Security audit of changes; enforce defense in depth and OWASP best practices
Scanned 9/12/2026
Install to Claude Code
npx -y skills add aibot88/sec_skill_store --skill gsd-secure --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Gsd Secure?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aibot88-gsd-secure)More formats (shields.io, HTML) on the badges page.
---
id: gsd-secure
title: GSD — Security Review
description: Security audit of changes; enforce defense in depth and OWASP best practices
trigger:
- "security review"
- "secure phase"
- "security audit"
---
# GSD — Security Review
## When to Use
Mandatory step before shipping. Run the security quality dimension checklist against all changes.
## Steps
### Step 1: Identify Security-Touching Files
From REVIEW.md or git diff, list files that handle:
- Authentication/authorization
- Data persistence
- External API calls
- User input
- File operations
- Secrets management
### Step 2: Run Security Checklist
Check each security-touching file against the security quality dimension:
- Input validation on all boundaries
- Parameterized queries (no string concatenation)
- Proper output encoding
- Auth/authz checks on every endpoint
- No hardcoded secrets
- Secure defaults
### Step 3: Write SECURITY.md
```
# Security Review — Phase <N>
## Scope
<files reviewed>
## Findings
| ID | File | Issue | Severity | Status |
|----|------|-------|----------|--------|
| SEC-01 | | | | |
## Gate: PASS / FAIL
```
### Step 4: Fix Critical Findings
Any CRITICAL security issue must be fixed before proceeding. MAJOR/MINOR can be logged as technical debt.
## Exit Condition
SECURITY.md exists with Gate: PASS (or all CRITICAL findings fixed).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Complete security architecture overhaul for claude-flow v3. Addresses critical CVEs (CVE-1, CVE-2, CVE-3) and implements secure-by-default patterns. Use for security-first v3 implementation.