~ / rigs / AnshumanAtrey / redink

AnshumanAtrey/redink

Compose pentest reports from 28 modular sections for 17+ compliance frameworks. Claude Code plugin + AGENTS.md compatible (codex, cursor, gemini, aider, kimi).

↗ GitHub ★ 0 MIT updated 5mo ago project Claude CodeCodex Claude plugin
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~3.7k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit AnshumanAtrey/redink/.claude ./rig-redink  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/cve-validator.md https://raw.githubusercontent.com/AnshumanAtrey/redink/main/.claude/agents/cve-validator.md
$ curl -fsSL --create-dirs -o .claude/agents/cvss-calculator.md https://raw.githubusercontent.com/AnshumanAtrey/redink/main/.claude/agents/cvss-calculator.md
$ curl -fsSL --create-dirs -o .claude/agents/cwe-validator.md https://raw.githubusercontent.com/AnshumanAtrey/redink/main/.claude/agents/cwe-validator.md
$ curl -fsSL --create-dirs -o .claude/agents/epss-lookup.md https://raw.githubusercontent.com/AnshumanAtrey/redink/main/.claude/agents/epss-lookup.md
$ curl -fsSL --create-dirs -o .claude/agents/finding-writer.md https://raw.githubusercontent.com/AnshumanAtrey/redink/main/.claude/agents/finding-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/report-reviewer.md https://raw.githubusercontent.com/AnshumanAtrey/redink/main/.claude/agents/report-reviewer.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,974 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(~/.aws/**)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(.env)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/.env.*)",
      "Read(**/*.key)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(npm publish:*)",
      "Bash(wget *)",
      "Bash(git rebase *)",
      "Bash(gh pr merge *)",
      "Bash(git commit *)"
    ]
  }
}

Subagents (6)

cve-validatorValidates a CVE citation against NVD. Fetches https://nvd.nist.gov/vuln/detail/<cve>, confirms the affected version range matches the target version, and returns the exact-quote version-range excerpt.
cvss-calculatorComputes CVSS v3.1 base score per FIRST.org spec. Shows per-metric reasoning and ISC/Impact/Exploitability/Base math. Never trusts a prefetched score — always recomputes. Framework-agnostic.
cwe-validatorValidates a CWE citation against MITRE. Fetches https://cwe.mitre.org/data/definitions/<n>.html, reads the Vulnerability Mapping Notes → Usage value, and returns an exact-quote excerpt. Rejects PROHIB
epss-lookupFetches EPSS probability for a CVE from api.first.org. Returns the exact-quote API response and the formatted EPSS line. Framework-agnostic.
finding-writerWrites one finding entry for a single poc/ folder, conforming to the active framework's schema. Reads frameworks/<active>/prompt.md to shape the output. Delegates CWE/CVE/CVSS/EPSS validation to speci
report-reviewerAdversarial QA pass over all generated finding JSONs. Independently re-fetches every cited CWE/CVE/EPSS and compares against the entry's audit-trail excerpts. Flags any drift in output/qa-report.md. F

Slash commands (5)

/redink-build/redink-frameworks/redink-rebuild/redink-recipe/redink-status

Similar rigs

copied ✓