SKILL.md
<objective> Verify threat mitigations for a completed phase. Three states:
- (A) SECURITY.md exists — audit and verify mitigations
- (B) No SECURITY.md, PLAN.md with threat model exists — run from artifacts
- (C) Phase not executed — exit with guidance
Output: updated SECURITY.md. </objective>
<executioncontext> @~/.claude/gsd-core/workflows/secure-phase.md </executioncontext>
<context> Phase: $ARGUMENTS — optional, defaults to last completed phase. </context>
<process> Execute end-to-end. Preserve all workflow gates. </process>