~ / rigs / alipajand / agent-context-doctor

alipajand/agent-context-doctor

Audit agent context files like AGENTS.md, CLAUDE.md, .cursor/rules/*.mdc, .github/copilot-instructions.md, and prompt docs for quality, safety, contradictions, and repo alignment.

↗ GitHub ★ 1 MIT updated 1d ago project Claude CodeCodexCursor
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.5k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit alipajand/agent-context-doctor/.claude ./rig-agent-context-doctor  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit alipajand/agent-context-doctor/.claude/skills/adding-an-audit-check .claude/skills/adding-an-audit-check
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/alipajand/agent-context-doctor/main/.claude/agents/security-reviewer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Bash(curl:*)",
      "Bash(wget:*)",
      "Bash(rm -rf:*)",
      "Bash(git push --force:*)",
      "Bash(git reset --hard:*)"
    ],
    "ask": [
      "Bash(git commit:*)",
      "Bash(git push:*)",
      "Bash(pnpm add:*)",
      "Bash(pnpm install:*)",
      "Bash(pnpm update:*)"
    ]
  }
}

Skills (1)

Subagents (1)

security-reviewerReviews a change to agent-context-doctor against its security rules. Use before finishing changes to file reading or writing, report output, or the CLI.

Slash commands (2)

/audit-self/verify

Cursor rules (2)

project · alwaysproject

Permissions

deny (7)
Read(./.env)
Read(./.env.*)
Bash(curl:*)
Bash(wget:*)
Bash(rm -rf:*)
Bash(git push --force:*)
Bash(git reset --hard:*)
ask (5)
Bash(git commit:*)
Bash(git push:*)
Bash(pnpm add:*)
Bash(pnpm install:*)
Bash(pnpm update:*)
allow (13)
Bash(pnpm format)
Bash(pnpm format:check)
Bash(pnpm typecheck)
Bash(pnpm lint)
Bash(pnpm test)
Bash(pnpm test:*)
Bash(pnpm build)
Bash(pnpm dev audit:*)
Bash(pnpm dev checks)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git show:*)

Similar rigs

copied ✓