dralgorhythm/claude-agentic-framework
A More Effective Agent Harness for Claude
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code $ claude mcp add sequential-thinking -- npx -y @modelcontextprotocol/server-sequential-thinking $ claude mcp add chrome-devtools -- npx -y chrome-devtools-mcp $ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem . $ claude mcp add context7 -- npx -y @upstash/context7-mcp $ npx degit dralgorhythm/claude-agentic-framework/.claude ./rig-claude-agentic-framework # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add sequential-thinking -- npx -y @modelcontextprotocol/server-sequential-thinking $ claude mcp add chrome-devtools -- npx -y chrome-devtools-mcp $ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem . $ claude mcp add context7 -- npx -y @upstash/context7-mcp
$ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/architect .claude/skills/architect $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/builder .claude/skills/builder $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/code-check .claude/skills/code-check $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/land-the-plane .claude/skills/land-the-plane $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/qa-engineer .claude/skills/qa-engineer $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/security-auditor .claude/skills/security-auditor $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/swarm-execute .claude/skills/swarm-execute $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/swarm-plan .claude/skills/swarm-plan $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/swarm-research .claude/skills/swarm-research $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/swarm-review .claude/skills/swarm-review $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/tailor .claude/skills/tailor $ npx degit dralgorhythm/claude-agentic-framework/.claude/skills/ui-ux-designer .claude/skills/ui-ux-designer
$ curl -fsSL --create-dirs -o .claude/agents/worker-architect.md https://raw.githubusercontent.com/dralgorhythm/claude-agentic-framework/main/.claude/agents/worker-architect.md $ curl -fsSL --create-dirs -o .claude/agents/worker-builder.md https://raw.githubusercontent.com/dralgorhythm/claude-agentic-framework/main/.claude/agents/worker-builder.md $ curl -fsSL --create-dirs -o .claude/agents/worker-explorer.md https://raw.githubusercontent.com/dralgorhythm/claude-agentic-framework/main/.claude/agents/worker-explorer.md $ curl -fsSL --create-dirs -o .claude/agents/worker-research.md https://raw.githubusercontent.com/dralgorhythm/claude-agentic-framework/main/.claude/agents/worker-research.md $ curl -fsSL --create-dirs -o .claude/agents/worker-reviewer.md https://raw.githubusercontent.com/dralgorhythm/claude-agentic-framework/main/.claude/agents/worker-reviewer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"// === Destructive File Operations ===",
"Bash(rm -rf:*)",
"Bash(rm -r:*)",
"Bash(sudo:*)",
"// === Git Destructive Operations ===",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git push origin --force:*)",
"Bash(git push origin -f:*)",
"Bash(git reset --hard:*)",
"Bash(git clean -f:*)",
"Bash(git clean -fd:*)",
"// === Infrastructure Destructive Operations ===",
"Bash(terraform destroy:*)",
"Bash(terraform apply -auto-approve:*)",
"Bash(docker system prune:*)",
"Bash(docker rm:*)",
"Bash(docker rmi:*)",
"// === Dangerous Permission Changes ===",
"Bash(chmod 777:*)",
