The Rig Report #1
This week in public AI-agent setups: 2,169 of the 6,413 rigs we index were updated in the last 7 days. Here's what stood out.
Stat of the week
73%
of 6,413 public AI-agent rigs score 0/5 on guardrails: no deny rules, no pre-tool hook, nothing. Only 34 score 5/5. More →
Fresh rigs worth stealing from
Updated this week, well guarded (3+/5) and lean.
Rising tools
- mcp.amplitude.com (MCP) in 6 rigs from 6 owners · 0.17% of active rigs vs 0% of older ones (×5.5)
- mcp.grep.app (MCP) in 11 rigs from 10 owners · 0.28% of active rigs vs 0.04% of older ones (×4.3)
- mcp.hubspot.com (MCP) in 5 rigs from 5 owners · 0.14% of active rigs vs 0% of older ones (×4.7)
- typesafe-ai (skill) in 17 rigs from 17 owners · 0.47% of active rigs vs 0% of older ones (×14.2)
- diagnosing-bugs (skill) in 53 rigs from 53 owners · 1.39% of active rigs vs 0.11% of older ones (×10.1)
- test-audit (skill) in 16 rigs from 16 owners · 0.45% of active rigs vs 0% of older ones (×13.4)
Full trending list and method →
This slot is open. Reach people who wire up AI agents for a living: book an issue ($99) or read the details.
Guardrail tip: Deny secret reads before anything else
Most rigs that leak keys never meant to: the agent just ran `cat .env` while debugging. Two lines in .claude/settings.json stop it:
{
"permissions": {
"deny": ["Read(./.env)", "Read(./.env.*)", "Read(~/.ssh/**)", "Read(**/*.pem)"]
}
}Check your own rig in 30 seconds with the Rig Doctor.
Starter of the week
Frontend web: React / Next.js / Vue / Svelte UIs. AGENTS.md, guarded settings.json, guard hook and skills in one command.