<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security and risk | SpecDD</title><link>https://specdd.ai/how-to/security-and-risk/</link><description>Spec-driven development security and risk guides for agent authority, security constraints, forbidden dependencies, authentication, privacy, secrets, audit logging, and review.</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://specdd.ai/how-to/security-and-risk/index.xml" rel="self" type="application/rss+xml"/><item><title>How to use SpecDD to limit agent risk</title><link>https://specdd.ai/how-to/security-and-risk/how-to-use-specdd-to-limit-agent-risk/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-use-specdd-to-limit-agent-risk/</guid><description>Limit AI coding agent risk with spec-driven development by defining write authority, readable context, Must not rules, Forbids entries, review gates, and verification evidence.</description></item><item><title>How to write security constraints in specs</title><link>https://specdd.ai/how-to/security-and-risk/how-to-write-security-constraints-in-specs/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-write-security-constraints-in-specs/</guid><description>Write security constraints in SpecDD specs for spec-driven development using Must, Must not, Forbids, ownership, interface contracts, scenarios, and Done when evidence.</description></item><item><title>How to prevent agents from adding forbidden dependencies</title><link>https://specdd.ai/how-to/security-and-risk/how-to-prevent-agents-from-adding-forbidden-dependencies/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-prevent-agents-from-adding-forbidden-dependencies/</guid><description>Prevent AI agents from adding forbidden dependencies with spec-driven development Forbids entries, dependency direction rules, static checks, review gates, and focused prompts.</description></item><item><title>How to spec authentication boundaries</title><link>https://specdd.ai/how-to/security-and-risk/how-to-spec-authentication-boundaries/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-spec-authentication-boundaries/</guid><description>Specify authentication boundaries with spec-driven development by naming the identity owner, trusted inputs, failure behavior, bypass rules, dependencies, scenarios, and checks.</description></item><item><title>How to spec data privacy requirements</title><link>https://specdd.ai/how-to/security-and-risk/how-to-spec-data-privacy-requirements/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-spec-data-privacy-requirements/</guid><description>Specify data privacy requirements with spec-driven development by documenting protected data, access rules, retention, redaction, deletion, logging limits, scenarios, and verification.</description></item><item><title>How to review security-sensitive changes with SpecDD</title><link>https://specdd.ai/how-to/security-and-risk/how-to-review-security-sensitive-changes-with-specdd/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-review-security-sensitive-changes-with-specdd/</guid><description>Review security-sensitive changes with spec-driven development by checking governing specs, write authority, Must not and Forbids rules, risk, tests, logs, secrets, and audit evidence.</description></item><item><title>How to use SpecDD for risk classification</title><link>https://specdd.ai/how-to/security-and-risk/how-to-use-specdd-for-risk-classification/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-use-specdd-for-risk-classification/</guid><description>Use spec-driven development for change risk classification by checking authority, constraints, security surfaces, data impact, dependencies, verification, and review needs.</description></item><item><title>How to create a secure coding bootstrap file</title><link>https://specdd.ai/how-to/security-and-risk/how-to-create-a-secure-coding-bootstrap-file/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-create-a-secure-coding-bootstrap-file/</guid><description>Create secure coding bootstrap rules for spec-driven development in .specdd/bootstrap.project.md with shared security review expectations, commands, dependency policy, secrets rules, and risk gates.</description></item><item><title>How to spec secrets handling</title><link>https://specdd.ai/how-to/security-and-risk/how-to-spec-secrets-handling/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-spec-secrets-handling/</guid><description>Specify secrets handling with spec-driven development by documenting secret loading, storage, passing, rotation expectations, logging rules, forbidden access, and verification.</description></item><item><title>How to spec audit logging</title><link>https://specdd.ai/how-to/security-and-risk/how-to-spec-audit-logging/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-spec-audit-logging/</guid><description>Specify audit logging with spec-driven development by naming security-sensitive events, required fields, forbidden sensitive data, failure handling, scenarios, and verification evidence.</description></item><item><title>How to spec rate limiting and abuse prevention</title><link>https://specdd.ai/how-to/security-and-risk/how-to-spec-rate-limiting-and-abuse-prevention/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-spec-rate-limiting-and-abuse-prevention/</guid><description>Specify rate limiting and abuse prevention with spec-driven development by defining enforcement points, limit keys, responses, bypass rules, observability, scenarios, and tests.</description></item><item><title>How to spec payment or billing safety rules</title><link>https://specdd.ai/how-to/security-and-risk/how-to-spec-payment-or-billing-safety-rules/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-spec-payment-or-billing-safety-rules/</guid><description>Specify payment and billing safety rules with spec-driven development for authorization, idempotency, double-charge prevention, refunds, rollback behavior, audit logs, and review.</description></item><item><title>How to prevent agents from weakening security checks</title><link>https://specdd.ai/how-to/security-and-risk/how-to-prevent-agents-from-weakening-security-checks/</link><guid>https://specdd.ai/how-to/security-and-risk/how-to-prevent-agents-from-weakening-security-checks/</guid><description>Prevent agents from weakening security checks with spec-driven development guardrails for validation, authorization, secrets, dependency boundaries, CI gates, and review evidence.</description></item></channel></rss>