kapadias/nonna
Your AI agent says done. Nonna makes it prove it: she runs your test suite before a coding agent can stop, and blocks pushes to main and secrets in files. Claude Code plugin, plus git hooks for Codex, Cursor, Copilot, Gemini and more
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit kapadias/nonna/.claude ./rig-nonna # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit kapadias/nonna/.claude/skills/adr .claude/skills/adr $ npx degit kapadias/nonna/.claude/skills/api-design .claude/skills/api-design $ npx degit kapadias/nonna/.claude/skills/audit .claude/skills/audit $ npx degit kapadias/nonna/.claude/skills/code-review .claude/skills/code-review $ npx degit kapadias/nonna/.claude/skills/concurrency-performance .claude/skills/concurrency-performance $ npx degit kapadias/nonna/.claude/skills/coverage .claude/skills/coverage $ npx degit kapadias/nonna/.claude/skills/debug .claude/skills/debug $ npx degit kapadias/nonna/.claude/skills/debugging .claude/skills/debugging $ npx degit kapadias/nonna/.claude/skills/fast-lane .claude/skills/fast-lane $ npx degit kapadias/nonna/.claude/skills/fix .claude/skills/fix $ npx degit kapadias/nonna/.claude/skills/implement .claude/skills/implement $ npx degit kapadias/nonna/.claude/skills/intake .claude/skills/intake $ npx degit kapadias/nonna/.claude/skills/lean .claude/skills/lean $ npx degit kapadias/nonna/.claude/skills/migration-safety .claude/skills/migration-safety $ npx degit kapadias/nonna/.claude/skills/nonna .claude/skills/nonna $ npx degit kapadias/nonna/.claude/skills/observability .claude/skills/observability $ npx degit kapadias/nonna/.claude/skills/plan .claude/skills/plan $ npx degit kapadias/nonna/.claude/skills/refactoring .claude/skills/refactoring $ npx degit kapadias/nonna/.claude/skills/release .claude/skills/release $ npx degit kapadias/nonna/.claude/skills/review .claude/skills/review $ npx degit kapadias/nonna/.claude/skills/rollback .claude/skills/rollback $ npx degit kapadias/nonna/.claude/skills/security-review .claude/skills/security-review $ npx degit kapadias/nonna/.claude/skills/ship .claude/skills/ship $ npx degit kapadias/nonna/.claude/skills/supply-chain .claude/skills/supply-chain $ npx degit kapadias/nonna/.claude/skills/sync .claude/skills/sync $ npx degit kapadias/nonna/.claude/skills/tdd-workflow .claude/skills/tdd-workflow $ npx degit kapadias/nonna/.claude/skills/tdd .claude/skills/tdd
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/code-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/debugger.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/debugger.md $ curl -fsSL --create-dirs -o .claude/agents/explorer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/explorer.md $ curl -fsSL --create-dirs -o .claude/agents/implementer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/implementer.md $ curl -fsSL --create-dirs -o .claude/agents/orchestrator.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/orchestrator.md $ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/planner.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/test-engineer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/test-engineer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(./**/.env)",
"Read(./**/.env.*)",
"Read(./**/secrets/**)",
"Read(./**/*.pem)",
"Read(./**/*.key)",
"Read(./**/*.p12)",
"Read(./**/id_rsa*)",
"Read(./**/.ssh/**)",
"Read(./**/.aws/**)",
"Read(./**/.npmrc)",
"Read(./**/*.p8)",
"Read(./**/*.pfx)",
"Read(./**/*.jks)",
"Read(./**/kubeconfig)",
"Read(./**/credentials)",
"Bash(git push --force:*)",
"Bash(git push --force-with-lease:*)",
"Bash(git push -f:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write|MultiEdit",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard-branch.sh"
},
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/secret-scan.sh"
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard-branch.sh"
},
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/secret-scan.sh"
}
]
},
{
"matcher": "Read|Grep",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/secret-scan.sh"