"// === Pipe-to-Shell (Remote Code Execution) ===",
"Bash(curl * | bash*)",
"Bash(wget * | bash*)",
"Bash(curl * | sh*)",
"Bash(wget * | sh*)",
"// === Sensitive Credential Paths (Read) ===",
"Read(~/.ssh/**)",
"Read(~/.gnupg/**)",
"Read(~/.aws/**)",
"Read(~/.azure/**)",
"Read(~/.config/gcloud/**)",
"// === Shell Profile & SSH Key Protection (Edit/Write) ===",
"Edit(~/.bashrc)",
"Edit(~/.zshrc)",
"Edit(~/.bash_profile)",
"Write(~/.bashrc)",
"Write(~/.zshrc)",
"Write(~/.bash_profile)",
"Edit(~/.ssh/**)",
"Write(~/.ssh/**)",
"// === Project Secrets (Read) ===",
"Read(**/.env)",
"Read(**/.env.*)",
"Read(**/secrets/**)",
"Read(**/*.pem)",
"Read(**/id_rsa*)",
"Read(**/credentials)",
"Read(**/.npmrc)",
"Read(~/.git-credentials)",
"Read(~/.config/gh/**)",
"// === Push to Default Branch ===",
"Bash(git push origin main:*)",
"Bash(git push origin master:*)",
"Bash(git push -u origin main:*)",
"Bash(git push -u origin master:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Write|Edit|MultiEdit|NotebookEdit",
"hooks": [
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/pre-tool-use-validator.sh"
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/dangerous-command-guard.sh"
},
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/pre-tool-use-validator.sh"
},
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/pre-commit-verification.sh"
},
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/pre-push-main-blocker.sh"
},
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/branch-pr-discipline.sh"
}
]
}
]
}
} MCP servers (4)
| server | source | est. tokens |
|---|---|---|
| Sequential Thinking · "sequential-thinking" | npm | 900 |
| Chrome DevTools MCP · "chrome-devtools" | npm | 9.0k |
| Filesystem | npm | 4.2k |
| Context7 | npm | 1.2k |
Skills (12)
architectbuildercode-checkland-the-planeqa-engineersecurity-auditorswarm-executeswarm-planswarm-researchswarm-reviewtailorui-ux-designer
Subagents (5)
| worker-architect model: opus | Senior architecture decisions. Use for complex design problems requiring deep analysis. |
| worker-builder model: sonnet | Implementation, testing, and refactoring worker for swarm tasks. Use for parallel coding, test writing, and code cleanup. |
| worker-explorer model: haiku | Codebase exploration and web research worker. Use for pattern search, dependency mapping, quick API/doc lookup, and library comparison. |
| worker-research model: sonnet | Deep research and investigation worker. Use for multi-source analysis, technology evaluation, competitive research, and comprehensive documentation. |
| worker-reviewer model: sonnet | Code review, security audit, and QA worker for swarm tasks. Use for parallel review, vulnerability detection, and quality assessment. |
Hooks (12)
| event | matcher | runs |
|---|---|---|
| SessionStart | startup|resume|compact|clear | $CLAUDE_PROJECT_DIR/.claude/hooks/session-start-loader.sh |
| PreToolUse | Write|Edit|MultiEdit|NotebookEdit | $CLAUDE_PROJECT_DIR/.claude/hooks/pre-tool-use-validator.sh |
| PreToolUse | Bash | $CLAUDE_PROJECT_DIR/.claude/hooks/dangerous-command-guard.sh |
| PreToolUse | Bash | $CLAUDE_PROJECT_DIR/.claude/hooks/pre-tool-use-validator.sh |
| PreToolUse | Bash | $CLAUDE_PROJECT_DIR/.claude/hooks/pre-commit-verification.sh |
| PreToolUse | Bash | $CLAUDE_PROJECT_DIR/.claude/hooks/pre-push-main-blocker.sh |
| PreToolUse | Bash | $CLAUDE_PROJECT_DIR/.claude/hooks/branch-pr-discipline.sh |
