Security
Stage ④.e verify sub-workflow — gstack /cso 安全审查 OWASP/auth/secrets (has_auth_or_secrets 触发, 可选 conditional; bundled verify-stage optional /cso step). schema_version: harnessed.workflow.v3 with disciplines_applied (6 default) + tools_available (gstack-cso) + 1 phase (gate ref has_auth_or_secrets conditional)。 Triggered by slash command `/verify-security` after `harnessed setup`.From its SKILL.md
npx -y skills add easyinplay/harnessed --skill securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
4.4 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it
verify-security workflow (v3)
Overview
1-phase sub-workflow mapping CLAUDE.md "Verify 阶段 — 可选 /cso" onto harnessed runtime (Phase v3.0-3.4 W0.13b — D-04 Stage ④ Verify 7 sub + D-12 gstack 治理关卡 + Pattern A sub-workflow ship)。
| phase | id | upstream | model | capability | gate |
|---|---|---|---|---|---|
| 1 | 01-cso | gstack | opus | {{ capabilities.gstack-cso.cmd }} | judgments.stage-routing.verify-security-secrets.fires |
Per-phase config loads from workflows/verify/security/workflow.yaml; engine 4-level gate
resolver evaluates phase.has_auth_or_secrets == true via expr-eval — true 则 invoke gstack
/cso (OWASP / auth / credentials / secrets 全面审查), false 则 skip。
Capability refs
Sister workflows/capabilities.yaml entries:
gstack-cso— Bucket 3 治理关卡 (impl: gstack, cmd: /cso, fires_when: phase.stage == 'verify' AND phase.has_auth_or_secrets == true)
Gate ref
Sister workflows/judgments/stage-routing.yaml:
verify-security-secrets.fires—phase.stage == 'verify' and phase.has_auth_or_secrets == true
Routing rules
- ✅ 触发: auth flow / session / credentials / API keys / SQL injection 路径 / OWASP top 10 area
- ❌ 跳过: docs / 纯 UI styling / 内部 refactor / non-security PR
How to invoke
!harnessed checkpoint intent verify-security
The banner above (when present) means this invocation is REGISTERED with the engine (an intent marker) — not yet compliant: the steps below (prompt → spawn → checkpoint complete) resolve it, and a per-turn
<workflow-intent>reminder persists until they run.
The numbered sequence below is the state machine — execute it with Bash. Do NOT improvise an equivalent flow from the Overview above: freelancing bypasses the engine (no ledger, no evidence guard). harnessed gives you the spawn-ready prompt; YOU spawn the subagent with a CC-native Task / Agent tool (keeps the session responsive + lets clarification round-trips reach the user).
Do NOT pipe to harnessed run verify-security — that is the CI/headless path (in-process SDK spawn
that blocks the session inside Claude Code).
- Bash:
harnessed prompt verify-security --task "$ARGUMENTS" --json→ parse{prompt, max_iterations, model}. - Spawn a CC-native subagent (Task / Agent tool) with that
prompt+model, wrapped in the ralph-loop plugin:/ralph-loop "<prompt>" --max-iterations <max_iterations> --completion-promise "COMPLETE". If the plugin is absent, use the native goal gate instead (Claude Code 2.1.139+ / Codex):/goal "this subtask is delivered: the subagent's final output contains verbatim <promise>COMPLETE</promise>; or stop after <max_iterations> turns"then spawn the subagent and let the goal evaluator drive re-spawns until it clears. If/goalis unavailable too, self-loop: spawn → check output for<promise>COMPLETE</promise>→ re-spawn with prior output appended (up to max_iterations). Set the goal only at the leaf subtask level —/goalis single-slot per session and a nested goal overwrites the outer one. - If the output contains
STATUS: NEEDS_CLARIFICATION+ a question list: STOP, relay them verbatim via AskUserQuestion, append the answers to the spec, then re-spawn the same sub. - On
<promise>COMPLETE</promise>: Bashharnessed checkpoint complete verify-security --summary "<one-line>". The evidence guard runs here (fail-CLOSED): if a declaredartifacts_expectedfile is missing it exits non-zero — re-spawn to produce it before treating the sub as done.
References
- D-04 Stage ④ Verify 7 sub 分解
- D-12 gstack 治理关卡可选
- workflows/capabilities.yaml — gstack-cso
- workflows/judgments/stage-routing.yaml — verify-security-secrets trigger
- workflows/verify-work/workflow.yaml v2 SHIPPED phase 06-cso-conditional sister verbatim
What ships with it: 2 files
6.6 KB alongside SKILL.md
- SKILL.zh-Hans.md4.9 KB
- workflow.yaml1.7 KB