~ / rigs / jitpass / jit

jitpass/jit

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and local-first.

↗ GitHub ★ 162 NOASSERTION updated 4d ago project Claude Code
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~5.5k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit jitpass/jit/.claude ./rig-jit  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit jitpass/jit/.claude/skills/qa-release .claude/skills/qa-release
$ curl -fsSL --create-dirs -o .claude/agents/jit-qa-bughunter.md https://raw.githubusercontent.com/jitpass/jit/main/.claude/agents/jit-qa-bughunter.md
$ curl -fsSL --create-dirs -o .claude/agents/jit-qa-code.md https://raw.githubusercontent.com/jitpass/jit/main/.claude/agents/jit-qa-code.md
$ curl -fsSL --create-dirs -o .claude/agents/jit-qa-docs.md https://raw.githubusercontent.com/jitpass/jit/main/.claude/agents/jit-qa-docs.md
$ curl -fsSL --create-dirs -o .claude/agents/jit-qa-functionality.md https://raw.githubusercontent.com/jitpass/jit/main/.claude/agents/jit-qa-functionality.md
$ curl -fsSL --create-dirs -o .claude/agents/jit-qa-integrations.md https://raw.githubusercontent.com/jitpass/jit/main/.claude/agents/jit-qa-integrations.md
$ curl -fsSL --create-dirs -o .claude/agents/jit-qa-ux.md https://raw.githubusercontent.com/jitpass/jit/main/.claude/agents/jit-qa-ux.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (1)

Subagents (6)

jit-qa-bughunterAdversarial QA engineer for jit — tries to BREAK the release. Use to stress edge cases, malformed inputs, guard-bypass attempts, unusual states, and concurrency before shipping. Reports bugs with repr
jit-qa-codeRead-only code QA engineer for a jit release. Use to review the code that changed since the last release for correctness bugs, security regressions, and behavior changes — before shipping. Points the
jit-qa-docsQA engineer for jit's docs and design fidelity. Use to verify the docs are up to date with the shipped CLI (help text, command reference, guides) and that the implementation follows the project's desi
jit-qa-functionalityQA engineer for jit's core secret engine. Use when validating a release candidate's core functionality — vault CRUD, scan, migrate mechanics, rekey, audit/status/doctor, export/import, the delete dril
jit-qa-integrationsQA engineer for jit's external-tool integration surface. Use when validating that real tools actually receive their secrets just-in-time through jit — wrap (catalog CLIs), mounts, terraform, clisso/aw
jit-qa-uxQA engineer for jit's user experience. Use when validating a release's output clarity, help text, error messages, flag consistency, house-style adherence, and first-time-user discoverability. Runs com

Similar rigs

copied ✓