Skip to content

[Preset]: Add SicarioSpec Core #3101

Description

@SiCar10mw

Preset ID

sicario-core

Preset Name

SicarioSpec Core

Version

0.4.0

Description

Evidence-first security operations governance that maps feature risk to controls, gates, evidence, owners, approval, and accepted-risk decisions.

Author

SicarioSpec Contributors

Repository URL

https://github.com/dfirs1car1o/sicario-spec

Download URL

https://github.com/dfirs1car1o/sicario-spec/releases/download/v0.4.0/sicario-core-0.4.0.zip

License

MIT

Required Spec Kit Version

=0.9.0

Required Extensions (optional)

None

Templates Provided

  • spec-template.md - adds data classification, trust boundaries, abuse cases, operational signal paths, and the Security Evidence Chain.
  • plan-template.md - maps risks to controls, gates, evidence, rollback, and readiness decisions.
  • tasks-template.md - turns security, compliance, documentation, evidence, and verification work into explicit delivery tasks.
  • checklist-template.md - checks secure-by-default specification, planning, task, and verification review.
  • constitution-template.md - establishes least privilege, deterministic gates, evidence integrity, and human approval principles.

Commands Provided

None

Number of Scripts (optional)

0

Tags

security, governance, security-ops, secure-by-default, evidence

Key Features

  • Security Evidence Chain from feature intent through approval or accepted risk.
  • Feature specs capture classification, trust boundaries, abuse cases, operational signal paths, and evidence expectations.
  • Implementation plans carry threat model, control mapping, rollback, and review checkpoints.
  • Tasks and checklists make evidence, verification, ownership, and release approval explicit.
  • Release archive is preset-rooted and tested with specify preset add --from.

Related PR

#3100

Testing Checklist

  • Preset installs successfully via specify preset add
  • Template resolution works correctly after installation
  • Documentation is complete and accurate
  • Tested on at least one real project

Submission Requirements

  • Valid preset.yml manifest included
  • README.md with description and usage instructions
  • LICENSE file included
  • GitHub release created with version tag
  • Preset ID follows naming conventions (lowercase-with-hyphens)

Validation Evidence

  • Release archive installed successfully in a fresh Spec Kit project initialized with specify init --here --integration claude --ignore-agent-tools --no-git --force.
  • Verified specify preset info sicario-core reports SicarioSpec Core v0.4.0, the repository URL, and five provided templates.
  • Verified specify preset resolve spec-template resolves to the installed SicarioSpec Core preset template.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions