~ / rigs / fotografvecerek-ai / claude-code-audit-gate

fotografvecerek-ai/claude-code-audit-gate

Independent audit agent for Claude Code: audits an app built by another agent (OWASP ASVS/Top 10 security, every feature, UI via Playwright, single source of truth, repo hygiene, git practice, token efficiency), never writes code, hands fin

↗ GitHub ★ 0 MIT updated 7d ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~10.3k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit fotografvecerek-ai/claude-code-audit-gate/auditor/.claude ./rig-claude-code-audit-gate  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit fotografvecerek-ai/claude-code-audit-gate/auditor/.claude/skills/predani .claude/skills/predani
$ curl -fsSL --create-dirs -o .claude/agents/auditor.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/auditor.md
$ curl -fsSL --create-dirs -o .claude/agents/mechanik.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/mechanik.md
$ curl -fsSL --create-dirs -o .claude/agents/overovatel-lehky.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/overovatel-lehky.md
$ curl -fsSL --create-dirs -o .claude/agents/overovatel.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/overovatel.md
$ curl -fsSL --create-dirs -o .claude/agents/pruzkumnik.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/pruzkumnik.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Edit(//c/dev/[DOPLŇ-repo]/**)",
      "Read(//c/dev/[DOPLŇ-repo]/.env*)",
      "Read(//c/dev/[DOPLŇ-repo]/**/*.pem)",
      "Read(~/.ssh/**)",
      "Bash(vercel *)",
      "Bash(npx vercel *)",
      "Bash(pnpm publish *)",
      "Bash(npm publish *)",
      "PowerShell(vercel *)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Edit|Write|NotebookEdit|Bash|PowerShell",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$CLAUDE_PROJECT_DIR/.claude/hooks/auditor-guard.js\" || exit 2"
          }
        ]
      },
      {
        "matcher": "Agent|Task|Read|Bash",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$CLAUDE_PROJECT_DIR/tools/usporny-guard.mjs\""
          }
        ]
      }
    ]
  }
}

Skills (1)

Subagents (5)

auditor
model: opus
Use proactively for independent read-only audit of a change or feature (security, function, UI via Playwright, SSOT/duplicity, token efficiency) — returns findings with proposed fixes and a PASS/FAIL
mechanik
model: sonnet
Mechanická práce auditora — spuštění skenů a testů, dávka UI průchodu (10–20 obrazovek), sondy endpointů, zápis surových výsledků do AUDIT/_data/. Vrací krátké shrnutí a cestu k výsledkům, hlavnímu vl
overovatel-lehky
model: sonnet
Ověření opravy nálezu P2/P3 (šest bran v krátké formě) — levnější model; při pochybnosti vrať NEPRUKAZNE a hlavní vlákno pošle položku overovateli.
overovatel
model: inherit
Nezávislé ověření opravy nálezu P0/P1 přes šest bran (šablona templates/verdikt_overeni.md). Stejný model jako hlavní vlákno — úsudek je tu drahý, ale nutný.
pruzkumnik
model: haiku
Levný průzkum pro auditora — najdi, spočítej, vypiš, klasifikuj soubory/dokumenty/endpointy, vytáhni fakta z velkých souborů. Nic nehodnotí, vrací krátký JSON. Použij místo čtení velkých souborů v hla

Hooks (6)

eventmatcherruns
PreToolUseEdit|Write|NotebookEdit|Bash|PowerShellnode "$CLAUDE_PROJECT_DIR/.claude/hooks/auditor-guard.js" || exit 2
PreToolUseAgent|Task|Read|Bashnode "$CLAUDE_PROJECT_DIR/tools/usporny-guard.mjs"
SessionStartstartup|resume|clear|compactnode "$CLAUDE_PROJECT_DIR/tools/bus.mjs" inbox --for auditor --unacked --brief; echo "AUDITOR (úsporný režim, CLAUDE.md §0b): po startu/kompakci načti AUDIT/_prubeh.md; z intake a handoffu jen potřebné části (Grep), stav drž v TaskList a _p
SessionStartcompact|clearnode "$CLAUDE_PROJECT_DIR/tools/stav-session.mjs" auditor
PostToolUse*node "$CLAUDE_PROJECT_DIR/tools/bus-notify.mjs" --for auditor --event post
Stop*node "$CLAUDE_PROJECT_DIR/tools/bus-notify.mjs" --for auditor --event stop

Permissions

deny (9)
Edit(//c/dev/[DOPLŇ-repo]/**)
Read(//c/dev/[DOPLŇ-repo]/.env*)
Read(//c/dev/[DOPLŇ-repo]/**/*.pem)
Read(~/.ssh/**)
Bash(vercel *)
Bash(npx vercel *)
Bash(pnpm publish *)
Bash(npm publish *)
PowerShell(vercel *)
ask (0)
—
allow (25)
Bash(node *)
Bash(npx playwright *)
Bash(npx tsc *)
Bash(npx jscpd *)
Bash(npx madge *)
Bash(npx knip *)
Bash(npx license-checker *)
Bash(npm run *)
Bash(npm install *)
Bash(pnpm *)
Bash(bash tools/*)
Bash(git *)
Bash(curl *)
Bash(semgrep *)
Bash(gitleaks *)
Bash(jq *)
Bash(python *)
Bash(python3 *)
WebFetch(domain:code.claude.com)
WebFetch(domain:owasp.org)
WebFetch(domain:cheatsheetseries.owasp.org)
WebFetch(domain:github.com)
WebFetch(domain:raw.githubusercontent.com)
WebFetch(domain:asvs.dev)
WebSearch

Similar rigs

copied ✓