ashishmerani/claude-code-security-harness
A security harness for AI coding agents. Supply chain, command scope, config integrity. Build specifications.
ARCHETYPE
Automator
Hooks on every lifecycle event: format, lint, notify, log.
Copy this rig
# review before running: this installs third-party code
$ npx degit ashishmerani/claude-code-security-harness/hooks ./rig-claude-code-security-harness/hooks MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "<config-dir>/hooks/bash-destructive-guard.sh"
},
{
"type": "command",
"command": "<config-dir>/hooks/bash-scope-guard.sh"
},
{
"type": "command",
"command": "<config-dir>/hooks/supply-chain-guard.sh"
}
]
},
{
"matcher": "Bash|Edit|MultiEdit|Write",
"hooks": [
{
"type": "command",
"command": "<config-dir>/hooks/workflow-posture-check.sh"
}
]
},
{
"matcher": "Edit|MultiEdit|NotebookEdit|Write",
"hooks": [
{
"type": "command",
"command": "<config-dir>/hooks/holy-files-guard.sh"
},
{
"type": "command",
"command": "<config-dir>/hooks/worktree-scope-guard.sh"
}
]
},
{
"matcher": "Glob|Grep|Read",
"hooks": [
{
"type": "command",
"command": "<config-dir>/hooks/read-scope-guard.sh"
}
]
}
]
}
} Hooks (13)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | <config-dir>/hooks/bash-destructive-guard.sh |
| PreToolUse | Bash | <config-dir>/hooks/bash-scope-guard.sh |
| PreToolUse | Bash | <config-dir>/hooks/supply-chain-guard.sh |
| PreToolUse | Bash|Edit|MultiEdit|Write | <config-dir>/hooks/workflow-posture-check.sh |
| PreToolUse | Edit|MultiEdit|NotebookEdit|Write | <config-dir>/hooks/holy-files-guard.sh |
| PreToolUse | Edit|MultiEdit|NotebookEdit|Write | <config-dir>/hooks/worktree-scope-guard.sh |
| PreToolUse | Glob|Grep|Read | <config-dir>/hooks/read-scope-guard.sh |
| PostToolUse | Bash | <config-dir>/hooks/npm-audit-on-install.sh |
| SessionStart | * | <config-dir>/hooks/integrity-check.sh |
| SessionStart | * | <config-dir>/hooks/non-npm-tree-detector.sh |
| SessionStart | * | <config-dir>/hooks/observability-self-check.sh |
| SessionStart | * | <config-dir>/hooks/supply-chain-guard-selftest.sh |
| SessionStart | * | <config-dir>/hooks/supply-chain-rescan.sh |
Similar rigs
cocoindex-io/cocoindex
Incremental engine for long horizon agents 🌟 Star if you like it!
Automator 7.3k tok ·
FailproofAI/failproofai
Observability and enforcement for AI agent harnesses. Capture every run and runtime reliability with policy enforcement.
Automator 22.9k tok ·
caliber-ai-org/ai-setup
Continuously sync your AI setups with one command. Codebase tailor suited agent skills, MCPs and config files for Claude Code, Cursor, and Codex.
Automator 3.2k tok ·
asklokesh/loki-mode
Autonomous software factory. Give it a GitHub issue, a spec or a one-line task; get back a pull request with a signed receipt anyone can re-check offline. Runs on your machine with your own keys: Claude, Codex, OpenCode.
Automator 8.2k tok ·