MuhammedZohaib/patchman
Defensive AI security audit skill for Claude and Codex. Reviews codebases and web apps for OWASP Top 10, auth and authorization flaws, business logic bugs, tenant isolation gaps, insecure defaults, secret leaks, and ORM or N+1 query issues,
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code $ npx degit MuhammedZohaib/patchman/commands ./rig-patchman/commands $ npx degit MuhammedZohaib/patchman/skills ./rig-patchman/skills $ npx degit MuhammedZohaib/patchman/hooks ./rig-patchman/hooks
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit <redacted>-review .claude/skills/api-review $ npx degit <redacted>-review .claude/skills/auth-review $ npx degit <redacted>-logic-review .claude/skills/business-logic-review $ npx degit <redacted>-diff-review .claude/skills/pr-diff-review $ npx degit <redacted>-review .claude/skills/query-review $ npx degit <redacted>-triage .claude/skills/quick-triage $ npx degit <redacted>-audit .claude/skills/security-audit
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (7)
Slash commands (9)
/api-review/audit-report/auth-review/bizlogic-review/pr-diff-review/query-review/quick-triage/security-audit/threat-model
Cursor rules (1)
patchman
Similar rigs
TheDecipherist/claude-code-mastery
The complete guide to Claude Code: CLAUDE.md, hooks, skills, MCP servers, and commands
Pragmatist 823 tok ·
jLAM-ERR/corp-llm-gateway
Corporate LLM gateway. Sanitizes traffic between developer Claude Code instances and Anthropic/OpenAI before it leaves the corp boundary.
Pragmatist 6.6k tok ·
pravindurgani/claude-code-multipane-iterm2
Stop your AI agent from reviewing its own code — 4-pane iTerm2 setup with role-locked Claude Code sessions. Step-by-step guide included.
Minimalist 1.0k tok ·
spawnpoint-inc/spawnpoint-plugin
Claude Code plugin for spawnpoint: your agent builds it, spawnpoint puts it online, you get a link.
Minimalist 187 tok ·