# Adlc Security Checklist

> Run a read-only ADLC security gate for secrets, trust boundaries, and unsafe workflow changes.

- **Type:** Skill
- **Install:** `agentstack add skill-davidvictor-adlc-skills-adlc-security-checklist`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [davidvictor](https://agentstack.voostack.com/s/davidvictor)
- **Installs:** 0
- **Category:** [Security](https://agentstack.voostack.com/c/security)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [davidvictor](https://github.com/davidvictor)
- **Source:** https://github.com/davidvictor/adlc-skills/tree/main/skills/adlc/adlc-security-checklist

## Install

```sh
agentstack add skill-davidvictor-adlc-skills-adlc-security-checklist
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# ADLC Security Checklist

Use this when a plan, diff, extension, MCP configuration, release candidate, or workflow change needs a standalone security gate.

## Process

1. Resolve effective ADLC paths from `.adlc/config.yaml`; use `adlc resolve-config` when the CLI is available.
2. Pin the target: plan, diff, extension directory, MCP template, agent install, or release candidate.
3. Read architecture, rules, configured security references, and relevant source files.
4. Inspect secrets, auth, authorization, prompt/data injection, path traversal, command execution, dependency/install behavior, and external integrations.
5. Stay read-only. Route fixes to `adlc-fix`, `adlc-rules`, `adlc-plan`, or `adlc-implement`.
6. Lead with exploitable or operationally meaningful findings.

## Output

End with a final parseable `adlc-gate-result` fenced block:

```adlc-gate-result
{
  "schema_version": 1,
  "gate": "security",
  "status": "pass|warn|fail",
  "blocking": false,
  "blockers": [],
  "affected_files": [],
  "suggested_next": {
    "command": "adlc-fix|adlc-rules|adlc-plan|adlc-commit|null",
    "reason": "Short reason."
  }
}
```

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [davidvictor](https://github.com/davidvictor)
- **Source:** [davidvictor/adlc-skills](https://github.com/davidvictor/adlc-skills)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-davidvictor-adlc-skills-adlc-security-checklist
- Seller: https://agentstack.voostack.com/s/davidvictor
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
