Dana-Afazeli/agentic-swe-kit
A maintained template for the agentic-SWE harness: proven gates, Claude Code hooks, CI, a headless review loop, and the workflow docs behind them. Use this template, run kit.py init, take updates with kit.py update.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit Dana-Afazeli/agentic-swe-kit/.claude ./rig-agentic-swe-kit # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit Dana-Afazeli/agentic-swe-kit/.claude/skills/review-loop .claude/skills/review-loop $ curl -fsSL --create-dirs -o .claude/agents/plan-reviewer.md https://raw.githubusercontent.com/Dana-Afazeli/agentic-swe-kit/main/.claude/agents/plan-reviewer.md Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git push origin main)",
"Bash(git push -u origin main)",
"Bash(git push origin HEAD:main)",
"Bash(git reset --hard:*)",
"Bash(rm -rf ~:*)",
"Bash(git commit --no-verify:*)",
"Bash(gh label:*)",
"Bash(gh pr edit --add-label:*)",
"Bash(gh pr edit --remove-label:*)"
],
"ask": [
"Bash(gh pr merge:*)",
"Edit(/.claude/**)",
"Edit(/.github/**)",
"Edit(/scripts/**)",
"Edit(/kit.py)",
"Edit(/Makefile)",
"Edit(/pyproject.toml)",
"Edit(/uv.lock)",
"Edit(/.pre-commit-config.yaml)",
"Edit(/.python-version)",
"Edit(/.gitignore)",
"Edit(/.betterleaks.toml)",
"Edit(/.betterleaksignore)",
"Edit(/GNUmakefile)",
"Edit(/makefile)",
"Edit(/pytest.toml)",
"Edit(/.pytest.toml)",
"Edit(/pytest.ini)",
"Edit(/.pytest.ini)",
"Edit(/ruff.toml)",
"Edit(/.ruff.toml)",
"Edit(/pyrightconfig.json)",
"Edit(/.coveragerc)",
"Edit(/.coveragerc.toml)",
"Edit(/.importlinter)",
"Edit(/setup.cfg)",
"Edit(/tox.ini)",
"Edit(/uv.toml)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "uv run --project \"$CLAUDE_PROJECT_DIR\" python \"$CLAUDE_PROJECT_DIR/scripts/guard_bash.py\""
}
]
}
]
}
} Skills (1)
Subagents (1)
| plan-reviewer model: sonnet | Conformance review of a pull request against its brief. Give it the path of the brief and the PR number. It reports only gaps between the two — an acceptance criterion with no test that bites, a chang |
Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | uv run --project "$CLAUDE_PROJECT_DIR" python "$CLAUDE_PROJECT_DIR/scripts/guard_bash.py" |
| PostToolUse | Edit|Write | uv run --project "$CLAUDE_PROJECT_DIR" python "$CLAUDE_PROJECT_DIR/scripts/fmt_hook.py" |
| Stop | * | uv run --project "$CLAUDE_PROJECT_DIR" python "$CLAUDE_PROJECT_DIR/scripts/stop_gate.py" |
Permissions
deny (11)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git push origin main)
Bash(git push -u origin main)
Bash(git push origin HEAD:main)
Bash(git reset --hard:*)
Bash(rm -rf ~:*)
Bash(git commit --no-verify:*)
Bash(gh label:*)
Bash(gh pr edit --add-label:*)
Bash(gh pr edit --remove-label:*)
ask (28)
Bash(gh pr merge:*)
Edit(/.claude/**)
Edit(/.github/**)
Edit(/scripts/**)
Edit(/kit.py)
Edit(/Makefile)
Edit(/pyproject.toml)
Edit(/uv.lock)
Edit(/.pre-commit-config.yaml)
Edit(/.python-version)
Edit(/.gitignore)
Edit(/.betterleaks.toml)
Edit(/.betterleaksignore)
Edit(/GNUmakefile)
Edit(/makefile)
Edit(/pytest.toml)
Edit(/.pytest.toml)
Edit(/pytest.ini)
Edit(/.pytest.ini)
Edit(/ruff.toml)
Edit(/.ruff.toml)
Edit(/pyrightconfig.json)
Edit(/.coveragerc)
Edit(/.coveragerc.toml)
Edit(/.importlinter)
Edit(/setup.cfg)
Edit(/tox.ini)
Edit(/uv.toml)
allow (25)
Bash(make:*)
Bash(uv run:*)
Bash(uv sync:*)
Bash(uv add:*)
Bash(uv lock:*)
Bash(uv python:*)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git show:*)
Bash(git branch --show-current)
Bash(git fetch:*)
Bash(git pull)
Bash(git add:*)
Bash(git commit:*)
Bash(git switch main-:*)
Bash(git switch -c main-:*)
Bash(git push -u origin main-:*)
Bash(git push origin main-:*)
Bash(gh pr create --base main:*)
Bash(gh pr view:*)
Bash(gh pr checks:*)
Bash(gh pr ready:*)
Bash(gh pr diff:*)
Bash(gh run view:*)
Similar rigs
spxrogers/agentsync
Sync AI coding-agent configs (Claude Code, OpenCode, Codex, and more) from one canonical, committable source.
Pragmatist 12.8k tok ·
HGInsights/claude-code-setup
Production-tested Claude Code harness configuration: hooks, skills, subagents, and automated review loops
Pragmatist 1.9k tok ·
RemiAsselin42/claude-config
Memory, features, skills, and agents for Claude, centralized and versioned, one-command installation
Automator 2.1k tok ·
code-yeongyu/my-claude-code-harness
I'm confident this setup will become deprecated and outdated in less than 3 months
Pragmatist 2.8k tok ·