~ / rigs / Saba-Var / claude-ward

Saba-Var/claude-ward

A read-only tripwire that watches Claude Code's local config and reports suspicious changes.

↗ GitHub ★ 2 MIT updated 3mo ago project Claude CodeCodex
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~1.8k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
2/5
Protects secrets · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit Saba-Var/claude-ward/.claude ./rig-claude-ward  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/implementer.md https://raw.githubusercontent.com/Saba-Var/claude-ward/main/.claude/agents/implementer.md
$ curl -fsSL --create-dirs -o .claude/agents/reviewer.md https://raw.githubusercontent.com/Saba-Var/claude-ward/main/.claude/agents/reviewer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./**/.credentials.json)",
      "Read(~/.claude/.credentials.json)",
      "Bash(curl:*)",
      "Bash(wget:*)"
    ]
  }
}

Subagents (2)

implementer
model: inherit
Implements a single task from a claude-ward plan during spec-driven development. Use when executing one well-scoped task test-first, then committing. Delegate one task at a time.
reviewer
model: inherit
Reviews a completed claude-ward task or diff before it is accepted. Use after an implementer finishes a task. Checks spec compliance first, then code quality and the project's trust-critical constrain

Slash commands (3)

/build/plan/spec

Permissions

deny (6)
Read(./.env)
Read(./.env.*)
Read(./**/.credentials.json)
Read(~/.claude/.credentials.json)
Bash(curl:*)
Bash(wget:*)
ask (0)
—
allow (15)
Bash(npm test:*)
Bash(npm run test:*)
Bash(npm run test:watch:*)
Bash(npm run typecheck:*)
Bash(npm run lint:*)
Bash(npm run format:*)
Bash(npm run build:*)
Bash(npx vitest:*)
Bash(npx tsc:*)
Bash(npx eslint:*)
Bash(npx prettier:*)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git add:*)

Similar rigs

copied ✓