sdlc

审查 · 54
已收录

Full SDLC workflow for implementing features, fixing bugs, refactoring code, testing, releasing, publishing, and deploying. Use this skill when implementing, fixing, refactoring, testing, adding features, building new code, or releasing/publishing/deploying.

Verified installs0
Stars44
版本1.0.0
质量58/100 · 有潜力
信任54/100 · Do not auto-install
审计70/100 · 需审查

供给资产档案

编程与开发 Agent

代码审查、仓库分析、测试、CI、GitHub、DevOps 与开发工作流 Skill。

浏览赛道

场景

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

适配 Agent

Claude Code + OpenAI Agents + CLI

适用于 Codex、Claude Code、Cursor、CLI 或自定义 Agent。

安装

就绪

npx skills add BaseInfinity/claude-sdlc-harness --skill sdlc

维护状态

新鲜

今天有推送

风险

需审查

许可证不清晰

GitHub 质量

44

58/100 质量 · 62/100 信任

覆盖标签

编程GitHub automation设计与创意agent-skill

审查说明

许可证不清晰 · Dependency or permission surface needs review

Agent 采用评分卡

一眼查看信任、审计与安装准备度

这些分数综合公开仓库元数据、OpenAgentSkill 审查信号、维护新鲜度与安装准备度。它用于候选筛选,不替代人工审查。

质量

有潜力
58

有用的候选项,但采用前应与替代方案比较。

信任

Do not auto-install
54

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

审计

需审查
70

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

OpenAgentSkill 信任评分 v5

安装前需人工审查

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

44 个 GitHub Stars

仓库活跃度

44 个 Star,6 个 Fork

维护状态

今天有推送

许可证

未知

安装

npx skills add BaseInfinity/claude-sdlc-harness --skill sdlc

安装安全性

标准软件包或运行时安装路径

权限范围

secrets or environment access, shell or command execution

Agent 结果

暂未有 Agent 结果数据

文档

README/SKILL.md 上下文充分

风险摘要

生产前审查

  • Repository license is unknown; no explicit license file or declaration in SKILL.md.
  • 许可证不清晰
  • Low GitHub adoption signal
  • Quality score needs review

安装准备度

安装路径可用

  • 安装路径可用
  • 仓库证据可用
  • 许可证不清晰
  • 暂无 Agent 验证结果证据

Agent 可读元数据

这个 Skill 的机器可读决策数据。

使用此区块或内嵌 JSON 判断 Agent 是否应安装该 Skill、选择替代方案,或先请求人工审查。

打开 JSON

适用任务

  • 研究 Agent 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects
  • 检索来源

适用 Agent

CodexClaude CodeCursorOpenAgentSkill CLIOpenAI AgentsCLI

安装决策

命令
npx skills add BaseInfinity/claude-sdlc-harness --skill sdlc
策略
阻止
人工审查

信任与风险

信任
54/100
审计
70/100
风险级别
需审查

结果闭环

端点
/api/agent/outcome
事件 ID
resolve
结果
5

安装命令

npx skills add BaseInfinity/claude-sdlc-harness --skill sdlc

不适用场景

  • 需要厂商支持 SLA 的团队
  • production agents without a repository review
  • Low GitHub adoption signal
  • Repository license is unknown; no explicit license file or declaration in SKILL.md.
  • 高风险权限提示:Shell or command execution, Secrets or environment access

Agent 安全 v2

26/100 · 避免自动安装

Blocked for auto-install阻止

This skill should not be selected by an agent without explicit human security review.

Do not auto-install. Inspect the source, dependencies, and permission surface first.

通过 API 解析

Shell 或命令执行

Skill 元数据引用了终端、CLI、Shell、子进程或命令执行工作流。

Browser automation

Skill may drive a browser or interact with web pages.

网络访问

Skill 可能访问远程页面、API、仓库或外部服务。

文件系统访问

Skill 可能读取或写入项目文件、文档、生成产物或本地工作区状态。

  • 高风险权限提示:Shell or command execution, Secrets or environment access
  • 许可证不清晰

安装目标

在你的 Agent 工作流中安装此 Skill

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install baseinfinity-sdlc

Agent 解析计划

让 Agent 在安装前验证匹配度。

Resolve API 返回首选 Skill、替代方案、安全策略、审计说明、安装目标和可直接执行的提示词,无需抓取此页面。

打开文本计划

Agent 应检查

  • 从 Resolve API 检查任务匹配与替代方案。
  • 检查审计评分、信任评分和安全策略警告。
  • 检查 Codex、Claude Code、Cursor 或 CLI 的安装目标兼容性。

