Use when a hardware design needs security sign-off before tape-out. Defines the builder-to-auditor handoff contract between Foundry (constructive design) and Forge (security review). Covers security review prerequisites, artifact checklist, sign-off criteria, and conditional approval workflow. Do not use for RTL security review itself (use rtl-security-review) or design flow guidance (use foundry/chip-design-flow).
Define the handoff contract between Foundry (builder) and Forge (security auditor) for hardware security sign-off. Ensure all security-critical design artifacts are delivered, reviewed, and approved before tape-out commitment.
Coordinates the handoff process between builder and auditor roles. Does not perform the security review itself (delegates to rtl-security-review, microarch-analysis, physical-design-security). Does not modify design files.
No user-provided values are used in commands or file paths. All inputs are treated as read-only analysis targets.
<!-- Observations appended after each use -->Foundry must deliver the following before security review begins:
Reject handoff if any artifact is missing. Document gaps and return to Foundry.
Dispatch to Forge specialist skills based on scope:
Track review progress per module and per skill.
Document decision with: reviewer, date, scope covered, open items (if conditional), and next review trigger.
Compaction resilience: If context was lost, re-read the Inputs section for the design under review, check the Progress Checklist, then resume from the earliest incomplete step.
| Field | Value |
|---|---|
| Design | ... |
| Reviewer | Forge |
| Date | ... |
| Decision | Approved / Conditional / Blocked |
| Scope | Modules A, B, C |
| Open items | ... |
| ID | Module | Category | Severity | Status | Owner |
|---|---|---|---|---|---|
| F1 | access_ctrl | Bypass | Critical | Fixed | Foundry |
| F2 | debug_if | Leakage | High | Mitigated | Foundry |