highflame-ai/ai-factory
An opinionated, config-driven AI-SDLC toolkit for AI-assisted software engineering. Skills, agents, hooks, and a role-based capability model. The 1-100 toolkit for AI coding agents: spec-driven pipeline, adversarial review bench, determinis
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit highflame-ai/ai-factory/.claude ./rig-ai-factory # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit highflame-ai/ai-factory/skills/add-detector .claude/skills/add-detector $ npx degit highflame-ai/ai-factory/skills/adversary .claude/skills/adversary $ npx degit highflame-ai/ai-factory/skills/analyze .claude/skills/analyze $ npx degit highflame-ai/ai-factory/skills/architect .claude/skills/architect $ npx degit highflame-ai/ai-factory/skills/audit-permissions .claude/skills/audit-permissions $ npx degit highflame-ai/ai-factory/skills/bugfix .claude/skills/bugfix $ npx degit highflame-ai/ai-factory/skills/canary .claude/skills/canary $ npx degit highflame-ai/ai-factory/skills/debug .claude/skills/debug $ npx degit highflame-ai/ai-factory/skills/dep-update .claude/skills/dep-update $ npx degit highflame-ai/ai-factory/skills/deprecate .claude/skills/deprecate $ npx degit highflame-ai/ai-factory/skills/doc-drift .claude/skills/doc-drift $ npx degit highflame-ai/ai-factory/skills/expert .claude/skills/expert $ npx degit highflame-ai/ai-factory/skills/feature-prep .claude/skills/feature-prep $ npx degit highflame-ai/ai-factory/skills/from-issue .claude/skills/from-issue $ npx degit highflame-ai/ai-factory/skills/git-workflow .claude/skills/git-workflow $ npx degit highflame-ai/ai-factory/skills/grill-feature .claude/skills/grill-feature $ npx degit highflame-ai/ai-factory/skills/handoff .claude/skills/handoff $ npx degit highflame-ai/ai-factory/skills/incremental-implementation .claude/skills/incremental-implementation $ npx degit highflame-ai/ai-factory/skills/init .claude/skills/init $ npx degit highflame-ai/ai-factory/skills/license-audit .claude/skills/license-audit $ npx degit highflame-ai/ai-factory/skills/manifest .claude/skills/manifest $ npx degit highflame-ai/ai-factory/skills/measure .claude/skills/measure $ npx degit highflame-ai/ai-factory/skills/new-admin-module .claude/skills/new-admin-module $ npx degit highflame-ai/ai-factory/skills/onboard .claude/skills/onboard $ npx degit highflame-ai/ai-factory/skills/optimize .claude/skills/optimize $ npx degit highflame-ai/ai-factory/skills/proceed .claude/skills/proceed $ npx degit highflame-ai/ai-factory/skills/reflect .claude/skills/reflect $ npx degit highflame-ai/ai-factory/skills/release-notes .claude/skills/release-notes $ npx degit highflame-ai/ai-factory/skills/review .claude/skills/review $ npx degit highflame-ai/ai-factory/skills/rotate-secrets .claude/skills/rotate-secrets $ npx degit highflame-ai/ai-factory/skills/ship .claude/skills/ship $ npx degit highflame-ai/ai-factory/skills/source-driven .claude/skills/source-driven $ npx degit highflame-ai/ai-factory/skills/spec .claude/skills/spec $ npx degit highflame-ai/ai-factory/skills/sprint .claude/skills/sprint $ npx degit highflame-ai/ai-factory/skills/status .claude/skills/status $ npx degit highflame-ai/ai-factory/skills/template-drift .claude/skills/template-drift $ npx degit highflame-ai/ai-factory/skills/threat-model .claude/skills/threat-model $ npx degit highflame-ai/ai-factory/skills/triage-dev .claude/skills/triage-dev $ npx degit highflame-ai/ai-factory/skills/using-aif .claude/skills/using-aif $ npx degit highflame-ai/ai-factory/skills/validate .claude/skills/validate
$ curl -fsSL --create-dirs -o .claude/agents/adversary.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/adversary.md $ curl -fsSL --create-dirs -o .claude/agents/api-cost-scanner.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/api-cost-scanner.md $ curl -fsSL --create-dirs -o .claude/agents/architecture-mapper.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/architecture-mapper.md $ curl -fsSL --create-dirs -o .claude/agents/architecture-reviewer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/architecture-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/cedar-policy-reviewer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/cedar-policy-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/code-quality-auditor.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/code-quality-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/convention-auditor.