~ / rigs / kapadias / nonna

kapadias/nonna

Your AI agent says done. Nonna makes it prove it: she runs your test suite before a coding agent can stop, and blocks pushes to main and secrets in files. Claude Code plugin, plus git hooks for Codex, Cursor, Copilot, Gemini and more

↗ GitHub ★ 0 MIT updated 5d ago project Claude CodeCodexCursorGemini CLICopilot Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~3.9k tokens
Moderate · median rig: 2.2k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit kapadias/nonna/.claude ./rig-nonna  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit kapadias/nonna/.claude/skills/adr .claude/skills/adr
$ npx degit kapadias/nonna/.claude/skills/api-design .claude/skills/api-design
$ npx degit kapadias/nonna/.claude/skills/audit .claude/skills/audit
$ npx degit kapadias/nonna/.claude/skills/code-review .claude/skills/code-review
$ npx degit kapadias/nonna/.claude/skills/concurrency-performance .claude/skills/concurrency-performance
$ npx degit kapadias/nonna/.claude/skills/coverage .claude/skills/coverage
$ npx degit kapadias/nonna/.claude/skills/debug .claude/skills/debug
$ npx degit kapadias/nonna/.claude/skills/debugging .claude/skills/debugging
$ npx degit kapadias/nonna/.claude/skills/fast-lane .claude/skills/fast-lane
$ npx degit kapadias/nonna/.claude/skills/fix .claude/skills/fix
$ npx degit kapadias/nonna/.claude/skills/implement .claude/skills/implement
$ npx degit kapadias/nonna/.claude/skills/intake .claude/skills/intake
$ npx degit kapadias/nonna/.claude/skills/lean .claude/skills/lean
$ npx degit kapadias/nonna/.claude/skills/migration-safety .claude/skills/migration-safety
$ npx degit kapadias/nonna/.claude/skills/nonna .claude/skills/nonna
$ npx degit kapadias/nonna/.claude/skills/observability .claude/skills/observability
$ npx degit kapadias/nonna/.claude/skills/plan .claude/skills/plan
$ npx degit kapadias/nonna/.claude/skills/refactoring .claude/skills/refactoring
$ npx degit kapadias/nonna/.claude/skills/release .claude/skills/release
$ npx degit kapadias/nonna/.claude/skills/review .claude/skills/review
$ npx degit kapadias/nonna/.claude/skills/rollback .claude/skills/rollback
$ npx degit kapadias/nonna/.claude/skills/security-review .claude/skills/security-review
$ npx degit kapadias/nonna/.claude/skills/ship .claude/skills/ship
$ npx degit kapadias/nonna/.claude/skills/supply-chain .claude/skills/supply-chain
$ npx degit kapadias/nonna/.claude/skills/sync .claude/skills/sync
$ npx degit kapadias/nonna/.claude/skills/tdd-workflow .claude/skills/tdd-workflow
$ npx degit kapadias/nonna/.claude/skills/tdd .claude/skills/tdd
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/debugger.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/debugger.md
$ curl -fsSL --create-dirs -o .claude/agents/explorer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/explorer.md
$ curl -fsSL --create-dirs -o .claude/agents/implementer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/implementer.md
$ curl -fsSL --create-dirs -o .claude/agents/orchestrator.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/orchestrator.md
$ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/planner.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/security-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/test-engineer.md https://raw.githubusercontent.com/kapadias/nonna/main/.claude/agents/test-engineer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./**/.env)",
      "Read(./**/.env.*)",
      "Read(./**/secrets/**)",
      "Read(./**/*.pem)",
      "Read(./**/*.key)",
      "Read(./**/*.p12)",
      "Read(./**/id_rsa*)",
      "Read(./**/.ssh/**)",
      "Read(./**/.aws/**)",
      "Read(./**/.npmrc)",
      "Read(./**/*.p8)",
      "Read(./**/*.pfx)",
      "Read(./**/*.jks)",
      "Read(./**/kubeconfig)",
      "Read(./**/credentials)",
      "Bash(git push --force:*)",
      "Bash(git push --force-with-lease:*)",
      "Bash(git push -f:*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Edit|Write|MultiEdit",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard-branch.sh"
          },
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/secret-scan.sh"
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard-branch.sh"
          },
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/secret-scan.sh"
          }
        ]
      },
      {
        "matcher": "Read|Grep",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/secret-scan.sh"
          }
        ]
      }
    ]
  }
}

