The headline this month was the product-side counterpart to the SDLC: a full PDLC skill set that carries an idea from discovery through measurement. August also realigned the verification skills around non-overlapping roles, added several new pipeline phases, and completed the ISO/IEC 25010 audit set. The month came to 61 commits, over 500 files changed, and 30 new skills.
What I Have Been Working On #
Shipped the PDLC pipeline.
This was last month’s open need, and it is now a self-contained product development lifecycle that wraps the engineering one.
It covers discovery, validation, strategy, definition, launch, and measurement, with a proceed, pivot, or kill gate at every phase.
PDLC is the only slash command; the 31 phase and cross-cutting sub-skills live under
skills/pdlc/skills/ and the orchestrator loads them on demand.
Artifacts live under .pdlc/, mirroring the .sdlc/ conventions: a shared reference file, a PDLC_DIR fallback, a state file, and a revision mode.
Definition is the seam where the product work hands the settled what and why to SDLC.
Two supporting skills came with it, create-roadmap and
review-roadmap, and
identify-feature-opportunities generates and ranks new ideas from the code surface.
Realigned the verification skills.
validate-pr,
verify-pr, and
review-pr had overlapping mandates, so I split them into three questions: validate-pr asks whether the change builds the right product, verify-pr asks whether the product is built right using runtime proof, and review-pr judges code craft from static reading alone.
The new
review-requested-prs orchestrator runs the three across the PRs waiting on me and skips any step already done for the current commit using SHA markers.
analyze-test-coverage became its own skill for reporting introduced tests, change coverage, and uncovered code, and
review-pr-full chains the whole review into one pass.
Added SDLC phases and artifacts.
A new validate-assumptions/
review-assumption-validation phase collects the assumptions made during design, runs the cheapest experiment that could invalidate each risky one, and blocks implementation when an assumption fails.
create-lifecycle/
review-lifecycle document how a resource’s states, transitions, and retention change over time, and
create-domain-model/
review-domain-model became standalone so a domain can be understood before solutioning.
create-project/
review-project fill the context files for a new repository, and
create-question/
review-question record open questions with what they block.
create-cli-design settles a feature’s command surface as a companion artifact to requirements.
Generated artifacts carry a
session_link so a reviewer can reopen the session that produced them, create-* auto-dispatches its review-* in a subagent, and outcome files list the artifacts a phase produced.
A single HTML slide deck now presents the whole SDLC family.
Completed the ISO/IEC 25010 audit set.
audit-sdlc is now the coordinator for the
ISO/IEC 25010 quality model, with a mapping table from each characteristic to a skill.
One skill now covers each remaining characteristic: functional suitability, performance efficiency, compatibility, usability, reliability, maintainability, and portability, alongside the existing security and observability audits.
Shipped general-purpose skills.
devils-advocate argues the strongest case against an idea, plan, or decision before you commit.
gh-stack manages stacked pull requests.
post-slack-message posts or threads a Slack message.
stakeholder-announcement drafts and posts infrastructure updates to stakeholder channels.
agents-section-daily-refresh runs the daily curation of the agent-maintained section of this blog.
sync-articles brings a batch of articles into conformance with the writing rules.
handle-pr-author-feedback (renamed from
handle-pr-feedback) verifies that an author’s new commits answer your review comments.
Gated GitHub writes and reworked tooling.
A should-post-to-github script now gates every GitHub content write, and the PR skills default to not posting, so a comment or merge only happens when --post is passed.
SDLC worktrees moved to /tmp/sdlc/<owner>/<repo>/<issue>, and ~/.sdlc/** and /tmp/sdlc/** are pre-approved in the agent CLI so unattended runs are not stopped by a prompt.
Script references moved to ~/.agents/scripts/, the audit and find skills switched from grep to ripgrep, and CLAUDE.md and .claude were replaced by AGENTS.md and .agents across the library.
Tightened conventions.
create-article now requires naming the referent rather than leaving a vague it, and the 2-5 link cap on its See also sections was removed.
What I Currently Need #
I did not write this entry at the time, so I have no record of what I needed in August and am stating that plainly rather than reconstructing a list I cannot trust.
See also #
- What I’ve built and what I need: July 2026 - the previous entry in this series; August delivers the PDLC pipeline it asked for.
- The Self-Evolving Repository - the end-to-end automation vision that the SDLC and PDLC pipelines now serve.
- Loops as Files - the scheduling layer that runs skills unattended, which the daily refresh and PR skills rely on.
- Iterating on Agent Skills - how the skill library changes over time, of which this month’s 30 additions are one step.
- A Pull Request Is a Claim, Not Evidence - the reasoning behind splitting verification into a right-product check and a built-right check.
References #
agents - the skill library where the PDLC pipeline, the verification realignment, and the audit set landed.
ISO/IEC 25010 - the quality model the audit skills now map one to one.
ghx - the GitHub CLI used across the review and feedback skills.