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/convention-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/correctness-reviewer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/correctness-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/cross-repo-impact.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/cross-repo-impact.md $ curl -fsSL --create-dirs -o .claude/agents/db-perf-scanner.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/db-perf-scanner.md $ curl -fsSL --create-dirs -o .claude/agents/delegate-pre-pass.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/delegate-pre-pass.md $ curl -fsSL --create-dirs -o .claude/agents/feature-tracer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/feature-tracer.md $ curl -fsSL --create-dirs -o .claude/agents/gemini-reviewer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/gemini-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/integration-explorer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/integration-explorer.md $ curl -fsSL --create-dirs -o .claude/agents/kind-regression-runner.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/kind-regression-runner.md $ curl -fsSL --create-dirs -o .claude/agents/latency-scanner.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/latency-scanner.md $ curl -fsSL --create-dirs -o .claude/agents/local-stack-runner.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/local-stack-runner.md $ curl -fsSL --create-dirs -o .claude/agents/migration-analyzer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/migration-analyzer.md $ curl -fsSL --create-dirs -o .claude/agents/pipeline-runner.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/pipeline-runner.md $ curl -fsSL --create-dirs -o .claude/agents/pr-shepherd.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/pr-shepherd.md $ curl -fsSL --create-dirs -o .claude/agents/quality-reviewer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/quality-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/reflector.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/reflector.md $ curl -fsSL --create-dirs -o .claude/agents/security-auditor.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/security-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/task-implementer.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/task-implementer.md $ curl -fsSL --create-dirs -o .claude/agents/test-auditor.md https://raw.githubusercontent.com/highflame-ai/ai-factory/main/agents/test-auditor.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf /*)",
"Bash(rm -rf /:*)"
],
"ask": [
"Bash(git push --force)",
"Bash(git push -f)",
"Bash(git push --force main:*)",
"Bash(git push --force origin main:*)",
"Bash(git reset --hard:*)",
"Bash(git clean -f:*)",
"Bash(git clean -fd:*)",
"Bash(git branch -D:*)",
"Bash(gh pr merge:*)",
"Bash(gh pr close:*)",
"Bash(gh release:*)",
"Bash(rm -rf:*)",
"Bash(rm -f:*)",
"Bash(./deploy.sh:*)",
"Bash(terraform apply:*)",
"Bash(terraform destroy:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "if [ -x \"$HOME/.claude/aif-hooks/secret-scan.sh\" ]; then \"$HOME/.claude/aif-hooks/secret-scan.sh\"; fi"
},
{
"type": "command",
"command": "if [ -x \"$HOME/.claude/aif-hooks/commit-prefix-check.sh\" ]; then \"$HOME/.claude/aif-hooks/commit-prefix-check.sh\"; fi"
},
{
"type": "command",
"command": "if [ -x \"$HOME/.claude/aif-hooks/precommit-gate.sh\" ]; then \"$HOME/.claude/aif-hooks/precommit-gate.sh\"; fi"
}
]
}
]
}
} Skills (41)
add-detectoradversaryanalyzearchitectaudit-permissionsbugfixcanarydebugdep-updatedeprecatedoc-driftexpertfeature-prepfrom-issuegit-workflowgrill-featurehandoffincremental-implementationinitlicense-auditmanifestmeasurenew-admin-moduleonboardoptimizeproceedreflectrelease-notesreviewrotate-secretsshipsource-drivenspecsprintstatustemplate-driftthreat-modeltriage-devusing-aifvalidatewrapup
Subagents (26)
| adversary model: opus | Adversarially attacks any artifact (spec, architecture, plan, diff/PR, README, or prose claim) — assumes it is wrong, broken, or incomplete and tries to prove it, then reports only the findings that s |
| api-cost-scanner model: sonnet | Scans codebase for AI/API cost optimization opportunities including model usage, token estimates, caching strategies, and redundant calls. Use when auditing API costs. |
| architecture-mapper model: haiku | Maps all files and architectural layers that will be affected by a proposed change. Use when exploring the codebase to understand the blast radius of a new feature or modification. |
