~ / rigs / blundergoat / goat-flow

blundergoat/goat-flow

A structured workflow system for AI coding agents - harness engineering, execution loop, skills, hooks, and a learning loop. Works with Claude Code, Codex, Antigravity CLI, Copilot.

↗ GitHub ★ 32 MIT updated today project Claude CodeCodexCopilot
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~4.7k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit blundergoat/goat-flow/.claude ./rig-goat-flow  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit blundergoat/goat-flow/.agents/skills/goat-clarity .claude/skills/goat-clarity
$ npx degit blundergoat/goat-flow/.agents/skills/goat-critique .claude/skills/goat-critique
$ npx degit blundergoat/goat-flow/.agents/skills/goat-debug .claude/skills/goat-debug
$ npx degit blundergoat/goat-flow/.agents/skills/goat-plan .claude/skills/goat-plan
$ npx degit blundergoat/goat-flow/.agents/skills/goat-qa .claude/skills/goat-qa
$ npx degit blundergoat/goat-flow/.agents/skills/goat-review .claude/skills/goat-review
$ npx degit blundergoat/goat-flow/.agents/skills/goat-security .claude/skills/goat-security
$ npx degit blundergoat/goat-flow/.agents/skills/goat .claude/skills/goat

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(*git commit*)",
      "Bash(*git push*)",
      "Read(**/.env)",
      "Read(**/.env.local)",
      "Read(**/.env.development)",
      "Read(**/.env.production)",
      "Read(**/.env.staging)",
      "Read(**/.env.test)",
      "Read(**/.envrc)",
      "Read(**/.env.*.local)",
      "Edit(**/.env)",
      "Edit(**/.env.local)",
      "Edit(**/.env.development)",
      "Edit(**/.env.production)",
      "Edit(**/.env.staging)",
      "Edit(**/.env.test)",
      "Edit(**/.envrc)",
      "Edit(**/.env.*.local)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(~/.docker/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.config/gcloud/**)",
      "Read(~/.npmrc)",
      "Read(~/.netrc)",
      "Read(~/.git-credentials)",
      "Read(~/.config/gh/hosts.yml)",
      "Read(~/.pgpass)",
      "Read(~/.pypirc)",
      "Read(**/*.pfx)",
      "Read(~/.kube/**)",
      "Edit(**/*.pem)",
      "Edit(**/*.key)",
      "Edit(~/.ssh/**)",
      "Edit(~/.aws/**)",
      "Edit(~/.docker/**)",
      "Edit(~/.gnupg/**)",
      "Edit(~/.config/gcloud/**)",
      "Edit(~/.npmrc)",
      "Edit(~/.netrc)",
      "Edit(~/.git-credentials)",
      "Edit(~/.config/gh/hosts.yml)",
      "Edit(~/.pgpass)",
      "Edit(~/.pypirc)",
      "Edit(**/*.pfx)",
      "Edit(~/.kube/**)",
      "Read(**/.ssh/**)",
      "Read(**/.aws/**)",
      "Read(**/.docker/**)",
      "Read(**/.gnupg/**)",
      "Read(**/.config/gcloud/**)",
      "Read(**/.npmrc)",
      "Read(**/.netrc)",
      "Read(**/.git-credentials)",
      "Read(**/.config/gh/hosts.yml)",
      "Read(**/.pgpass)",
      "Read(**/.pypirc)",
      "Read(**/.kube/**)",
      "Edit(**/.ssh/**)",
      "Edit(**/.aws/**)",
      "Edit(**/.docker/**)",
      "Edit(**/.gnupg/**)",
      "Edit(**/.config/gcloud/**)",
      "Edit(**/.npmrc)",
      "Edit(**/.netrc)",
      "Edit(**/.git-credentials)",
      "Edit(**/.config/gh/hosts.yml)",
      "Edit(**/.pgpass)",
      "Edit(**/.pypirc)",
      "Edit(**/.kube/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|PowerShell",
        "hooks": [
          {
            "type": "command",
            "command": "node"
          },
          {
            "type": "command",
            "command": "node"
          }
        ]
      }
    ]
  }
}

Skills (8)

Hooks (6)

eventmatcherruns
PreToolUseBash|PowerShellnode
PreToolUseBash|PowerShellnode
PostToolUseEditnode
PostToolUseWritenode
PostToolUseBashnode
Stop*node

Permissions

deny (72)
Bash(*git commit*)
Bash(*git push*)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.development)
Read(**/.env.production)
Read(**/.env.staging)
Read(**/.env.test)
Read(**/.envrc)
Read(**/.env.*.local)
Edit(**/.env)
Edit(**/.env.local)
Edit(**/.env.development)
Edit(**/.env.production)
Edit(**/.env.staging)
Edit(**/.env.test)
Edit(**/.envrc)
Edit(**/.env.*.local)
Read(**/*.pem)
Read(**/*.key)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.docker/**)
Read(~/.gnupg/**)
Read(~/.config/gcloud/**)
Read(~/.npmrc)
Read(~/.netrc)
Read(~/.git-credentials)
Read(~/.config/gh/hosts.yml)
Read(~/.pgpass)
Read(~/.pypirc)
Read(**/*.pfx)
Read(~/.kube/**)
Edit(**/*.pem)
Edit(**/*.key)
Edit(~/.ssh/**)
Edit(~/.aws/**)
Edit(~/.docker/**)
Edit(~/.gnupg/**)
Edit(~/.config/gcloud/**)
Edit(~/.npmrc)
Edit(~/.netrc)
Edit(~/.git-credentials)
Edit(~/.config/gh/hosts.yml)
Edit(~/.pgpass)
Edit(~/.pypirc)
Edit(**/*.pfx)
Edit(~/.kube/**)
Read(**/.ssh/**)
Read(**/.aws/**)
Read(**/.docker/**)
Read(**/.gnupg/**)
Read(**/.config/gcloud/**)
Read(**/.npmrc)
Read(**/.netrc)
Read(**/.git-credentials)
Read(**/.config/gh/hosts.yml)
Read(**/.pgpass)
Read(**/.pypirc)
Read(**/.kube/**)
ask (0)
—
allow (4)
Read(.env.example)
Read(**/.env.example)
Edit(.env.example)
Edit(**/.env.example)

Similar rigs

copied ✓