~ / rigs / arsen-ask-lx / Agent_Quality_Kit

arsen-ask-lx/Agent_Quality_Kit

A check that cannot fail looks exactly like a check that passes. AQK plants a known defect into a copy of your most-repaired file, runs your own declared checks against it, and counts a catch only when one names the planted file. Zero depen

↗ GitHub ★ 4 MIT updated 12d ago project Claude CodeCodex Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~32.1k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add browser -- npx -y chrome-devtools-mcp@1.9.0
$ claude mcp add search -- uvx some-search-mcp==0.4.1
$ claude mcp add own-code -- npx tsx rag/src/index.ts
$ npx degit arsen-ask-lx/Agent_Quality_Kit/.claude ./rig-agent_quality_kit  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add browser -- npx -y chrome-devtools-mcp@1.9.0
$ claude mcp add search -- uvx some-search-mcp==0.4.1
$ claude mcp add own-code -- npx tsx rag/src/index.ts
$ npx degit arsen-ask-lx/Agent_Quality_Kit/.claude/skills/growth .claude/skills/growth
$ npx degit arsen-ask-lx/Agent_Quality_Kit/.claude/skills/search-first .claude/skills/search-first
$ npx degit arsen-ask-lx/Agent_Quality_Kit/.claude/skills/status .claude/skills/status
$ npx degit arsen-ask-lx/Agent_Quality_Kit/plugin/skills/check .claude/skills/check
$ npx degit arsen-ask-lx/Agent_Quality_Kit/plugin/skills/fix .claude/skills/fix

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(git clean:*)",
      "Bash(git branch -D:*)",
      "Bash(rm -rf /:*)",
      "Bash(rm -rf ~:*)",
      "Read(./.env)"
    ],
    "ask": [
      "Bash(git rebase:*)",
      "Bash(git rm:*)",
      "Bash(gh repo rename:*)",
      "Bash(gh repo delete:*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": ".claude/hooks/block-dangerous.sh"
          }
        ]
      }
    ]
  }
}

MCP servers (5)

serversourceest. tokens
Chrome DevTools MCP · "browser" npm 9.0k
some-search-mcp · "search" pypi 2.5k
local local / custom 2.5k
tsx · "own-code" npm 2.5k
memory local / custom 2.5k

Skills (5)

Hooks (7)

eventmatcherruns
PreToolUseBash.claude/hooks/block-dangerous.sh
PostToolUseWrite|Edit.claude/hooks/auto-format.sh
Stop*.claude/hooks/stop-gate.sh
UserPromptSubmit*.claude/hooks/prompt.sh
TaskCompleted*.claude/hooks/done.sh
TeammateIdle*.claude/hooks/idle.sh
SessionStartstartup|resumenode "$CLAUDE_PROJECT_DIR/.claude/hooks/session.mjs"

Permissions

deny (11)
Read(./.env)
Read(./.env.*)
Read(./secrets/**)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(git clean:*)
Bash(git branch -D:*)
Bash(rm -rf /:*)
Bash(rm -rf ~:*)
Read(./.env)
ask (4)
Bash(git rebase:*)
Bash(git rm:*)
Bash(gh repo rename:*)
Bash(gh repo delete:*)
allow (14)
Bash(git push origin main)
Bash(git push)
Bash(git add:*)
Bash(git commit:*)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(gh repo view:*)
Bash(gh api:*)
Bash(node tool/program.mjs:*)
Bash(npx github:arsen-ask-lx/Agent_Quality_Kit:*)
Bash(git checkout:*)
Bash(git switch:*)
Bash(git merge:*)

Similar rigs

copied ✓