| architecture-reviewer model: sonnet | Reviews code changes for architectural compliance, separation of concerns, test coverage, and API contract adherence. Use when performing code review focused on architecture and testing. |
| cedar-policy-reviewer model: opus | Reviews Cedar policy authoring against your org's Cedar schemas and conventions (for orgs that use Cedar). Validates syntax, schema conformance, and scoping conventions when adding or modifying Cedar |
| code-quality-auditor model: sonnet | Audits codebase for technical debt, dead code, complexity, duplication, and maintenance issues. Use when performing a codebase health audit focused on code quality. |
| convention-auditor model: haiku | Audits codebase for convention violations including naming, logging, configuration, imports, and error handling patterns. Use when performing a codebase health audit focused on convention compliance. |
| correctness-reviewer model: opus | Reviews code changes for logic errors, race conditions, security vulnerabilities, and edge cases. Use when performing code review focused on correctness and bug detection. |
| cross-repo-impact model: sonnet | Finds every downstream effect of a proposed change across your org's repos. Use before renaming a field, changing an API signature, modifying a shared contract or schema, or touching any inter-service |
| db-perf-scanner model: sonnet | Scans codebase for database and storage performance issues including Firestore query patterns, GCS operations, pagination, and batching opportunities. Use when auditing database performance. |
| delegate-pre-pass model: haiku | Per-repo advisory delegation pre-pass for the /sprint --workflow Phase-5 review panel. Runs the gate + worktree diff + redaction + aif-read I/O and returns a structured CANDIDATES object (untrusted de |
| feature-tracer model: haiku | Traces existing features and implementation patterns in the codebase to find similar precedents for a new feature. Use when exploring the codebase during architecture design. |
| gemini-reviewer model: sonnet | Fetches all gemini-code-assist[bot] comments from a GitHub PR, evaluates each against your org's conventions, applies good suggestions, rejects bad ones with reasons, and reports. Use when Gemini has |
| integration-explorer model: haiku | Identifies extension points, existing tests, integration surfaces, and API contracts that a new feature must respect. Use when exploring the codebase to understand integration requirements. |
| kind-regression-runner model: sonnet | Drives your org's end-to-end regression suite from the repo named by `regression.repo` in `.aif/config.yml` — commonly a kind (Kubernetes-in-Docker) cluster deployed via helmfile with a pytest suite o |
| latency-scanner model: sonnet | Scans codebase for request latency issues including sequential async operations, payload sizes, middleware overhead, and cold start impact. Use when auditing request performance. |
| local-stack-runner model: sonnet | Brings up (or down) the local development stack defined by `local_stack.*` in `.aif/config.yml`. Picks the minimum set of services for the user's task, runs pre-flight checks (env file, registry login |
| migration-analyzer model: opus | Audits SQL schema and data migrations for safety before they run against shared dev, staging, or production Postgres. Checks for locking hazards, backfill strategies, NULL handling, rollback capabilit |
| pipeline-runner model: opus | Runs the complete /proceed pipeline for a single REQ in subagent mode (all phases sequential, no sub-agent dispatch). Use when /sprint needs to run multiple REQs in parallel. |
| pr-shepherd model: sonnet | Watches an open PR after push and auto-fixes mechanical CI failures (commit-message format, dependency-scanner CVE bumps, formatter drift, lockfile drift) until the PR is green or a non-mechanical fai |
| quality-reviewer model: sonnet | Reviews code changes for convention compliance, naming standards, code duplication, and quality issues. Use when performing code review focused on code quality and project conventions. |
| reflector model: opus | Performs post-implementation self-review using a comprehensive checklist and checks lessons learned for applicable pitfalls. Use for honest self-assessment of recently implemented code before formal r |
| security-auditor model: opus | Audits codebase for security vulnerabilities including input validation, authentication, authorization, data exposure, and dependency issues. Use when performing a security-focused codebase audit. |
