fotografvecerek-ai/claude-code-audit-gate
Independent audit agent for Claude Code: audits an app built by another agent (OWASP ASVS/Top 10 security, every feature, UI via Playwright, single source of truth, repo hygiene, git practice, token efficiency), never writes code, hands fin
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit fotografvecerek-ai/claude-code-audit-gate/auditor/.claude ./rig-claude-code-audit-gate # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit fotografvecerek-ai/claude-code-audit-gate/auditor/.claude/skills/predani .claude/skills/predani $ curl -fsSL --create-dirs -o .claude/agents/auditor.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/auditor.md $ curl -fsSL --create-dirs -o .claude/agents/mechanik.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/mechanik.md $ curl -fsSL --create-dirs -o .claude/agents/overovatel-lehky.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/overovatel-lehky.md $ curl -fsSL --create-dirs -o .claude/agents/overovatel.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/overovatel.md $ curl -fsSL --create-dirs -o .claude/agents/pruzkumnik.md https://raw.githubusercontent.com/fotografvecerek-ai/claude-code-audit-gate/main/auditor/.claude/agents/pruzkumnik.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Edit(//c/dev/[DOPLŇ-repo]/**)",
"Read(//c/dev/[DOPLŇ-repo]/.env*)",
"Read(//c/dev/[DOPLŇ-repo]/**/*.pem)",
"Read(~/.ssh/**)",
"Bash(vercel *)",
"Bash(npx vercel *)",
"Bash(pnpm publish *)",
"Bash(npm publish *)",
"PowerShell(vercel *)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write|NotebookEdit|Bash|PowerShell",
"hooks": [
{
"type": "command",
"command": "node \"$CLAUDE_PROJECT_DIR/.claude/hooks/auditor-guard.js\" || exit 2"
}
]
},
{
"matcher": "Agent|Task|Read|Bash",
"hooks": [
{
"type": "command",
"command": "node \"$CLAUDE_PROJECT_DIR/tools/usporny-guard.mjs\""
}
]
}
]
}
} Skills (1)
Subagents (5)
| auditor model: opus | Use proactively for independent read-only audit of a change or feature (security, function, UI via Playwright, SSOT/duplicity, token efficiency) — returns findings with proposed fixes and a PASS/FAIL |
| mechanik model: sonnet | Mechanická práce auditora — spuštění skenů a testů, dávka UI průchodu (10–20 obrazovek), sondy endpointů, zápis surových výsledků do AUDIT/_data/. Vrací krátké shrnutí a cestu k výsledkům, hlavnímu vl |
| overovatel-lehky model: sonnet | Ověření opravy nálezu P2/P3 (šest bran v krátké formě) — levnější model; při pochybnosti vrať NEPRUKAZNE a hlavní vlákno pošle položku overovateli. |
| overovatel model: inherit | Nezávislé ověření opravy nálezu P0/P1 přes šest bran (šablona templates/verdikt_overeni.md). Stejný model jako hlavní vlákno — úsudek je tu drahý, ale nutný. |
| pruzkumnik model: haiku | Levný průzkum pro auditora — najdi, spočítej, vypiš, klasifikuj soubory/dokumenty/endpointy, vytáhni fakta z velkých souborů. Nic nehodnotí, vrací krátký JSON. Použij místo čtení velkých souborů v hla |
Hooks (6)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Edit|Write|NotebookEdit|Bash|PowerShell | node "$CLAUDE_PROJECT_DIR/.claude/hooks/auditor-guard.js" || exit 2 |
| PreToolUse | Agent|Task|Read|Bash | node "$CLAUDE_PROJECT_DIR/tools/usporny-guard.mjs" |
| SessionStart | startup|resume|clear|compact | node "$CLAUDE_PROJECT_DIR/tools/bus.mjs" inbox --for auditor --unacked --brief; echo "AUDITOR (úsporný režim, CLAUDE.md §0b): po startu/kompakci načti AUDIT/_prubeh.md; z intake a handoffu jen potřebné části (Grep), stav drž v TaskList a _p |
| SessionStart | compact|clear | node "$CLAUDE_PROJECT_DIR/tools/stav-session.mjs" auditor |
| PostToolUse | * | node "$CLAUDE_PROJECT_DIR/tools/bus-notify.mjs" --for auditor --event post |
| Stop | * | node "$CLAUDE_PROJECT_DIR/tools/bus-notify.mjs" --for auditor --event stop |
Permissions
deny (9)
Edit(//c/dev/[DOPLŇ-repo]/**)
Read(//c/dev/[DOPLŇ-repo]/.env*)
Read(//c/dev/[DOPLŇ-repo]/**/*.pem)
Read(~/.ssh/**)
Bash(vercel *)
Bash(npx vercel *)
Bash(pnpm publish *)
Bash(npm publish *)
PowerShell(vercel *)
ask (0)
—
allow (25)
Bash(node *)
Bash(npx playwright *)
Bash(npx tsc *)
Bash(npx jscpd *)
Bash(npx madge *)
Bash(npx knip *)
Bash(npx license-checker *)
Bash(npm run *)
Bash(npm install *)
Bash(pnpm *)
Bash(bash tools/*)
Bash(git *)
Bash(curl *)
Bash(semgrep *)
Bash(gitleaks *)
Bash(jq *)
Bash(python *)
Bash(python3 *)
WebFetch(domain:code.claude.com)
WebFetch(domain:owasp.org)
WebFetch(domain:cheatsheetseries.owasp.org)
WebFetch(domain:github.com)
WebFetch(domain:raw.githubusercontent.com)
WebFetch(domain:asvs.dev)
WebSearch
Similar rigs
SchotjeChrisman/agentic-workflow
A self-improving Claude Code setup
Orchestrator 2.8k tok ·
homeofe/improvements
Portable, LLM-agnostic framework for multi-model AI workflows: model routing, structured agent handoff (AAHP), and a phased agent pipeline. MIT.
Orchestrator 1.4k tok ·
radozaprazny/attest
A Claude Code kit: a push guard that holds a push until a leak scan and one audit have cleared HEAD.
Automator 259 tok ·
Dipen-Dedania/agent-pulse
Know what your agents are doing
Orchestrator 1.7k tok ·