~ / rigs / danielfarnose / claude-code-dev-loop

danielfarnose/claude-code-dev-loop

A multi-agent development loop for Claude Code: five specialized subagents plan, implement, verify and merge — with a QA gate that cannot edit the code it judges.

↗ GitHub ★ 1 MIT updated today project Claude Code Claude plugin
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~1.2k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit danielfarnose/claude-code-dev-loop/agents ./rig-claude-code-dev-loop/agents
$ npx degit danielfarnose/claude-code-dev-loop/commands ./rig-claude-code-dev-loop/commands
$ npx degit danielfarnose/claude-code-dev-loop/skills ./rig-claude-code-dev-loop/skills

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit danielfarnose/claude-code-dev-loop/skills/codex-board .claude/skills/codex-board
$ npx degit danielfarnose/claude-code-dev-loop/skills/codex-explain .claude/skills/codex-explain
$ npx degit danielfarnose/claude-code-dev-loop/skills/codex-patrol .claude/skills/codex-patrol
$ npx degit danielfarnose/claude-code-dev-loop/skills/codex-run .claude/skills/codex-run
$ npx degit danielfarnose/claude-code-dev-loop/skills/codex-security-audit .claude/skills/codex-security-audit
$ npx degit danielfarnose/claude-code-dev-loop/skills/inspect-project .claude/skills/inspect-project
$ npx degit danielfarnose/claude-code-dev-loop/skills/qa-live-user .claude/skills/qa-live-user
$ npx degit danielfarnose/claude-code-dev-loop/skills/recording-learnings .claude/skills/recording-learnings
$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/danielfarnose/claude-code-dev-loop/main/agents/architect.md
$ curl -fsSL --create-dirs -o .claude/agents/developer.md https://raw.githubusercontent.com/danielfarnose/claude-code-dev-loop/main/agents/developer.md
$ curl -fsSL --create-dirs -o .claude/agents/legal.md https://raw.githubusercontent.com/danielfarnose/claude-code-dev-loop/main/agents/legal.md
$ curl -fsSL --create-dirs -o .claude/agents/pm.md https://raw.githubusercontent.com/danielfarnose/claude-code-dev-loop/main/agents/pm.md
$ curl -fsSL --create-dirs -o .claude/agents/qa.md https://raw.githubusercontent.com/danielfarnose/claude-code-dev-loop/main/agents/qa.md
$ curl -fsSL --create-dirs -o .claude/agents/security.md https://raw.githubusercontent.com/danielfarnose/claude-code-dev-loop/main/agents/security.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (8)

Subagents (6)

architect
model: claude-fable-5
Analyzes a CODE task in the current project, does brainstorming + a minimalist plan (ponytail), and generates a ticket in the project's tickets path (defined in .claude/squad.md). Does NOT write featu
developer
model: claude-sonnet-5
Implements the ticket with TDD and minimum code (ponytail) on the current project's real stack (defined in .claude/squad.md). Receives a ticket path and produces verified, committed code. Use it after
legal
model: claude-opus-5
Legal-texts writer for a project going to production. Renders the plugin's generic templates (templates/legal/*, no product inside) with what the repo already says plus the operator's answers to what
pm
model: claude-opus-5
Product manager of the current project's development squad. Keeps the backlog prioritized, turns the human's raw ideas into product specs that feed the architect in two modes (discovery: intent + open
qa
model: claude-sonnet-5
Gate of the development loop. Read-only over the code. Runs the current project's verification (defined in .claude/squad.md) and answers APPROVED / REJECTED with actionable reasons. Use it after the d
security
model: claude-opus-5
MANUAL security auditor (outside the dev loop). Scans the current project's code for vulnerabilities, focused on multi-tenant isolation (one client must not see another's data), data/pricing leaks, pr

Slash commands (5)

/board/explain/launch/patrol/run

Similar rigs

copied ✓