adlc-govern
v2.4.0Governance and security for agentic development: OWASP Agentic Top 10 threat modeling, auto-mode-era agent permissions, guardrail hooks, compliance mapping (ISO 42001, NIST AI RMF, EU AI Act, SOC 2), extension vetting, and governance for non-engineers building with AI.
By Shmulik Davar — BrAIght WaveLicense: MIT1 GitHub starsUpdated 1 hour ago
Directory evidence
- Runtimes
- Codex and Claude Code
- Parsed components
- 6 skill or MCP entries
- Source updated
- Oct 1, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install adlc-govern for Codex and Claude Code
codex plugin marketplace add shmulikdav/adlc-skills
codex plugin marketplace upgrade adlc-skills
codex plugin add adlc-govern@adlc-skillsPaste and run these commands in a terminal with Codex. They add and refresh the adlc-skills catalog, then install this plugin.
Compatibility: the page URL and API slug “adlc-govern” remain stable.
- Codex:
adlc-govern@agent-plugin-marketplace→adlc-govern@adlc-skills
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/shmulikdav/adlc-skillsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is adlc-govern/.
Plugin files
├── .codex-plugin/plugin.json├── .claude-plugin/plugin.json├── skills/agent-permissions/SKILL.md├── skills/agentic-threat-model/SKILL.md├── skills/ai-compliance-mapping/SKILL.md├── skills/citizen-builder-governance/SKILL.md├── skills/extension-vetting/SKILL.md└── skills/guardrail-hooks/SKILL.md
Included Skills6
Use when configuring what a coding agent may read, edit, or run (Claude Code settings, permissions, sandboxing), deciding what runs without approval, setting up agents in CI or headless mode, or after a near-miss with an agent action.
Use when assessing the security of coding agents, MCP connections, CI agents, or an AI agent being built, preparing a security review of an agentic setup, or when a team asks what could go wrong if an agent is manipulated.
Use when preparing for an AI audit or certification (ISO/IEC 42001, SOC 2), answering customer security questionnaires about AI use in development, or aligning agentic development practices with NIST AI RMF or the EU AI Act.
Use when non-engineers (operations, finance, sales, legal, HR, analysts) are building tools, automations, or apps with Claude Cowork, Claude Code, Lovable, or similar, when shadow AI apps appear on company data, or when leaders ask how to enable business teams to build without creating security and maintenance risk.
Use when someone asks whether a skill, plugin, MCP server, hook, or agent rules file is safe to install, before adding a new plugin marketplace, or when building an approved-extensions list for a team.
Use when a rule must be enforced every time rather than remembered, when CLAUDE.md instructions are not followed reliably, when protecting secrets, CI config, or migrations from agent edits, or when setting up Claude Code hooks.
Plugin manifests2
{
"name": "adlc-govern",
"version": "2.4.0",
"description": "Governance and security for agentic development: OWASP Agentic Top 10 threat modeling, auto-mode-era agent permissions, guardrail hooks, compliance mapping (ISO 42001, NIST AI RMF, EU AI Act, SOC 2), extension vetting, and governance for non-engineers building with AI.",
"author": {
"name": "Shmulik Davar — BrAIght Wave",
"email": "[email protected]",
"url": "https://www.braightwave.com"
},
"homepage": "https://braightwave.com/adlc",
"repository": "https://github.com/shmulikdav/adlc-skills",
"license": "MIT",
"keywords": [
"adlc",
"ai-security",
"owasp",
"governance",
"iso-42001",
"hooks",
"citizen-developers"
],
"skills": [
"./skills/",
"./workflows/"
],
"interface": {
"displayName": "ADLC Govern",
"shortDescription": "Security, permissions & compliance",
"longDescription": "Governance and security for agentic development: OWASP Agentic Top 10 threat modeling, auto-mode-era agent permissions, guardrail hooks, compliance mapping (ISO 42001, NIST AI RMF, EU AI Act, SOC 2), extension vetting, and governance for non-engineers building with AI.",
"developerName": "BrAIght Wave",
"category": "Coding",
"capabilities": [
"Interactive",
"Write"
],
"websiteURL": "https://braightwave.com/adlc",
"defaultPrompt": [
"Run $citizen-builder-policy",
"Run $governance-pack",
"Run $threat-model"
]
}
}{
"name": "adlc-govern",
"displayName": "ADLC Govern",
"version": "2.4.0",
"description": "Governance and security for agentic development: OWASP Agentic Top 10 threat modeling, auto-mode-era agent permissions, guardrail hooks, compliance mapping (ISO 42001, NIST AI RMF, EU AI Act, SOC 2), extension vetting, and governance for non-engineers building with AI.",
"author": {
"name": "Shmulik Davar — BrAIght Wave",
"email": "[email protected]",
"url": "https://www.braightwave.com"
},
"homepage": "https://github.com/shmulikdav/adlc-skills",
"repository": "https://github.com/shmulikdav/adlc-skills",
"license": "MIT",
"keywords": [
"adlc",
"ai-security",
"owasp",
"governance",
"iso-42001",
"hooks",
"citizen-developers"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[adlc-govern on Agent Plugins Marketplace](https://pluginsmp.com/plugins/adlc-govern)