# Review Tech Lifecycle

> Technology lifecycle review for runtime, framework, build-tool, plugin, dependency, and API support status, deprecation, compatibility, and migration pressure. Use for end-of-life, upgrade-readiness, or obsolete-technology questions.

- Skill: `kenlck/review-tech-lifecycle` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add kenlck/review-tech-lifecycle`
- Raw SKILL.md: https://api.skillmd.com/api/skills/kenlck/review-tech-lifecycle/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: kenlck (https://skillmd.com/u/kenlck)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/kenlck/review-tech-lifecycle

---


# Review technology lifecycle

Assess one repository, a repository group, or an existing fleet evidence bundle. Keep upstream support status, local policy preference, and migration urgency distinct.

## Run the lens

1. Read the [standalone lens protocol](../audit-software-fleet/references/standalone-lens.md) completely and prepare the supplied scope with lens ID `tech-lifecycle`.
2. Read [the lifecycle checks](references/checks.md) completely. Apply every check family relevant to the detected stacks, repository roles, and policy.
3. Classify evidenced outcomes as strengths or findings. Record unanswered questions as unknowns and unavailable sources as incomplete coverage. Preserve official support, policy fit, compatibility, and migration effort as separate claims.
4. Follow the protocol to account for every contract-registered check family, validate the result, ingest it, and hand back the canonical artifact path.

For raw collection, deep execution, or refreshed lifecycle data, read and follow the [safety model](../audit-software-fleet/references/safety-model.md). Use cached policy and lifecycle evidence by default.

Read [lifecycle sources](../audit-software-fleet/references/lifecycle-sources.md) whenever judging upstream support or refreshing time-sensitive facts.

## Boundary

Own support windows, deprecation, compatibility, and migration pressure. Route exploitability to application security and build provenance or artifact integrity to delivery and supply chain.

## Completion

**Complete when:** every in-scope repository has an exact commit or explicit unavailable state, every applicable check family is accounted for, every claim has bounded sanitized evidence at an appropriate confidence, gaps remain visible in unknowns and coverage, and the shared result validator succeeds.