}
]
}
]
}
} Skills (27)
adrapi-designauditcode-reviewconcurrency-performancecoveragedebugdebuggingfast-lanefiximplementintakeleanmigration-safetynonnaobservabilityplanrefactoringreleasereviewrollbacksecurity-reviewshipsupply-chainsynctdd-workflowtdd
Subagents (8)
| code-reviewer model: opus | Independent, read-only, adversarial correctness review before merge. Hunts bugs, broken contracts, missing tests, silent failures. Use on every change headed for develop. |
| debugger model: opus | Root-cause analysis for failing tests, crashes, and wrong behavior. Reproduces, isolates, and fixes the cause — not the symptom. Use when the cause is not obvious. |
| explorer model: haiku | Read-only fan-out search. Sweeps many files to answer "where is X?" or "how is Y wired?" and returns the conclusion, not file dumps. Use whenever answering means reading broadly. |
| implementer model: sonnet | Builds and modifies features to make failing tests pass. The bulk of day-to-day engineering. Use after a plan and a failing test exist. |
| orchestrator model: opus | Top-level router. Decomposes a request, sequences the dev loop, and delegates. Use for anything cross-cutting or multi-step. Read-only — it routes, it does not edit. |
| planner model: opus | Turns a request into a written plan: restates the requirement, surfaces risks, decomposes into reviewable steps, and names the gate each step must pass. Read-only. |
| security-reviewer model: opus | Independent, read-only security review: injection, secret leakage, broken authz, unsafe deserialization, supply-chain risk. Use when a change touches auth, data, money, or input. |
| test-engineer model: sonnet | Writes the failing tests that pin behavior before implementation, and hardens the suite with golden and property tests. Opens the TDD cycle; closes coverage gaps. |
Hooks (11)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Edit|Write|MultiEdit | "$CLAUDE_PROJECT_DIR"/.claude/hooks/guard-branch.sh |
| PreToolUse | Edit|Write|MultiEdit | "$CLAUDE_PROJECT_DIR"/.claude/hooks/secret-scan.sh |
| PreToolUse | Bash | "$CLAUDE_PROJECT_DIR"/.claude/hooks/guard-branch.sh |
| PreToolUse | Bash | "$CLAUDE_PROJECT_DIR"/.claude/hooks/secret-scan.sh |
| PreToolUse | Read|Grep | "$CLAUDE_PROJECT_DIR"/.claude/hooks/secret-scan.sh |
| PostToolUse | Edit|Write|MultiEdit | "$CLAUDE_PROJECT_DIR"/.claude/hooks/format.sh |
| SessionStart | * | "$CLAUDE_PROJECT_DIR"/.claude/hooks/session-start.sh |
| Stop | * | "$CLAUDE_PROJECT_DIR"/.claude/hooks/stop-dod.sh |
| SubagentStop | code-reviewer|security-reviewer | "$CLAUDE_PROJECT_DIR"/.claude/hooks/subagent-verdict.sh |
| SubagentStart | * | "$CLAUDE_PROJECT_DIR"/.claude/hooks/subagent-start.sh |
| PostCompact | * | "$CLAUDE_PROJECT_DIR"/.claude/hooks/post-compact.sh |
Cursor rules (2)
nonna · alwaysnonna · always
Permissions
deny (18)
Read(./**/.env)
Read(./**/.env.*)
Read(./**/secrets/**)
Read(./**/*.pem)
Read(./**/*.key)
Read(./**/*.p12)
Read(./**/id_rsa*)
Read(./**/.ssh/**)
Read(./**/.aws/**)
Read(./**/.npmrc)
Read(./**/*.p8)
Read(./**/*.pfx)
Read(./**/*.jks)
Read(./**/kubeconfig)
Read(./**/credentials)
Bash(git push --force:*)
Bash(git push --force-with-lease:*)
Bash(git push -f:*)
ask (0)
—
allow (0)
—
Similar rigs
r3dpepper/claude-dotfiles
Claude code workflow harness files. Goes to ~/.claude in user-scoped location.
Fort Knox 1.5k tok ·
anujg21/claude-engineering-os
A repository template that gives Claude Code a working engineering method: phased workflow, path-scoped standards, independent review agents, and hooks that block dangerous commands.
Skill Collector 3.1k tok ·
selmakcby/claude-agents-skills
Multi-Agent Claude Code setup — 4 uzman ajan (planner · ui-agent · builder · reviewer) + skills + Next.js demo projesi. YouTube Bölüm 1 video materyalleri.
Orchestrator 1.5k tok ·
ZaaliMohamed123/evolving-claude
A self-improving global Claude Code setup: 10 subagents, on-demand skills, safety hooks, three-tier memory, and a config feedback loop.
Orchestrator 2.2k tok ·