~ / rigs / MuhammedZohaib / patchman

MuhammedZohaib/patchman

Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for OWASP Top 10, auth and authorization flaws, business logic bugs, tenant isolation gaps, insecure defaults, secret leaks, and ORM or N+1 query issues,

↗ GitHub ★ 3 MIT updated 6mo ago project Claude CodeCodexCursor Claude plugin
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~655 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
1/5
No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit MuhammedZohaib/patchman/commands ./rig-patchman/commands
$ npx degit MuhammedZohaib/patchman/skills ./rig-patchman/skills
$ npx degit MuhammedZohaib/patchman/hooks ./rig-patchman/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit <redacted>-review .claude/skills/api-review
$ npx degit <redacted>-review .claude/skills/auth-review
$ npx degit <redacted>-logic-review .claude/skills/business-logic-review
$ npx degit <redacted>-diff-review .claude/skills/pr-diff-review
$ npx degit <redacted>-review .claude/skills/query-review
$ npx degit <redacted>-triage .claude/skills/quick-triage
$ npx degit <redacted>-audit .claude/skills/security-audit

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (7)

Slash commands (9)

/api-review/audit-report/auth-review/bizlogic-review/pr-diff-review/query-review/quick-triage/security-audit/threat-model

Cursor rules (1)

patchman

Similar rigs

copied ✓