Install
$ agentstack add skill-enocgit-sdlc-kit-definition-of-done-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
definition-of-done-review
A consistent, team-specific final check. Generic code-review and simplify catch bugs and cleanup; this verifies the change is actually done by our standard. Run it after them.
Checklist — read it from AGENTS.md, don't rely on a copy
The canonical Definition of Done lives in the project's AGENTS.md ("Definition of Done" section). Read it at run time and review the change against that exact list, item by item — this skill deliberately embeds no copy, so a project that tightens or extends its DoD is automatically reviewed against its own standard. (The sensitive-areas list is likewise canonical in AGENTS.md → Sensitive areas.)
How to judge the items that need interpretation:
- Acceptance criteria — quote each criterion from the PRD/issue and map it to evidence.
- Contract fidelity — no undocumented endpoints/fields; types derived from the contract, not
hand-duplicated; any mismatch is a finding even if tests pass.
- Tests / observed working — green suite is necessary, not sufficient: the change must have
been run and observed (run/verify), and new logic covered, not just touched.
- Docs —
docs/architecture.mdif the system's shape changed; a new ADR if a decision was
made; the tracker issue reflects reality.
- Security — for sensitive-area changes,
security-reviewwas run with findings resolved and
docs/security.md updated.
Output
Produce a pass/fail verdict per item with file:line evidence. If anything fails, list the exact follow-ups and do NOT mark the task ready to merge. This is a gate.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: enocgit
- Source: enocgit/sdlc-kit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.