| PostToolUse | Edit|MultiEdit|Write | $CLAUDE_PROJECT_DIR/.claude/hooks/post-tool-use-tracker.sh |
| PostToolUse | Edit|MultiEdit|Write | $CLAUDE_PROJECT_DIR/.claude/hooks/post-edit-lint.sh |
| Stop | * | $CLAUDE_PROJECT_DIR/.claude/hooks/stop-validator.sh |
| SubagentStop | * | $CLAUDE_PROJECT_DIR/.claude/hooks/subagent-stop-validator.sh |
| TaskCompleted | * | $CLAUDE_PROJECT_DIR/.claude/hooks/task-quality-gate.sh |
Permissions
deny (55)
// === Destructive File Operations ===
Bash(rm -rf:*)
Bash(rm -r:*)
Bash(sudo:*)
// === Git Destructive Operations ===
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git push origin --force:*)
Bash(git push origin -f:*)
Bash(git reset --hard:*)
Bash(git clean -f:*)
Bash(git clean -fd:*)
// === Infrastructure Destructive Operations ===
Bash(terraform destroy:*)
Bash(terraform apply -auto-approve:*)
Bash(docker system prune:*)
Bash(docker rm:*)
Bash(docker rmi:*)
// === Dangerous Permission Changes ===
Bash(chmod 777:*)
// === Pipe-to-Shell (Remote Code Execution) ===
Bash(curl * | bash*)
Bash(wget * | bash*)
Bash(curl * | sh*)
Bash(wget * | sh*)
// === Sensitive Credential Paths (Read) ===
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.config/gcloud/**)
// === Shell Profile & SSH Key Protection (Edit/Write) ===
Edit(~/.bashrc)
Edit(~/.zshrc)
Edit(~/.bash_profile)
Write(~/.bashrc)
Write(~/.zshrc)
Write(~/.bash_profile)
Edit(~/.ssh/**)
Write(~/.ssh/**)
// === Project Secrets (Read) ===
Read(**/.env)
Read(**/.env.*)
Read(**/secrets/**)
Read(**/*.pem)
Read(**/id_rsa*)
Read(**/credentials)
Read(**/.npmrc)
Read(~/.git-credentials)
Read(~/.config/gh/**)
// === Push to Default Branch ===
Bash(git push origin main:*)
Bash(git push origin master:*)
Bash(git push -u origin main:*)
Bash(git push -u origin master:*)
ask (0)
—
allow (120)
// === Core Claude Tools (Read/Navigation) ===
Read
Glob
Grep
WebSearch
// === Core Claude Tools (Write) ===
Edit
Write
NotebookEdit
// === File System Read Operations ===
Bash(cat:*)
Bash(ls:*)
Bash(head:*)
Bash(tail:*)
Bash(wc:*)
Bash(file:*)
Bash(stat:*)
Bash(diff:*)
Bash(tree:*)
Bash(find:*)
Bash(which:*)
Bash(type:*)
Bash(pwd:*)
Bash(xxd:*)
Bash(realpath:*)
Bash(dirname:*)
Bash(basename:*)
// === File System Write Operations ===
Bash(cp:*)
Bash(mv:*)
Bash(touch:*)
Bash(mkdir:*)
Bash(chmod:*)
// === Text Processing ===
Bash(grep:*)
Bash(sort:*)
Bash(uniq:*)
Bash(awk:*)
Bash(sed:*)
Bash(tr:*)
Bash(cut:*)
Bash(xargs:*)
Bash(jq:*)
Bash(yq:*)
// === System Info ===
Bash(date:*)
Bash(uname:*)
Bash(whoami:*)
Bash(id:*)
Bash(ps:*)
Bash(lsof:*)
Bash(env:*)
Bash(printenv:*)
Bash(netstat:*)
Bash(ss:*)
Bash(dig:*)
Bash(whois:*)
Bash(curl:*)
Bash(command -v:*)
Bash(command:*)
Similar rigs
cassler/awesome-claude-code-setup
Give Claude the super powers it deserves with this power user collection of bash scripts and slash commands
Pragmatist 31.8k tok ·
nandhasuhendra/dotfiles
My configuration files that I use on several applications and Linux desktops.
MCP Hoarder 19.1k tok ·
grimoire-rs/grimoire
Package manager for AI-agent config. grim installs, updates, and publishes skills, rules, agents, MCP servers, and bundles into Claude Code, Copilot, Cursor, Codex, Gemini, Zed, Amp, Kiro, Junie, and opencode — pinned by digest in a lockfil
Skill Collector 26.4k tok ·
affaan-m/agentshield
AI agent security scanner. Detect vulnerabilities in agent configurations, MCP servers, and tool permissions. Available as CLI, GitHub Action, ECC plugin, and GitHub App integration. 🛡️
MCP Hoarder 60.2k tok ·