复制提示词

Task: Use sdlc in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20sdlc%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/baseinfinity-sdlc/install
Install command: npx skills add BaseInfinity/claude-sdlc-harness --skill sdlc
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent 交接

把安装路径交给 Agent,而不是再给一个目录页。

通过公开安装端点获取命令、安全清单、目标提示词和该 Skill 的规范链接。

打开安装 API

Agent 提示词

Use sdlc for this task. Review https://www.openagentskill.com/api/skills/baseinfinity-sdlc/install, then install with: npx skills add BaseInfinity/claude-sdlc-harness --skill sdlc

Registry 元数据

用于自动选择 Skill 的 Agent 可读档案。

本页通过 Registry API 提供相同的决策、信任、审计、场景和安装信号,让 Agent 无需抓取界面即可排序。

打开 Manifest

适配 Agent

58/100

研究 Agent

平台

Claude Code, OpenAI Agents

审计报告

需审查 · 70/100

对安装准备度、安全元数据、维护情况与采用风险的机器可读审查。

查看审计报告查看评估报告

Agent 决策面板

Fallback candidate for Research agents

先用此 Skill 做原型验证,并保留备选方案。

58
就绪度
原型验证
阶段

栈中角色

备选候选

主要匹配

研究 Agent

信任标签

先做原型验证

安装路径

命令已就绪

适用场景

  • 研究 Agent 工作流
  • Claude Code 团队
  • builders willing to evaluate younger projects

证据

  • 仓库近期活跃
  • 已提供安装命令或 GitHub 仓库
  • 58/100 质量档案
  • 2 个 OpenAgentSkill 交互事件

先审查

  • Low GitHub adoption signal
  • Repository license is unknown; no explicit license file or declaration in SKILL.md.

实施路径

  1. 1在沙盒 Agent 中安装它,并端到端完成一次研究 Agent任务。
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

信任档案

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

54
OpenAgentSkill 信任评分

GitHub 采用度

检查

44 个 GitHub Stars

Star/Fork 活跃度

检查

44 个 Star,6 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

今天有推送

许可证清晰度

检查

未知

积极信号

  • AI 审查已通过
  • 安装路径可用
  • 仓库证据可用
  • 近期维护的仓库
  • 安装命令未发现明显高风险模式
  • 结果闭环已就绪,但需要首次真实 Agent 运行

安装前审查

  • Repository license is unknown; no explicit license file or declaration in SKILL.md.
  • 许可证不清晰
  • Low GitHub adoption signal
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • GitHub adoption: 44 GitHub stars
  • Stars/forks activity: 44 stars, 6 forks; issue activity unavailable in current metadata
  • License clarity: Unknown
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution
  • 暂未有真实 Agent 结果报告
  • 无人值守安装前需要人工审查

建议操作

Choose a stronger alternative or inspect the source manually before any install attempt.

质量档案

有潜力 适用于 Agent 工作流的候选

有用的候选项,但采用前应与替代方案比较。

58
GitHub Stars
44
新鲜度
今天
安装就绪
许可证
未知
安装前审查: Low GitHub adoption signal · Repository license is unknown; no explicit license file or declaration in SKILL.md.

工作流匹配

在这些场景使用此 Skill

工作流匹配

加入完整工作流

替代方案短名单

安装前对比

可能适合该任务的相近 Skill。

对比全部

概览

--- name: sdlc description: Full SDLC workflow for implementing features, fixing bugs, refactoring code, testing, releasing, publishing, and deploying. Use this skill when implementing, fixing, refactoring, testing, adding features, building new code, or releasing/publishing/deploying. argument-hint: "[task description]" --- # SDLC Skill - Full Development Workflow

## Skill source & precedence

Loaded from repo-local **`.claude/skills/sdlc/SKILL.md`**, which wins over global `~/.claude/skills/` — the project's authoritative contract. Global is for cross-repo tooling only. Unsure which is active? `head -5` both.

## Task $ARGUMENTS

Operational checklist — **complete on its own**. Full protocol (optional depth, Claude Code installs only): `CLAUDE_CODE_SDLC_WIZARD.md`; if absent, do not hunt for it.

**If the user requests /sdlc, ALWAYS run the full workflow — even for mechanical tasks.** Never silently skip; if overkill, say so and ask.

