Skip to content
Back to skills

Gsd Secure

ASecurity

Security audit of changes; enforce defense in depth and OWASP best practices

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 12, 2026
securitygitapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 12, 2026

npx -y skills add aibot88/sec_skill_store --skill gsd-secure --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gsd Secure?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Gsd Secure
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aibot88-gsd-secure/badge)](https://www.skillsdirectory.com/skills/aibot88-gsd-secure)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
id: gsd-secure
title: GSD — Security Review
description: Security audit of changes; enforce defense in depth and OWASP best practices
trigger:
  - "security review"
  - "secure phase"
  - "security audit"
---

# GSD — Security Review

## When to Use
Mandatory step before shipping. Run the security quality dimension checklist against all changes.

## Steps

### Step 1: Identify Security-Touching Files
From REVIEW.md or git diff, list files that handle:
- Authentication/authorization
- Data persistence
- External API calls
- User input
- File operations
- Secrets management

### Step 2: Run Security Checklist
Check each security-touching file against the security quality dimension:
- Input validation on all boundaries
- Parameterized queries (no string concatenation)
- Proper output encoding
- Auth/authz checks on every endpoint
- No hardcoded secrets
- Secure defaults

### Step 3: Write SECURITY.md
```
# Security Review — Phase <N>

## Scope
<files reviewed>

## Findings

| ID | File | Issue | Severity | Status |
|----|------|-------|----------|--------|
| SEC-01 | | | | |

## Gate: PASS / FAIL
```

### Step 4: Fix Critical Findings
Any CRITICAL security issue must be fixed before proceeding. MAJOR/MINOR can be logged as technical debt.

## Exit Condition
SECURITY.md exists with Gate: PASS (or all CRITICAL findings fixed).

Files in this skill

  • SKILL.md1.3 KB
  • source.json573 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…