sdlc-engine

sdlc-engine is a skill for Claude Code, Codex from Jarroslav/agentic-os. It costs 269 tokens per session (6,988 once invoked), scanned A, original, Apache-2.0.

An orchestrator for running a complete, governed software-development process for one unit of work. It covers planning, specification, test-driven development (writing tests before implementation), review, quality checks, and handoff.

In plain words
What is it for?
Use it only when dispatched by the guided or autonomous SDLC commands to manage the full development workflow.
Why use it?
It provides a controlled path from a task request to verified delivery, while requiring evidence instead of guesses about the code or results.

Skill for Claude CodeCodex

Installs and runs on its own, but its text points at files inside its plugin — anything it tells you to read at a ${CLAUDE_PLUGIN_ROOT} path is only there once the plugin is installed. Installing the plugin gets both.

Part of the agentic-sdlc plugin — 27 skills, 5 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/jarroslav/agentic-os/sdlc-engine
Any agent
npx skills add Jarroslav/agentic-os --skill sdlc-engine
Clone the repo
git clone --depth 1 https://github.com/Jarroslav/agentic-os

Made for: Claude Code, Codex.

Or install agentic-sdlc, the plugin that ships this one along with the rest of its 27 skills, 5 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for sdlc-engine

README.md
[![agentmods](https://agentmods.dev/badge/skills/jarroslav/agentic-os/sdlc-engine.svg)](https://agentmods.dev/skills/jarroslav/agentic-os/sdlc-engine)
Your own site
<a href="https://agentmods.dev/skills/jarroslav/agentic-os/sdlc-engine"><img src="https://agentmods.dev/badge/skills/jarroslav/agentic-os/sdlc-engine.svg" alt="Measured on agentmods" height="20"></a>
Per session 269 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 6,988 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00269 $0.06988
Opus 5 $0.00134 $0.03494
Sonnet 5 $0.00054 $0.01398
Haiku 4.5 $0.00027 $0.00699

Measured 4d ago against content hash a205f2296493, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

sdlc-engine scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/agentic-sdlc/skills/sdlc-engine/SKILL.md · 447 lines

How it starts

The opening of the file, as written. The whole thing — 447 lines — stays where its author put it; the contents beside it link to each section on GitHub.

sdlc-engine

Purpose

You are the single orchestrator behind every governed SDLC run in this plugin. sdlc-guided and sdlc-auto are thin wrappers: each normalizes its caller's intent into a task_input and a mode, then dispatches you. From that point forward you own the run end to end — bootstrapping the run directory, routing through complexity, driving spec/plan approval, supervising TDD implementation, running the deferred two-round code review, executing QA gates and feature verification, and handing off. sdlc-runs retains resume and repair authority over runs you produce; you must leave behind evidence it can act on, but you do not implement resume/repair yourself beyond honoring the run state you are handed.

Ground every phase in what the run's own artifacts and the host repo's guides actually say. Never invent a fact — about the codebase, the ticket, test output, or review findings — that isn't backed by an artifact, a tool result, or a dispatched subagent's return. When information is missing, say so and route to a gate or a clarifying question; do not fill the gap from assumption.

When to invoke — and when not to

  • Invoke when sdlc-guided or sdlc-auto dispatch you with a mode and a task_input. That is the only legitimate entry point.
  • Invoke when sdlc-runs hands back a run_id for a run that was interrupted mid-phase and the user or the calling skill wants it driven to completion.
  • Do not invoke yourself in response to a raw user message — route through sdlc-guided (hitl) or sdlc-auto (autonomous) first, so mode is always explicit before you start.
  • Do not re-implement logic owned by the superpowers skills you dispatch into (brainstorming, writing-plans, test-driven-development, subagent-driven-development) — call them, don't inline their behavior.

Where this pipeline stops and the project's own begins

Some repositories already run their own delivery pipelines. When .agentic/agentic-sdlc/config.json defines project_orchestration, load it before Phase 0 and treat those pipelines as the only thing permitted to select or invoke the project's fleet roles.

Read the full file on GitHub · 447 lines

Files

What ships with it

2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 447 lines · 0 tokens per session scan A a205f2296493

Subscribe to this mod's changes

sdlc-engine is a skill published in the GitHub repository Jarroslav/agentic-os (0 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 269 tokens to every session and 6,988 once invoked, about $0.0013 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.