Checks

Reference for AttackTree's sixteen deterministic checks A1 to A16 with severities and fixes, and the ten semantic passes the check command adds.

attacktree.sh check runs sixteen deterministic checks over the tree, tasks.md, the sources, and the configured OTM file. /speckit-attacktree-check prints them and adds ten semantic passes that need judgement. Findings cite a location, such as attack-tree.yaml#goal.forge-ticket or spec.md, and a recommendation.

# Deterministic checks

IDFindsSeverityFix
A1Schema violations, or a missing attack-tree.yamlCRITICALCorrect the field the message names.
A2Dangling references, parent cycles, an attack block on a node with children, effects for a node the control is not attached to, unknown requires tagsCRITICALPoint the reference at an existing id, or add the entity.
A3A goal without any nodeMEDIUMModel its paths, or retire it.
A4A leaf without attack, actors, or complexityHIGHRate the attack vector.
A5An AND or OR node, or an AND goal, with a single childLOWAdd the missing alternative or step, or merge the node into its child.
A6A feasible path to a goal with no control on any of its nodes and no decisionHIGH, CRITICAL for critical-impact goalsAttach a control on the path (a choke point covers every path), or record a decision.
A7A control without a CR-### requirementHIGHDerive a requirement with acceptance scenarios.
A8A requirement without a task in tasks.mdHIGHAdd a task tagged [CR-###].
A9A requirement without verificationLOW before implementation, MEDIUM in progress, MEDIUM or HIGH once its tasks are doneRun converge after implementation.
A10A decision missing owner, rationale, or expiry, or already expired (HIGH); an expiry beyond max_duration_days (MEDIUM)HIGH or MEDIUMComplete, renew, or shorten the decision.
A11spec.md, plan.md, or the OTM file changed since the tree was generated (MEDIUM), or was never hashed (LOW)MEDIUM or LOWRe-run the model command.
A12A control marked verified without a passing verification for all its requirementsHIGHRun converge; statuses follow evidence.
A13A link to a threat or mitigation that is not in the OTM fileMEDIUMFix the link, or refresh the tree after the OTM file changed.
A14A node that needs clarificationMEDIUMAnswer the question with /speckit-clarify, then re-run the model command.
A15An actor without some of skill, resources, access, or risk appetiteMEDIUMRate the missing capabilities.
A16Path enumeration truncated at risk.max_pathsLOWRaise the limit, or split the goal.

Expired decisions protect nothing: A6 and the simulation ignore them. More than three pre-implementation A9 findings are aggregated into one line.

# Exit codes and enforcement

Worst findingwarnstrict
CRITICAL22
HIGH11
MEDIUM01
LOW or none00

Set enforcement in the configuration, or pass --strict for one run. Under strict, the agent also refuses to proceed to /speckit-implement while a CRITICAL finding is open.

# Output formats

md (the default) is the report table. json contains findings, metrics, the worst severity, and the effective enforcement. sarif is SARIF 2.1.0 for GitHub code scanning, with one rule per check ID.

# Semantic passes

The check command’s agent adds these after reading the tree, the spec, the plan, the tasks, the OTM file, the profiles, and the constitution:

PassLooks for
S1 Drift contentwhat changed in the sources that the tree does not reflect yet
S2 Missing pathsentry points, goals, or actors the artifacts imply but the tree lacks
S3 Duplicatesnodes or controls that describe the same step or safeguard
S4 Control fitcontrols that do not address their node, controls far from a choke point, single points of failure on critical goals
S5 Rating plausibilityratings the artifacts contradict, missing requires tags
S6 Requirement and task fituntestable requirements, acceptance that skips the validation steps, tasks that cannot implement the control
S7 ConstitutionMUST principles about security without a goal or control
S8 Decisionsdecisions whose rationale no longer holds
S9 Probabilistic controlsguardrails not marked probabilistic, human approval without context
S10 Wordinggoals phrased as weaknesses, controls without touchpoints or validation steps