jposluns/grc_library
A documentation library for governance, risk, compliance, cybersecurity, privacy, resilience, AI assurance, and operational control practices + a Claude Code rules-and-skills pack distilled from maintaining it.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit jposluns/grc_library/.claude ./rig-grc_library # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit jposluns/grc_library/.claude/skills/addyosmani-ci-cd-and-automation .claude/skills/addyosmani-ci-cd-and-automation $ npx degit jposluns/grc_library/.claude/skills/addyosmani-code-review-and-quality .claude/skills/addyosmani-code-review-and-quality $ npx degit jposluns/grc_library/.claude/skills/addyosmani-context-engineering .claude/skills/addyosmani-context-engineering $ npx degit jposluns/grc_library/.claude/skills/addyosmani-security-and-hardening .claude/skills/addyosmani-security-and-hardening $ npx degit jposluns/grc_library/.claude/skills/addyosmani-using-agent-skills .claude/skills/addyosmani-using-agent-skills $ npx degit jposluns/grc_library/.claude/skills/ci-wait .claude/skills/ci-wait $ npx degit jposluns/grc_library/.claude/skills/clean-language .claude/skills/clean-language $ npx degit jposluns/grc_library/.claude/skills/pr-close-out .claude/skills/pr-close-out $ npx degit jposluns/grc_library/guardrails/skills/action-before-explanation-of-inaction .claude/skills/action-before-explanation-of-inaction $ npx degit jposluns/grc_library/guardrails/skills/adopt .claude/skills/adopt $ npx degit jposluns/grc_library/guardrails/skills/artefact-discipline-check .claude/skills/artefact-discipline-check $ npx degit jposluns/grc_library/guardrails/skills/change-tracking-write-entry .claude/skills/change-tracking-write-entry $ npx degit jposluns/grc_library/guardrails/skills/citation-quote-verification .claude/skills/citation-quote-verification $ npx degit jposluns/grc_library/guardrails/skills/claim-fit .claude/skills/claim-fit $ npx degit jposluns/grc_library/guardrails/skills/clarify-before-acting .claude/skills/clarify-before-acting $ npx degit jposluns/grc_library/guardrails/skills/deep-assessment .claude/skills/deep-assessment $ npx degit jposluns/grc_library/guardrails/skills/deep-qa-review .claude/skills/deep-qa-review $ npx degit jposluns/grc_library/guardrails/skills/evidence-grounded-completion .claude/skills/evidence-grounded-completion $ npx degit jposluns/grc_library/guardrails/skills/fresh-reader-validation .claude/skills/fresh-reader-validation $ npx degit jposluns/grc_library/guardrails/skills/gate-discipline-diagnose .claude/skills/gate-discipline-diagnose $ npx degit jposluns/grc_library/guardrails/skills/guardrail-review .claude/skills/guardrail-review $ npx degit jposluns/grc_library/guardrails/skills/high-assurance-verification .claude/skills/high-assurance-verification $ npx degit jposluns/grc_library/guardrails/skills/library-fitness-review .claude/skills/library-fitness-review $ npx degit jposluns/grc_library/guardrails/skills/matrix-fit .claude/skills/matrix-fit $ npx degit jposluns/grc_library/guardrails/skills/pr-retrospective .claude/skills/pr-retrospective $ npx degit jposluns/grc_library/guardrails/skills/publication-screening .claude/skills/publication-screening $ npx degit jposluns/grc_library/guardrails/skills/reference-audit .claude/skills/reference-audit $ npx degit jposluns/grc_library/guardrails/skills/skill-authoring-discipline .claude/skills/skill-authoring-discipline $ npx degit jposluns/grc_library/guardrails/skills/surface-instruction-concern .claude/skills/surface-instruction-concern $ npx degit jposluns/grc_library/guardrails/skills/validate-inference .claude/skills/validate-inference $ npx degit jposluns/grc_library/guardrails/skills/validation-sweep-pr-scoped .claude/skills/validation-sweep-pr-scoped $ npx degit jposluns/grc_library/guardrails/skills/validation-sweep .claude/skills/validation-sweep
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./secrets/**)",
"Bash(rm -rf *)",
"Bash(git push --force*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-repeated-tool-failure.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-verification-pipes.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-wrong-repo-tool.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-unbumped-version-commit.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-public-working-write.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-bulk-git-add.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-on-open-findings.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-pr-without-resume-validate.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-claude-attribution.py"
}
]
},
{
"matcher": "AskUserQuestion",
"hooks": [
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-repeated-tool-failure.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-askuserquestion-unattended.py"
}
]
},
{
"matcher": "Edit|Write",
"hooks": [
