Stage 5 — Code Creation
Agents: bmad-agent-dev, bmad-quick-dev · Approvers: L1 Tech Lead · L2 Architect
Scaffold → Generate → Senior Review (Phase B) → OWASP Security Audit (Phase C).
Stages 4 & 5 require L1 + L2 dual approval from two separate named approvers.
-
Invoke Dev Agent: System calls
Skill: bmad-agent-dev→Skill: bmad-quick-dev -
Greenfield Scaffold: Creates project directory structure, package.json/pom.xml, config files, Docker-free startup scripts
-
Phase A — Code Generation (layer order must be respected):
- Configuration & Environment
- Data Layer (models, migrations, repositories)
- Service Layer (business logic)
- API Layer (controllers, routes, DTOs, validators)
- Integration Layer (external APIs, message queues)
- Entry Point & startup wiring
-
Phase B — Senior Code Review: Checks correctness, architecture conformance, and operability (logging, error handling, observability)
-
Phase C — OWASP Top 10 Security Audit: Maps each vulnerability category (injection, broken auth, XSS, IDOR, etc.) against the generated code; Critical & High findings auto-fixed before proceeding
-
Code Enforcer Audit:
agent-s5-code-enforcerreviews for residual issues -
Tech Lead L1 Approval
-
Architect L2 Approval → Stage 6 unlocks
Auth uses JWT RS256 (15-min access tokens + 7-day refresh cookie). Never store tokens in localStorage. Never generate secrets in code — always use environment variables.
Artifacts: docs/sdlc/{ProjectName}_05-code-creation.md · .docx, src/ (all source files)