~ / rigs / ashishmerani / claude-code-security-harness

ashishmerani/claude-code-security-harness

A security harness for AI coding agents. Supply chain, command scope, config integrity. Build specifications.

↗ GitHub ★ 3 MIT updated 2mo ago personal setup Claude Code
share on X
ARCHETYPE
Automator
Hooks on every lifecycle event: format, lint, notify, log.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit ashishmerani/claude-code-security-harness/hooks ./rig-claude-code-security-harness/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "<config-dir>/hooks/bash-destructive-guard.sh"
          },
          {
            "type": "command",
            "command": "<config-dir>/hooks/bash-scope-guard.sh"
          },
          {
            "type": "command",
            "command": "<config-dir>/hooks/supply-chain-guard.sh"
          }
        ]
      },
      {
        "matcher": "Bash|Edit|MultiEdit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "<config-dir>/hooks/workflow-posture-check.sh"
          }
        ]
      },
      {
        "matcher": "Edit|MultiEdit|NotebookEdit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "<config-dir>/hooks/holy-files-guard.sh"
          },
          {
            "type": "command",
            "command": "<config-dir>/hooks/worktree-scope-guard.sh"
          }
        ]
      },
      {
        "matcher": "Glob|Grep|Read",
        "hooks": [
          {
            "type": "command",
            "command": "<config-dir>/hooks/read-scope-guard.sh"
          }
        ]
      }
    ]
  }
}

Hooks (13)

eventmatcherruns
PreToolUseBash<config-dir>/hooks/bash-destructive-guard.sh
PreToolUseBash<config-dir>/hooks/bash-scope-guard.sh
PreToolUseBash<config-dir>/hooks/supply-chain-guard.sh
PreToolUseBash|Edit|MultiEdit|Write<config-dir>/hooks/workflow-posture-check.sh
PreToolUseEdit|MultiEdit|NotebookEdit|Write<config-dir>/hooks/holy-files-guard.sh
PreToolUseEdit|MultiEdit|NotebookEdit|Write<config-dir>/hooks/worktree-scope-guard.sh
PreToolUseGlob|Grep|Read<config-dir>/hooks/read-scope-guard.sh
PostToolUseBash<config-dir>/hooks/npm-audit-on-install.sh
SessionStart*<config-dir>/hooks/integrity-check.sh
SessionStart*<config-dir>/hooks/non-npm-tree-detector.sh
SessionStart*<config-dir>/hooks/observability-self-check.sh
SessionStart*<config-dir>/hooks/supply-chain-guard-selftest.sh
SessionStart*<config-dir>/hooks/supply-chain-rescan.sh

Similar rigs

copied ✓