Skip to content

Define one security rubric for planning, implementation, and review #8361

Description

@jyaunches

Outcome

One canonical security resource owns the NemoClaw security categories, trust-boundary questions, names, meanings, and expected evidence across the software lifecycle.

Scope

  • Extract the stage-neutral security rubric from the procedural security-review skill.
  • Use System Security as the canonical ninth category and remove the competing Holistic Security Posture name.
  • Make current implementation discovery, issue planning, issue implementation, the procedural security review, and the PR Review Advisor consume the same rubric.
  • Keep PR resolution, checkout, review execution, PASS or WARNING or FAIL decisions, and report formatting in the security-review workflow.
  • Make the Advisor load the rubric from its trusted checkout while keeping dynamic skill loading disabled.
  • Remove the Advisor fallback rubric and the embedding of the entire procedural security skill.

Acceptance criteria

  • Exactly nine canonical categories and their evidence expectations have one owner.
  • Planning identifies applicable risks and controls, implementation records negative evidence, and review independently evaluates the completed change.
  • The security-review skill and Advisor use identical category names and meanings.
  • Category nine round-trips as System Security without being discarded or replaced.
  • Missing or malformed trusted rubric input produces visible Advisor failure artifacts.
  • This change includes its own rubric round-trip, trusted-loading, and no-fallback tests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions