YounusHussain9/claude-agent-workspace
Multi-repo workspace for Claude Code: plain-language requests, specialist AI agents, approval gates and safety hooks.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit YounusHussain9/claude-agent-workspace/.claude ./rig-claude-agent-workspace # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit YounusHussain9/claude-agent-workspace/.claude/skills/data .claude/skills/data $ npx degit YounusHussain9/claude-agent-workspace/.claude/skills/feature .claude/skills/feature $ npx degit YounusHussain9/claude-agent-workspace/.claude/skills/intake .claude/skills/intake
$ curl -fsSL --create-dirs -o .claude/agents/backend.md https://raw.githubusercontent.com/YounusHussain9/claude-agent-workspace/main/.claude/agents/backend.md $ curl -fsSL --create-dirs -o .claude/agents/designer.md https://raw.githubusercontent.com/YounusHussain9/claude-agent-workspace/main/.claude/agents/designer.md $ curl -fsSL --create-dirs -o .claude/agents/frontend.md https://raw.githubusercontent.com/YounusHussain9/claude-agent-workspace/main/.claude/agents/frontend.md $ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/YounusHussain9/claude-agent-workspace/main/.claude/agents/planner.md $ curl -fsSL --create-dirs -o .claude/agents/qa.md https://raw.githubusercontent.com/YounusHussain9/claude-agent-workspace/main/.claude/agents/qa.md $ curl -fsSL --create-dirs -o .claude/agents/reviewer.md https://raw.githubusercontent.com/YounusHussain9/claude-agent-workspace/main/.claude/agents/reviewer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(git commit:*)",
"Bash(git push:*)",
"Bash(git merge:*)",
"Bash(git rebase:*)",
"Bash(git pull:*)",
"Bash(git cherry-pick:*)",
"Bash(git reset:*)",
"Bash(git stash:*)",
"Bash(git checkout:*)",
"Bash(git switch:*)",
"Bash(git apply:*)",
"Bash(gh pr merge:*)",
"Bash(bin/approve:*)",
"Bash(./bin/approve:*)",
"Read(./.secrets/**)",
"Edit(./.secrets/**)",
"Write(./.secrets/**)",
"Read(./**/.env)",
"Read(./**/.env.*)",
"Edit(./**/.env)",
"Edit(./**/.env.*)",
"Write(./**/.env)",
"Write(./**/.env.*)",
"Edit(./bin/approve)",
"Write(./bin/approve)",
"Edit(./.claude/hooks/**)",
"Write(./.claude/hooks/**)",
"Edit(./.claude/settings.json)",
"Write(./.claude/settings.json)"
],
"ask": [
"mcp__claude_ai_Shortcut__stories-create",
"mcp__claude_ai_Shortcut__stories-update",
"mcp__claude_ai_Shortcut__stories-create-comment",
"mcp__claude_ai_Shortcut__stories-add-task",
"mcp__claude_ai_Shortcut__stories-update-task",
"mcp__claude_ai_Shortcut__epics-create",
"mcp__claude_ai_Shortcut__epics-update",
"mcp__claude_ai_Shortcut__epics-delete"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Agent",
"hooks": [
{
"type": "command",
"command": "bash \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/approval-gate.sh"
}
]
},
{
"matcher": "Edit|Write|MultiEdit",
"hooks": [
{
"type": "command",
"command": "bash \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/no-self-approve.sh"
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "bash \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/bash-guard.sh"
}
]
}
]
}
} Skills (3)
Subagents (6)
| backend model: sonnet | One backend lane (an endpoint group, service or job). Builds exactly to contract.md with validation, server-side auth and tests. Runs in parallel with frontend and QA lanes. |
| designer model: sonnet | Turns a Figma link, image or URL into a per-element spec.md plus reference images for one feature. With no design source, builds mockup.html in the existing screen's look and screenshots it. |
| frontend model: sonnet | Builds the approved UI from plan.md (context map), the contract and design/spec.md. Design tokens only, every state, with tests. No new packages, no git. |
| planner model: sonnet | Detects each repo's stack and writes missing .claude/rules files from the real code. For M/L features it asks gap questions, then writes docs/features/<name>/plan.md with acceptance criteria and a con |
| qa model: sonnet | One QA lane. Writes end-to-end tests (Playwright by default) from the plan's acceptance criteria, spec.md and contract samples, not from app code, while the build lanes run; then runs them when told " |
| reviewer model: sonnet | Read-only review of a repo's diff (plus untracked files) against plan.md acceptance criteria, the contract, decisions and the repo's rules. Edits nothing. |
Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Agent | bash "$CLAUDE_PROJECT_DIR"/.claude/hooks/approval-gate.sh |
| PreToolUse | Edit|Write|MultiEdit | bash "$CLAUDE_PROJECT_DIR"/.claude/hooks/no-self-approve.sh |
| PreToolUse | Bash | bash "$CLAUDE_PROJECT_DIR"/.claude/hooks/bash-guard.sh |
Permissions
deny (29)
Bash(git commit:*)
Bash(git push:*)
Bash(git merge:*)
Bash(git rebase:*)
Bash(git pull:*)
Bash(git cherry-pick:*)
Bash(git reset:*)
Bash(git stash:*)
Bash(git checkout:*)
Bash(git switch:*)
Bash(git apply:*)
Bash(gh pr merge:*)
Bash(bin/approve:*)
Bash(./bin/approve:*)
Read(./.secrets/**)
Edit(./.secrets/**)
Write(./.secrets/**)
Read(./**/.env)
Read(./**/.env.*)
Edit(./**/.env)
Edit(./**/.env.*)
Write(./**/.env)
Write(./**/.env.*)
Edit(./bin/approve)
Write(./bin/approve)
Edit(./.claude/hooks/**)
Write(./.claude/hooks/**)
Edit(./.claude/settings.json)
Write(./.claude/settings.json)
ask (8)
mcp__claude_ai_Shortcut__stories-create
mcp__claude_ai_Shortcut__stories-update
mcp__claude_ai_Shortcut__stories-create-comment
mcp__claude_ai_Shortcut__stories-add-task
mcp__claude_ai_Shortcut__stories-update-task
mcp__claude_ai_Shortcut__epics-create
mcp__claude_ai_Shortcut__epics-update
mcp__claude_ai_Shortcut__epics-delete
allow (10)
Bash(node bin/scan-repos.js:*)
Bash(node bin/api-scan.js:*)
Bash(node bin/api-get.js:*)
Bash(node bin/data-count.js:*)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git show:*)
Bash(git blame:*)
Bash(git branch --show-current)
Similar rigs
eugeek/claude-config-tdd
Claude Code config with TDD workflow, plan -> tests -> red -> implementation -> green -> review -> shipment
Orchestrator 5.8k tok ·
Markuysa/vibe-coding-template
Claude Code project template: five agent roles with tool-level permission boundaries, four workflow commands, and a permission baseline that keeps secrets and build noise out of context. Built on native worktrees and subagents — no third-pa
Fort Knox 1.2k tok ·
xhulz/nina
Harness orchestration for Claude Code: composes a gated multi-agent pipeline into projects from versioned layers, holds its loop caps with hooks, measures it from transcripts, and turns recurring mistakes into rules.
Orchestrator 9.3k tok ·
diegosvart/main-base-claude-code
Claude Code project template with inception agent, specialized subagents, and quality-enforced workflows. From idea to codebase in one structured discovery session.
Orchestrator 52 tok ·