Gsd secure phase
Skill coco-research/coco/systems/gsd/skills/gsd-secure-phase
Meet Coco. A superintelligent agent framework powered by an advisory board of 389 world-class minds. Scale your AI assistant into a complete engineering department with 142 skills, 277 commands, and persistent state. Universal compatibility. Local privacy. Free and open source.
npx -y skills add coco-research/coco --skill gsd-secure-phaseAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
What its author says it does
Copied from the file, not written here
Retroactively verify threat mitigations for a completed phase
SKILL.md
0.8 KB, 143 tokens by cl100k_base, as published. Nobody here has run it
Output: updated SECURITY.md. </objective>
<execution_context> @$HOME/.claude/get-shit-done/workflows/secure-phase.md </execution_context>
<context> Phase: $ARGUMENTS — optional, defaults to last completed phase. </context> <process> Execute @$HOME/.claude/get-shit-done/workflows/secure-phase.md. Preserve all workflow gates. </process>Gives 0 of the 12 instructions most security skills give in 143 tokens
Counted across 648 of the 828 authors here whose files we hold, read 2026-08-06
- parameterize all database queriesin 67 of 648, across 49 files
- hash passwords using bcrypt scrypt or argon2in 48 of 648, across 35 files
- apply rate limiting to authentication endpointsin 48 of 648, across 24 files
- Configure security headersin 35 of 648, across 18 files
- validate all inputsin 32 of 648, across 24 files
- validate all external input at the system boundaryin 29 of 648, across 18 files
- run containers as a non-root userin 28 of 648, across 15 files
- use httponly secure samesite cookies for sessionsin 26 of 648, across 15 files
- run dependency audits before every releasein 21 of 648, across 10 files
- encode output to prevent cross-site scriptingin 21 of 648, across 10 files
- copy dependencies before source codein 20 of 648, across 9 files
- store secrets in environment variablesin 20 of 648, across 17 files
Said here and by no other author read
- execute the secure-phase workflow
- run from artifacts if threat model exists
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.