ai-sdlc-change-impact
AI SDLC change-impact and lifecycle recovery workflow. Use when a requirement, acceptance criterion, decision, API contract, risk assumption, or other traced source changed after downstream artifacts were created and an AI assistant must identify stale artifacts, affected lifecycle stages, and evidence-backed reopen or revalidation actions without silently rewriting authoritative state. Supports `--quick-flow` for focused trace scanning and `--full-flow` for strict state and source-evidence gates.
How do I install this agent skill?
npx skills add https://github.com/mikegorelikoff/ai-sdlc-harness --skill ai-sdlc-change-impactIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill is a utility for software development lifecycle (SDLC) recovery that identifies stale artifacts based on changes. It uses a Python script to scan local Markdown files for specific trace IDs. The code follows secure practices, including robust path validation to prevent directory traversal and atomic file writing.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
ai-sdlc-change-impact: Evidence-Backed Lifecycle Recovery
Internal AI SDLC skill, not client-facing by default. Every rule below is important to follow. None of it can be skipped. Analysis proposes recovery actions; the owning lifecycle skill applies them.
0. Skill Card
- Skill name:
ai-sdlc-change-impact - Primary audience: Delivery, Dev, BA, QA
- Supporting audience: PM, Architecture, Security
- Audience tags: Delivery, Dev, BA, QA
- SDLC stage: Cross-lifecycle change recovery
- Purpose: Trace changed sources to stale artifacts and safe reopen actions.
- Output:
change-impact.mdand_ai_sdlc/change-impact.toon
0.1 Required Inputs
- Feature root in
specs/orspecs-refiniment/. - A JSON change set with stable changed references and exact source evidence.
- Readable feature artifacts and, in full flow, canonical lifecycle state.
0.2 Clarification Rules
- Ask only when the feature, changed reference, or source evidence is ambiguous.
- Do not infer that an artifact is stale without an exact trace occurrence.
- Report missing state or unowned artifacts as blockers, not guessed stages.
- Preserve multiple changes independently even when they affect one artifact.
0.2.1 Flow Mode Flags
- Support
--quick-flowand--full-flow; full flow takes precedence. - Quick flow scans feature Markdown and reports missing state as a blocker.
- Full flow requires canonical state plus valid changed-reference source lines.
- Neither mode changes state, artifacts, decisions, tasks, or indexes.
0.3 Output Rules
- Return changed refs, stale artifacts, affected stages, blockers, and ordered reopen actions directly in the Codex response.
- Before the final response, emit
ai-sdlc-handoff/v1withresult,blockers,next_required, andnext_optional; every action includesreason,command, andexpected_artifact. - Do not create
summary.txt,*-summary.txt, or ad hoc recovery files. - Every affected artifact and reopen action must retain exact evidence.
0.4 Artifact Routing
- Write human analysis to
<feature-root>/change-impact.md. - Write machine analysis to
<feature-root>/_ai_sdlc/change-impact.toon. - Never overwrite the changed source, downstream artifacts, or state.
- Route approved actions through the owning lifecycle skill.
0.5 Feature State Machine
- Read
<feature-root>/_ai_sdlc/state.toonbefore proposing stage actions. --state-checkvalidates read-only state availability.--begin-stateand--complete-stateare rejected because analysis cannot authorize reopening.- A
reopenproposal applies only to a stage currently in a complete state; active and not-started stages receive revalidation or pre-start gates. - The owning workflow records accepted recovery in state and decision log.
0.6 Artifact Metadata And Metatags
- Markdown starts with
artifact_metadatausing schemaai-sdlc-change-impact-metadata/v1. - Include
metatagsforai-sdlc,change-impact,recovery, and the affected stage identifiers. - Record feature, workspace, changed refs, state file, and flow mode.
0.7 Specs Index
- Read
specs/_ai_sdlc/specs-index.toonorspecs-refiniment/_ai_sdlc/specs-index.toonbefore feature analysis. - Do not refresh
specs/specs-index.mdorspecs-refiniment/specs-index.mdduring read-only analysis. - The owning workflow refreshes indexes only after an accepted state or authoritative artifact change.
References
- Read
references/change-set-contract.mdbefore preparing change evidence. - Use
scripts/change_impact.pyfor deterministic trace scanning, stage mapping, validation, and canonical report generation.
Script Usage
python3 skills/ai-sdlc-change-impact/scripts/change_impact.py specs/payments --changes /tmp/changes.json --emit --quick-flow
python3 skills/ai-sdlc-change-impact/scripts/change_impact.py specs/payments --changes /tmp/changes.json --write --full-flow --format toon
python3 skills/ai-sdlc-change-impact/scripts/change_impact.py specs/payments --changes /tmp/changes.json --state-check --format toon
The change set is read-only input. --write atomically creates both report
formats after all evidence gates pass.
Purpose
Make late change recovery explicit and bounded so teams update the smallest credible lifecycle surface instead of either ignoring drift or restarting all delivery work.
Inputs
- Use repository-relative source evidence with a positive line number.
- Use stable trace IDs already present in source and downstream artifacts.
- Read state status and artifact ownership from canonical repository records.
- Exclude generated change-impact reports from their own analysis.
Steps
- Record each changed reference and exact changed-source evidence.
- Validate that the source path is inside the feature and the evidence line contains the changed reference.
- Scan feature Markdown for exact downstream trace occurrences.
- Map affected artifacts to lifecycle skills and stages using metadata.
- Classify the safe action from current state: reopen complete work, revalidate active work, or add a pre-start validation gate.
- Order actions by canonical lifecycle stage order and retain all evidence.
- Emit or write the analysis, then hand approved actions to owning skills.
Output Spec
The TOON schema ai-sdlc-change-impact/v1 contains changes, affected artifacts,
stage status, blockers, and actions with stage, skill, action, reason,
evidence_path, evidence_line, changed_ref, and expected_artifact.
Quality gate:
- Pass when every change has valid source evidence and every impact/action is backed by an exact downstream trace occurrence.
- Full flow fails when state is absent, source evidence is invalid, or an affected artifact cannot be mapped to a lifecycle owner.
Examples
Valid change:
{"id":"CHG-001","changed_ref":"AC-004","source":{"path":"requirements.md","line":121,"detail":"Retry behavior changed from optional to required."}}
Invalid counter-example: The requirements changed recently. It cannot prove
which durable source changed or which downstream artifacts are stale.
Edge Cases
- A valid change with no downstream occurrence reports no stale artifact and recommends targeted trace review rather than broad reopening.
- Multiple occurrences in one artifact are collapsed into one affected row per changed reference using the earliest exact line as evidence.
- Unknown artifact owners block full flow but remain visible in quick flow.
- Already active stages are revalidated, never reopened concurrently.
Scope Boundary
- Do not mutate lifecycle state, indexes, source artifacts, or policy.
- Do not reopen a stage solely because it follows another stage chronologically.
- Do not treat filename similarity or model intuition as impact evidence.
- Do not approve recovery actions on behalf of artifact owners.
- Use
$ai-sdlc-navigatorwhen the owning workflow is unclear.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/mikegorelikoff/ai-sdlc-harness/ai-sdlc-change-impact">View ai-sdlc-change-impact on skillZs</a>