Skip to main content

Stage 5 — Code Creation

Agents: bmad-agent-dev, bmad-quick-dev · Approvers: L1 Tech Lead · L2 Architect

Scaffold → Generate → Senior Review (Phase B) → OWASP Security Audit (Phase C).

warning

Stages 4 & 5 require L1 + L2 dual approval from two separate named approvers.

  1. Invoke Dev Agent: System calls Skill: bmad-agent-dev → Skill: bmad-quick-dev

  2. Greenfield Scaffold: Creates project directory structure, package.json/pom.xml, config files, Docker-free startup scripts

  3. Phase A — Code Generation (layer order must be respected):

    1. Configuration & Environment
    2. Data Layer (models, migrations, repositories)
    3. Service Layer (business logic)
    4. API Layer (controllers, routes, DTOs, validators)
    5. Integration Layer (external APIs, message queues)
    6. Entry Point & startup wiring
  4. Phase B — Senior Code Review: Checks correctness, architecture conformance, and operability (logging, error handling, observability)

  5. Phase C — OWASP Top 10 Security Audit: Maps each vulnerability category (injection, broken auth, XSS, IDOR, etc.) against the generated code; Critical & High findings auto-fixed before proceeding

  6. Code Enforcer Audit: agent-s5-code-enforcer reviews for residual issues

  7. Tech Lead L1 Approval

  8. Architect L2 Approval → Stage 6 unlocks

info

Auth uses JWT RS256 (15-min access tokens + 7-day refresh cookie). Never store tokens in localStorage. Never generate secrets in code — always use environment variables.

Artifacts: docs/sdlc/{ProjectName}_05-code-creation.md · .docx, src/ (all source files)