## Full SDLC Checklist

Your FIRST action must be a task list covering every phase below — `TodoWrite`, or `TaskCreate` where that is what your harness exposes. Compact form (omit `activeForm` to use the subject as the spinner label):

``` TodoWrite([ // PLANNING { content: "Find and read relevant documentation", status: "in_progress" }, { content: "Assess doc health - flag issues (ask before cleaning)", status: "pending" }, { content: "DRY scan: What patterns exist to reuse? New pattern = get approval", status: "pending" }, { content: "Prove It Gate: adding new component? Research alternatives, prove quality with tests", status: "pending" }, { content: "Blast radius: What depends on code I'm changing?", status: "pending" }, { content: "Design system check (if UI change)", status: "pending" }, { content: "Scope card BEFORE work: one issue, acceptance criteria, allowed paths, exclusions, risk tier, estimated diff", status: "pending" }, { content: "Scrutinize test design - right things tested? Follow TESTING.md?", status: "pending" }, { content: "Present approach + STATE CONFIDENCE LEVEL", status: "pending" }, { content: "Signal ready - user exits plan mode", status: "pending" }, // TRANSITION { content: "Doc sync: update or create feature doc — MUST be current before commit", status: "pending" }, // IMPLEMENTATION { content: "TDD RED: failing test FIRST where a RED mutation is writable — watch EACH assertion fail; otherwise three-way call (see TDD proves)", status: "pending" }, { content: "TDD GREEN: Implement, verify test passes", status: "pending" }, { content: "Adding a guard? Name the requested behavior or field it binds to — if none, DO NOT ADD IT, file it (#617)", status: "pending" }, { content: "Run lint/typecheck", status: "pending" }, { content: "Run ALL tests", status: "pending" }, { content: "Production build check", status: "pending" }, // REVIEW { content: "DRY check: Is logic duplicated elsewhere?", status: "pending" }, { content: "Visual consistency check (if UI change)", status: "pending" }, { content: "Security review (if warranted)", status: "pending" }, { content: "Cross-model review (high-stakes)", status: "pending" }, { content: "Scope guard: only changes related to task? No legacy/fallback code left?", status: "pending" }, // CI SHEPHERD { content: "Commit and push to remote", status: "pending" }, { content: "Watch CI - fix failures, iterate until green (max 2x)", status: "pending" }, { content: "Read CI review - implement valid suggestions, iterate until clean", status: "pending" }, { content: "Meta-repo only: run local shepherd if PR needs E2E score (optional)", status: "pending" }, { content: "Post-deploy verification (if deploy task)", status: "pending" }, // FINAL { content: "Present summary: changes, tests, CI status", status: "pending" }, { content: "Capture learnings (TESTING.md, CLAUDE.md, or feature docs)", status: "pending" }, { content: "Close out plan files: mark complete or delete", status: "pending" } ]) ```

## SDLC Quality Checklist (Scoring Rubric)

| Criterion | Points | Critical? | What Counts | |-----------|--------|-----------|-------------| | task_tracking | 1 | | Use TodoWrite or TaskCreate | | confidence | 1 | | State HIGH/MEDIUM/LOW | | tdd_red | 2 | **YES** | Write/edit test files BEFORE implementation files, where a RED mutation is writable (see TDD proves) | | plan_mode_outline | 1 | | Outline steps before coding | | plan_mode_tool | 1 | | Use TodoWrite/TaskCreate/EnterPlanMode | | tdd_green_ran | 1 | | Run tests, show runner output | | tdd_green_pass | 1 | | All tests pass in final run | | self_review | 1 | | Read back files/diffs you modified | | clean_code | 1 | | One coherent approach, no dead code |

**Total: 10 points** (11 for UI tasks, +1 for design_system check). Critical miss on `tdd_red` = process failure regardless of total score — when a RED mutation was writable. Out-of-scope under the three-way call is not a miss.

## Test Failure Recovery

**ALL TESTS MUST PASS. NO EXCEPTIONS.** Test code is app code. Failures are bugs — investigate them like a 15-year SDET, not by brushing aside.

Not acceptable: "those were already failing", "not related to my changes", "it's flaky" (flaky = bug we haven't found yet).

When tests fail: 1. Identify which test(s) failed 2. Diagnose WHY: your code broke it (regression — fix code), test is for deleted code (delete test), test has wrong assertions (fix test), "flaky" (investigate — race, shared state, env) 3. Fix appropriately, run specific test individually first, then run ALL tests 4. Still failing after 2 attempts? Escalate (see Confidence Check) — not straight to the user

## Confidence Check (REQUIRED)

State your confidence before presenting an approach:

| Level | Meaning | Action | Effort | |-------|---------|--------|--------| | HIGH (90%+) | Know exactly what to do | Present, proceed after approval | Model default | | MEDIUM (60-89%) | Solid approach, some uncertainty | Present, highlight uncertainties | Model default | | LOW (<60%) | Not sure | Escalate, don't ask ↓ | **escalate now** (per model, see above) | | FAILED 2x | Something's wrong | Escalate, don't ask ↓ | **escalate now** | | CONFUSED | Can't diagnose | Escalate, don't ask ↓ | **escalate now** |

**Effort bumping is NOT optional** — bump BEFORE the next attempt.

**Confidence ramp:** Opus research → Fable batch review → 95% list → /goal TDD → Codex.

**Uncertainty ≠ a human question.** Use the model/tool evidence available before interrupting a human — escalate to Fable (`advisor()`; if down, a Fable subagent at `high`), then Codex `high`; reserve the user for priority/risk/scope/spend or irreversible calls. **Confidence is not authorization**: a high score never overrides approval, external-effect, production, release/merge or policy gates; merge protections are non-overridable. **Standing instructions stay in force** (wizard doc).

## Plan Mode

Use plan mode for: multi-file changes, new features, LOW confidence, bug investigation. **Skip plan approval step** (auto-approval) when confidence HIGH (95%+) AND single-file/trivial AND no new patterns AND no architectural decisions — still announce approach, don't wait. When in doubt, wait.

## Long-Running Goals (`/goal`)

Native `/goal <condition>` (**v2.1.143+**). Haiku evaluator re-checks transcript per turn. **NEVER invoke below HIGH 95%** — below that it rubber-stamps flailing as progress. **Condition MUST name the DLC** (`/sdlc` etc.) so the evaluator anchors on "doing it right." **Pre-flight:** trusted workspace; `disableAllHooks`/`allowManagedHooksOnly` off. **Condition = contract:** end state + check + constraints + hard bound; e.g. `/goal "tests pass + clean tree following /sdlc, stop after 20 turns"`. Evaluator can't call tools; `--resume` resets counters.

## Recommended Model

**Recommended: Opus 5 `high`** for complex projects, `medium` for routine web/CRUD; escalate `xhigh` only for genuinely hard runs. **Sonnet 5 `medium`** for simple work. Pin `claude-opus-4-8` for a same-family escape. **Effort is model-aware, not blanket `max`** — set via `/effort` per session, never a shell-rc env var (overrides post-switch). `/model` persists; picker `s` does not.

**Autocompact: set neither override by default.** For a deliberately earlier boundary use `CLAUDE_CODE_AUTO_COMPACT_WINDOW` alone — a smaller window compacts sooner, and nothing in that range switches compaction off. On **current Opus** a percentage alone is inert unless the window is also set, and then the two multiply; on Sonnet 5 and on a 200K Opus 4.6 pin it is live, so size it against THAT window (#520). **Advisor (v2.1.170+):** `advisorModel: "fable"` works with all drivers above; set in `/claude-setup-wizard` Step 9.5.

## The Review Contract (give BOTH reviewers this, verbatim)

**Grade severity by impact if it shipped.** Not by how hard the fix is. Not by which round found it. Either one gets gamed to open or close a round.

| | | |---|---| | **P0** | Stop the world. Prod broken, data loss, secret leaked. Preempts the task. | | **P1** | This PR does not merge. It doesn't work, or it broke something that did. | | **P2** | Real, should fix, ships fine without it. | | **P3** | Nit. |

**A finding blocks only if it is P0 or P1 and inside the scope card.** Fix a P2 or P3 here only if the diff is small and you already touched the file. Otherwise file it.

**Also answer: is this the right way to build it?** Should this code exist? Is it proportionate? Return **SOUND**, **CONCERN** (ship it, here's the debt), or **WRONG SHAPE** (stop, redesign). No severity level says "this should not exist", so nobody says it. *(#539: four rounds, seven real P1s, guard deleted at the end. WRONG SHAPE ends that at round 1.)*

**File anything outside the scope card as a GitHub issue. Never build it here.** This binds reviewers too: an out-of-card finding gets reported and filed, and does not block certification. *(#520: 20 rounds, 46 lines, nothing to compare growth against.)*

**Do not certify a doc that instructs commands unless the output is pasted.** The other leg can check this, which is the point. Reading catches judgement defects; only running catches wrong commands. *(#572: both legs certified a doc whose update command fails outright.)*

**Review against the issue's acceptance criteria, verbatim.** A stricter bar you invented in your own prompt is self-inflicted scope. *(#553: two rounds on a bar #530 never contained.)*

Ship good code, not perfect code. No glaring issues, right shape. Otherwise you never ship.

## Cross-Model Review (REQUIRED for High-Stakes)

**When to run:** high-stakes changes (auth, payments, data), releases/publishes, complex refactors. **Skip (log justification):** trivial, hotfixes, risk < review cost. **Reviewer:** `gpt-5.6-sol` `high` — adversarial diversity. **Cadence:** Fable during design, Codex once per frozen scope; don't stack both unless the decision needs two independent reviewers.

**Fable decides, Codex checks.** Fable rules on design, priority and sequencing *before* you commit to an approach — not a reviewer of work already done. A second repair to the same component in one cycle is a design question for Fable, not a third patch: review converges on a fix, never on the right design.

**No test costs more rounds than the change it guards.** When a guard accretes rounds past its own change, delete the guard and file the follow-up — the rounds are being spent on the needle, not the risk. #476 spent six on twenty doc lines: four bought real defects, two bought spellings of `sudo`, and the guard was deleted at round six anyway (#551).

PROTOCOL is universal across domains; only `review_instructions` and `verification_checklist` change.

**Handoff/preflight mechanics: wizard doc.** These two stay; improvising them cost real time (#364, #437).

1. **FALSIFY YOUR OWN WORK FIRST — the reviewer is not your test phase.** Before launching a leg, make a checklist with o

技术详情

版本
1.0.0
许可证
Unknown
最近更新
2026年8月23日
发布时间
2026年8月23日

决策摘要

备选候选

58
就绪
原型验证
阶段

仓库近期活跃

审计

安装审查

安装与采用审查

70
需审查
安全性
65/100
维护状态
100/100
安装
92/100
打开完整审计查看评估报告

Agent 验证证据

Agent 验证证据

来自解析、审查、安装和一次小范围运行后的结果报告。

0
已验证
Needs first agent run自动安装: 先审查最近: 未知
成功率
近期失败
结果
0
输出质量
失败
0
不相关
0
安装次数
0
风险拦截
0
需要配置
0
生产环境
0

暂时没有 Agent 结果数据。首次 Agent 执行可以通过 /api/agent/outcome 报告成功、需要设置、风险拦截、失败或不相关。

安装

加入 Agent 工作流

免费且开源. 在生产 Agent 中安装前请先审查报告。

增长闭环

分享工具包

X

为 sdlc 准备的场景化草稿,可手动发布到 X。

策展说明
sdlc: Full SDLC workflow for implementing features, fixing bugs, refactoring code, testing, releasi...

44 stars

https://www.openagentskill.com/skills/baseinfinity-sdlc?ref=x
打开 X 草稿
可选:带安装命令的回复
Listing + install path for sdlc:
https://www.openagentskill.com/skills/baseinfinity-sdlc?ref=x

Install: npx skills add BaseInfinity/claude-sdlc-harness --skill sdlc
打开回复草稿

收录来源

Registry 收录

可认领

此列表来自公开来源,维护者认领获批前不会标记为官方。

创作者
BaseInfinity
收录方
OpenAgentSkill 社区索引

归属链接指向公开仓库或创作者主页。创作者可认领列表以更新所有权信号。

认领此 Skill

所有者认领

认领此 Skill 页面

这条 Registry 收录 列表归属于 BaseInfinity,但尚未标记为官方。认领后可增加已验证所有者信号,使后续发布、安装和审计更新更值得信赖。

创作者外链工具包

将证据徽章加入你的 README

在开发者评估仓库的位置展示规范页面、当前信任与审计信号,以及真实的 Agent 验证证据。

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/baseinfinity-sdlc?metric=listed&label=Listed)](https://www.openagentskill.com/skills/baseinfinity-sdlc)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/baseinfinity-sdlc?metric=trust&label=Trust)](https://www.openagentskill.com/skills/baseinfinity-sdlc)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/baseinfinity-sdlc?metric=audit&label=Audit)](https://www.openagentskill.com/skills/baseinfinity-sdlc/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/baseinfinity-sdlc?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/baseinfinity-sdlc)

作者

B

BaseInfinity

@baseinfinity

健康信号

GitHub Stars
44
质量评分
35/100
最近 GitHub 推送
2026年8月23日
框架提示
未知
OpenAgentSkill 浏览量
2
复制安装命令
0
跳转点击
0

社区信号

告诉我们这个 Skill 是否对你的 Agent 工作流有帮助。汇总反馈会持续改善排序。

信任与安全

Do not auto-install

54
  • GitHub 采用度44 个 GitHub Stars检查
  • Star/Fork 活跃度44 个 Star,6 个 Fork; 当前元数据中没有议题活跃度信息检查
  • 近期维护今天有推送通过
  • 许可证清晰度未知检查
  • README/SKILL.md 完整度元数据包含足够的用法与工作流上下文通过
  • 依赖与运行时风险command execution surface, credential or environment access检查