Skip to content

[Preset]: Add SicarioSpec Core v0.5.1 #3164

Description

@SiCar10mw

Preset ID

sicario-core

Preset Name

SicarioSpec Core

Version

0.5.1

Description

Baseline secure-by-default Spec Kit governance profile.

Author

SicarioSpec Contributors

Repository URL

https://github.com/dfirs1car1o/sicario-spec

Download URL

https://github.com/dfirs1car1o/sicario-spec/releases/download/v0.5.1/sicario-core-0.5.1.zip

Documentation URL

https://github.com/dfirs1car1o/sicario-spec/blob/main/presets/sicario-core/README.md

License

MIT

Required Spec Kit Version

=0.9.0

Required Extensions (optional)

None

Templates Provided

  • spec-template.md - adds data classification, trust boundaries, abuse cases, security requirements, control applicability, operational signal paths, misuse cases, and evidence expectations.
  • plan-template.md - maps risks to controls, gates, owners, evidence paths, rollback, operational readiness, and approval decisions.
  • tasks-template.md - turns evidence-chain, control, test, verification, documentation, and handoff work into explicit delivery tasks.
  • checklist-template.md - checks secure-by-default specification, planning, task, and verification review.
  • constitution-template.md - establishes least privilege, deterministic gates, evidence integrity, trust-boundary sanitization, and human approval principles.

Commands Provided

None

Number of Scripts (optional)

0

Tags

governance, security-ops, secure-by-default, evidence

Key Features

  • Security Evidence Chain from feature intent through control, gate, evidence, owner, and approval or accepted risk.
  • Secure-by-default feature specs with classification, tagging, trust boundaries, abuse cases, signal paths, and evidence expectations.
  • Implementation plans that map risks and decisions to controls, tests, CI/security gates, rollback, and human approval points.
  • Task and checklist templates that make verification, documentation impact, control evidence, and release handoff explicit.
  • Release archive installs cleanly with specify preset add --from and keeps the preset scoped to templates only.

Related PR

#3160 was closed at maintainer request to submit this version update through the preset submission issue template.

Testing Checklist

  • Preset installs successfully via specify preset add
  • Template resolution works correctly after installation
  • Documentation is complete and accurate
  • Tested on at least one real project

Submission Requirements

  • Valid preset.yml manifest included
  • Linked README (Documentation URL) explains how to use this preset and includes a valid specify preset add ... command using the exact Download URL
  • LICENSE file included
  • GitHub release created with version tag
  • Preset ID follows naming conventions (lowercase-with-hyphens)

Validation Evidence

  • curl -fsSI https://github.com/dfirs1car1o/sicario-spec/releases/download/v0.5.1/sicario-core-0.5.1.zip returned a GitHub release-asset redirect.
  • The preset-scoped README at presets/sicario-core/README.md contains the exact install command specify preset add --from https://github.com/dfirs1car1o/sicario-spec/releases/download/v0.5.1/sicario-core-0.5.1.zip.
  • Fresh Spec Kit project initialized with specify init --here --integration claude --ignore-agent-tools --force using specify 0.11.8.
  • Installed release archive successfully with specify preset add --from https://github.com/dfirs1car1o/sicario-spec/releases/download/v0.5.1/sicario-core-0.5.1.zip.
  • Verified specify preset info sicario-core reports SicarioSpec Core v0.5.1, MIT license, repository URL, four tags, and five templates.
  • Verified specify preset resolve spec-template, plan-template, tasks-template, checklist-template, and constitution-template all resolve to .specify/presets/sicario-core/templates/.
  • Release asset digest reported by GitHub: sha256:c88d61cb2e8a23a2f1ce4daafbddeb663e2dfac826e945fc805aa979a0e1fdc3.

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions