents/ directory
</augment_skill_adapter>
Verify threat mitigations for a completed phase. Three states:
- (A) SECURITY.md exists — audit and verify mitigations
- (B) No SECURITY.md, PLAN.md with threat model exists — run from artifacts
- (C) Phase not executed — exit with guidance
Output: updated SECURITY.md.
<execution_context>
@/home/delorenj/code/bhappy/.augment/get-shit-done/workflows/secure-phase.md
</execution_context>
Phase: {{GSD_ARGS}} — optional, defaults to last completed phase.
Execute @/home/delorenj/code/bhappy/.augment/get-shit-done/workflows/secure-phase.md.
Preserve all workflow gates.