| security-reviewer model: opus | Audits code for auth, multi-tenancy, JWT, secret exposure, and SQL-injection violations against your project's documented conventions. Use when reviewing a PR, before merging auth-adjacent changes, or |
| task-implementer model: opus | Implements a single AIF task from a task file, following project conventions and architecture. Use when executing implementation tasks from /proceed Phase 4. |
| test-auditor model: sonnet | Audits codebase for test coverage gaps, mock completeness, test quality, and testing best practices. Use when performing a codebase health audit focused on testing. |
Hooks (9)
| event | matcher | runs |
|---|---|---|
| SessionStart | * | if [ -x "$HOME/.claude/aif-hooks/session-start-skills.sh" ]; then "$HOME/.claude/aif-hooks/session-start-skills.sh"; fi |
| PostToolUse | Edit|Write|NotebookEdit | if [ -x "$HOME/.claude/aif-hooks/go-format.sh" ]; then "$HOME/.claude/aif-hooks/go-format.sh"; fi |
| PostToolUse | Edit|Write|NotebookEdit | if [ -x "$HOME/.claude/aif-hooks/ts-format.sh" ]; then "$HOME/.claude/aif-hooks/ts-format.sh"; fi |
| PostToolUse | Edit|Write|NotebookEdit | if [ -x "$HOME/.claude/aif-hooks/py-format.sh" ]; then "$HOME/.claude/aif-hooks/py-format.sh"; fi |
| PostToolUse | Edit|Write|NotebookEdit | if [ -x "$HOME/.claude/aif-hooks/rust-format.sh" ]; then "$HOME/.claude/aif-hooks/rust-format.sh"; fi |
| PreToolUse | Bash | if [ -x "$HOME/.claude/aif-hooks/secret-scan.sh" ]; then "$HOME/.claude/aif-hooks/secret-scan.sh"; fi |
| PreToolUse | Bash | if [ -x "$HOME/.claude/aif-hooks/commit-prefix-check.sh" ]; then "$HOME/.claude/aif-hooks/commit-prefix-check.sh"; fi |
| PreToolUse | Bash | if [ -x "$HOME/.claude/aif-hooks/precommit-gate.sh" ]; then "$HOME/.claude/aif-hooks/precommit-gate.sh"; fi |
| Stop | * | if [ -x "$HOME/.claude/aif-hooks/session-reflect.sh" ]; then "$HOME/.claude/aif-hooks/session-reflect.sh"; fi |
Permissions
deny (2)
Bash(rm -rf /*)
Bash(rm -rf /:*)
ask (18)
Bash(git push --force)
Bash(git push -f)
Bash(git push --force main:*)
Bash(git push --force origin main:*)
Bash(git reset --hard:*)
Bash(git clean -f:*)
Bash(git clean -fd:*)
Bash(git branch -D:*)
Bash(gh pr merge:*)
Bash(gh pr close:*)
Bash(gh release:*)
Bash(rm -rf:*)
Bash(rm -f:*)
Bash(./deploy.sh:*)
Bash(terraform apply:*)
Bash(terraform destroy:*)
Bash(git push --force:*)
Bash(git push -f:*)
allow (93)
Bash(awk:*)
Bash(cat:*)
Bash(cd:*)
Bash(cp:*)
Bash(date:*)
Bash(docker compose logs:*)
Bash(docker compose ps:*)
Bash(docker logs:*)
Bash(docker ps:*)
Bash(echo:*)
Bash(find:*)
Bash(gh api:*)
Bash(gh auth status:*)
Bash(gh issue list:*)
Bash(gh issue view:*)
Bash(gh pr checks:*)
Bash(gh pr comment:*)
Bash(gh pr create:*)
Bash(gh pr diff:*)
Bash(gh pr edit:*)
Bash(gh pr list:*)
Bash(gh pr ready:*)
Bash(gh pr review:*)
Bash(gh pr view:*)
Bash(gh run list:*)
Bash(gh run view:*)
Bash(gh run watch:*)
Bash(git add:*)
Bash(git branch:*)
Bash(git checkout:*)
Bash(git commit:*)
Bash(git config --get:*)
Bash(git config user.email)
Bash(git config user.name)
Bash(git diff:*)
Bash(git fetch:*)
Bash(git log:*)
Bash(git merge-base:*)
Bash(git merge:*)
Bash(git mv:*)
Bash(git pull:*)
Bash(git push:*)
Bash(git rebase:*)
Bash(git restore:*)
Bash(git rm:*)
Bash(git show:*)
Bash(git stash:*)
Bash(git status:*)
Bash(git worktree:*)
Bash(go build:*)
Bash(go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@*)
Bash(go mod:*)
Bash(go test:*)
Bash(go vet:*)
Bash(gofmt:*)
Bash(goimports:*)
Bash(golangci-lint:*)
Bash(head:*)
Bash(ls:*)
Bash(make build:*)
Similar rigs
itsOmidKarami/kraft
A local orchestrator that takes your coding agent from spec to pull request, stopping only when a decision is yours.
Skill Collector 7.9k tok ·
chengxuniucode/ForgeTeam
AI coding framework — one person, full team delivery. Pure Shell+Markdown, zero dependencies, works with Claude Code / Cursor / Codex / OpenCode. 开源 AI 编码框架,一人全栈交付。
Skill Collector 748 tok ·
mehrad-dm/mastermind
⚗️ Experimental — A markdown brain that gives your AI coding tools judgment and rigor: sharp defaults, real decisions, and the discipline to verify before saying done. For Claude Code, Cursor and Codex. It improves itself over time.
Orchestrator 6.8k tok ·
stefan-jansen/coding-agent-plugins
Plugin marketplace for coding-agent-toolkit — workflow, memory, transition, development, and code-quality plugins for Claude Code.
Skill Collector 1.0k tok ·