A reusable Claude Code software-delivery framework. It installs a set of Claude Code agents, skills, and rules into any repository so that feature delivery follows a consistent workflow: requirements analysis → conditional architecture review → conditional design-time security review → implementation → security audit → independent QA.
- Node.js
>= 20(seepackage.json) - Git
- Claude Code installed and configured in the target repository
Clone this repository to a local folder (it is not published to a package registry, so it must be installed from source):
git clone <this-repo-url> claude-sdlc
cd claude-sdlc
npm installnpm install only installs development/test dependencies for this repo. The
CLI itself has no runtime dependencies.
From inside the cloned claude-sdlc folder, link the package so the claude-sdlc
binary (declared in package.json) is available globally:
npm linkAlternatively, invoke the CLI directly without linking:
node /path/to/claude-sdlc/bin/claude-sdlc.js <command>Run the init command from inside the repository you want to deliver
software in (see bin/claude-sdlc.js):
cd /path/to/your-project
claude-sdlc initOr point at a target without changing directories:
claude-sdlc init --target /path/to/your-projectAvailable flags:
| Flag | Description |
|---|---|
--target, -t <path> |
Target repository; defaults to the current directory |
--dry-run |
Preview changes without writing any files |
--force |
Overwrite conflicting framework-owned files |
--help, -h |
Show CLI help |
Running init performs (see install()):
- Copies managed framework files (agents, skills, rules) into
.claude/ - Creates project-owned directories (
.claude/project-knowledge/,.claude/delivery/) - Merges
framework/templates/settings.jsoninto.claude/settings.json - Writes the framework block and the initial project block into
CLAUDE.md - Updates
.gitignore - Writes an install manifest to
.claude/framework.json
Running init again on an already-installed project fails on purpose —
use claude-sdlc update instead.
claude-sdlc validate
claude-sdlc doctorvalidatechecks that all required framework paths exist and that.claude/framework.json/CLAUDE.mdare well-formed (seevalidate-project.js).doctorrunsvalidateplus additional health checks: version drift, project-knowledge completeness, stack skills, and Git state (seedoctor.js).
Inside Claude Code, run the onboarding command to generate persistent
project knowledge from the actual repository (see
project-onboarding/SKILL.md):
/project-onboarding
This creates, under .claude/project-knowledge/:
PROJECT_PROFILE.mdTECHNOLOGY_STACK.mdARCHITECTURE.mdREPOSITORY_MAP.mdCOMMANDS.mdCONVENTIONS.mdTESTING_STRATEGY.mdINTEGRATIONS.mdONBOARDING_REPORT.md
If the repository structure, dependencies, commands, or architecture change later, refresh this knowledge instead of re-onboarding from scratch:
/refresh-project-knowledge
Once onboarding is complete, deliver features or fixes through the guided
workflow (see deliver-requirement/SKILL.md):
/deliver-requirement <describe your requirement>
This command orchestrates five specialist subagents in the main conversation:
| Agent | Role |
|---|---|
requirements-analyst |
Converts the request into repository-aware, testable requirements. Does not implement code. |
solution-architect |
Produces a repository-consistent technical design for changes spanning multiple components, contracts, persistence, security, or infrastructure. Does not implement code. |
software-developer |
Implements the accepted requirements/design, modifies production code and tests, and runs focused validation. |
security-analyst |
Identifies the technology stack and audits designs and implemented changes against OWASP-aligned checks (dependencies, secrets, auth, input validation, infra hardening). Runs after solution-architect for design review and after software-developer as a mandatory pre-QA audit. Does not implement fixes. |
qa-engineer |
Independently validates acceptance criteria, regression risk, security, and test coverage against the final diff. |
Delivery artifacts (request, analysis, design, implementation, QA report)
are recorded under .claude/delivery/<requirement-id>/.
To upgrade an already-installed project to the current framework version:
cd /path/to/your-project
claude-sdlc updateupdate (see update()) backs up the existing
installation, re-copies managed framework files, removes stale
framework-managed files, re-merges settings, and updates only the framework
block of CLAUDE.md — the project block created by onboarding and your
project-knowledge/delivery/stack-* files are preserved.
claude-sdlc init [options] One-time framework installation
claude-sdlc update [options] Upgrade framework-managed files safely
claude-sdlc validate [options] Verify the installed framework structure
claude-sdlc doctor [options] Diagnose framework and project-knowledge health
Run any command with --help for details.
Inside the cloned claude-sdlc repo:
npm testThis runs the Node.js built-in test runner (node --test, see
package.json) against tests/. The
tests/ directory does not yet contain any test files; add specs there
as test coverage is introduced.
MIT — see the license field in package.json.