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-operational-without-private.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-unjustified-decision.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-branch-to-main-edit.py"
},
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-public-working-write.py"
}
]
},
{
"matcher": "Task|Agent|Workflow|SendMessage",
"hooks": [
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-orchestrator-self-qa.py"
}
]
},
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "/usr/bin/python3 -I \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-opus5-orchestrator-model.py"
}
]
}
]
}
} Skills (32)
addyosmani-ci-cd-and-automationaddyosmani-code-review-and-qualityaddyosmani-context-engineeringaddyosmani-security-and-hardeningaddyosmani-using-agent-skillsci-waitclean-languagepr-close-outaction-before-explanation-of-inactionadoptartefact-discipline-checkchange-tracking-write-entrycitation-quote-verificationclaim-fitclarify-before-actingdeep-assessmentdeep-qa-reviewevidence-grounded-completionfresh-reader-validationgate-discipline-diagnoseguardrail-reviewhigh-assurance-verificationlibrary-fitness-reviewmatrix-fitpr-retrospectivepublication-screeningreference-auditskill-authoring-disciplinesurface-instruction-concernvalidate-inferencevalidation-sweep-pr-scopedvalidation-sweep
Hooks (25)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-repeated-tool-failure.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-verification-pipes.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-wrong-repo-tool.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-unbumped-version-commit.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-public-working-write.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-bulk-git-add.py |
| PreToolUse | AskUserQuestion | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-repeated-tool-failure.py |
| PreToolUse | AskUserQuestion | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-askuserquestion-unattended.py |
| PreToolUse | Edit|Write | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-operational-without-private.py |
| PreToolUse | Edit|Write | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-unjustified-decision.py |
| PreToolUse | Edit|Write | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-branch-to-main-edit.py |
| PreToolUse | Edit|Write | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-public-working-write.py |
| PreToolUse | Task|Agent|Workflow|SendMessage | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-orchestrator-self-qa.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-on-open-findings.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-pr-without-resume-validate.py |
| PreToolUse | Bash | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-claude-attribution.py |
| PreToolUse | * | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-opus5-orchestrator-model.py |
| Stop | * | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-turn-end-with-outstanding-work.py |
| Stop | * | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/surface-session-facts.py |
| Stop | * | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-opus5-orchestrator-model.py |
| Stop | * | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-unstamped-turn-end.py |
| Stop | * | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/stop-guard-unattended.py |
| UserPromptSubmit | * | /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/inject-session-timestamp.py |
| PostToolUse | * | ORCH_LEASE_FILE="$CLAUDE_PROJECT_DIR"/../private/session-state.md /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/clock-inject.py |
| PostToolUseFailure | * | ORCH_LEASE_FILE="$CLAUDE_PROJECT_DIR"/../private/session-state.md /usr/bin/python3 -I "$CLAUDE_PROJECT_DIR"/.claude/hooks/clock-inject.py |
Slash commands (16)
/adopt/claim-fit/deep-assessment/fitness/full-qa/guardrails/high-assurance/matrix-fit/pipeline/reference-audit/restore-broken/retro/screen-publications/trust-recovery/validate-pr/validate
Permissions
deny (5)
Read(./.env)
Read(./.env.*)
Read(./secrets/**)
Bash(rm -rf *)
Bash(git push --force*)
ask (0)
—
allow (0)
—
Similar rigs
BytesFromToby/plumbline
A "trust, but verify" workflow of AI-agent skills: prompt to verified code, every step trackable and deviations logged — plus an autonomous maintenance loop to keep a built project honest.
Pragmatist 1.7k tok ·
heltondoria/claude-code-sdd-kit
Specification-Driven Development toolkit for Claude Code — skills, hooks, agents, and templates for TDD-first project workflows
Skill Collector 2.2k tok ·
ballred/obsidian-claude-pkm
A complete starter kit for an Obsidian + Claude Code personal knowledge management system.
Skill Collector 2.0k tok ·
checkwright/checkwright
Deterministic verification for coding-agent delivery. Checkwright is the verification layer under agent orchestration: spec drift, skipped stages, and unsupported done claims become failing checks before a merge, instead of review findings
Orchestrator 4.1k tok ·