dev-lifecycle — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited dev-lifecycle (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Coordinate the phase-specific AI DevKit skills instead of running phase details directly.
Required phase skills:
dev-worktree for feature workspace setup and resume.dev-requirements for phases 1-2: new requirement and requirements review.dev-design for phase 3: design review.dev-planning for phases 4 and 6: initial task planning and updates after implementation tasks.dev-implementation for phases 5 and 7: execute plan and check implementation.dev-testing for phase 8: write tests and verify coverage.dev-review for phase 9: final code review.Supporting skills:
memory for reusable project knowledge during clarification.tdd for implementation tasks.verify before completing implementation, implementation checks, testing claims, and review readiness.At the beginning of every dev-lifecycle run:
npx ai-devkit@latest skill list to inspect currently installed project skills.npx ai-devkit@latest skill add --built-in to install all AI DevKit built-in skills. Then rerun npx ai-devkit@latest skill list.npx ai-devkit@latest lint to verify the configured AI docs structure.npx ai-devkit@latest lint --feature <name>.npx ai-devkit@latest init -a -e claude --built-in --yes, then rerun lint.Before executing any phase:
| Phase | Route to | When |
|---|---|---|
| Setup. Workspace | dev-worktree | Starting or resuming feature work |
| 1. New Requirement | dev-requirements | User wants to add a feature or start /new-requirement |
| 2. Review Requirements | dev-requirements | Requirements doc needs validation |
| 3. Review Design | dev-design | Design doc needs validation against requirements |
| 4. Create Initial Plan | dev-planning | Requirements, design, and testing docs are ready for task breakdown |
| 5. Execute Plan | dev-implementation | Ready to implement tasks from planning doc |
| 6. Update Planning | dev-planning | Auto-trigger after completing any implementation task |
| 7. Check Implementation | dev-implementation | Verify code matches design and docs |
| 8. Write Tests | dev-testing | Add or verify test coverage |
| 9. Code Review | dev-review | Final pre-push review |
Sequential flow: setup -> 1 -> 2 -> 3 -> 4 -> 5 -> 6 after each completed task -> 7 -> 8 -> 9.
If the user wants to continue work on an existing feature:
dev-worktree to identify and confirm the target branch/worktree.npx ai-devkit@latest lint --feature <feature-name> in the active context.dev-lifecycle skill directory:<skill-dir> as the directory containing this SKILL.md.<skill-dir>/scripts/check-status.sh <feature-name>.Not every phase moves forward. When a phase reveals problems, route back:
dev-requirements Phase 1.dev-requirements Phase 2.dev-design and revise design.dev-design if design is wrong, or dev-implementation if code is wrong.dev-design.dev-implementation or dev-testing.npx ai-devkit@latest lint and npx ai-devkit@latest lint --feature <name> to discover and validate the configured docs directory. Do not assume docs/ai; it is only the default.feature-<name>.npx ai-devkit@latest docs init-feature <name>. Use the paths returned by the command as authoritative.npx ai-devkit@latest lint --feature <name>. If you must infer manually, first resolve the configured docs directory from .ai-devkit.json paths.docs, falling back to docs/ai.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.