Skills (27)

Subagents (8)

code-reviewer
model: opus
Independent, read-only, adversarial correctness review before merge. Hunts bugs, broken contracts, missing tests, silent failures. Use on every change headed for develop.
debugger
model: opus
Root-cause analysis for failing tests, crashes, and wrong behavior. Reproduces, isolates, and fixes the cause — not the symptom. Use when the cause is not obvious.
explorer
model: haiku
Read-only fan-out search. Sweeps many files to answer "where is X?" or "how is Y wired?" and returns the conclusion, not file dumps. Use whenever answering means reading broadly.
implementer
model: sonnet
Builds and modifies features to make failing tests pass. The bulk of day-to-day engineering. Use after a plan and a failing test exist.
orchestrator
model: opus
Top-level router. Decomposes a request, sequences the dev loop, and delegates. Use for anything cross-cutting or multi-step. Read-only — it routes, it does not edit.
planner
model: opus
Turns a request into a written plan: restates the requirement, surfaces risks, decomposes into reviewable steps, and names the gate each step must pass. Read-only.
security-reviewer
model: opus
Independent, read-only security review: injection, secret leakage, broken authz, unsafe deserialization, supply-chain risk. Use when a change touches auth, data, money, or input.
test-engineer
model: sonnet
Writes the failing tests that pin behavior before implementation, and hardens the suite with golden and property tests. Opens the TDD cycle; closes coverage gaps.

Hooks (11)

eventmatcherruns
PreToolUseEdit|Write|MultiEdit"$CLAUDE_PROJECT_DIR"/.claude/hooks/guard-branch.sh
PreToolUseEdit|Write|MultiEdit"$CLAUDE_PROJECT_DIR"/.claude/hooks/secret-scan.sh
PreToolUseBash"$CLAUDE_PROJECT_DIR"/.claude/hooks/guard-branch.sh
PreToolUseBash"$CLAUDE_PROJECT_DIR"/.claude/hooks/secret-scan.sh
PreToolUseRead|Grep"$CLAUDE_PROJECT_DIR"/.claude/hooks/secret-scan.sh
PostToolUseEdit|Write|MultiEdit"$CLAUDE_PROJECT_DIR"/.claude/hooks/format.sh
SessionStart*"$CLAUDE_PROJECT_DIR"/.claude/hooks/session-start.sh
Stop*"$CLAUDE_PROJECT_DIR"/.claude/hooks/stop-dod.sh
SubagentStopcode-reviewer|security-reviewer"$CLAUDE_PROJECT_DIR"/.claude/hooks/subagent-verdict.sh
SubagentStart*"$CLAUDE_PROJECT_DIR"/.claude/hooks/subagent-start.sh
PostCompact*"$CLAUDE_PROJECT_DIR"/.claude/hooks/post-compact.sh

Cursor rules (2)

nonna · alwaysnonna · always

Permissions

deny (18)
Read(./**/.env)
Read(./**/.env.*)
Read(./**/secrets/**)
Read(./**/*.pem)
Read(./**/*.key)
Read(./**/*.p12)
Read(./**/id_rsa*)
Read(./**/.ssh/**)
Read(./**/.aws/**)
Read(./**/.npmrc)
Read(./**/*.p8)
Read(./**/*.pfx)
Read(./**/*.jks)
Read(./**/kubeconfig)
Read(./**/credentials)
Bash(git push --force:*)
Bash(git push --force-with-lease:*)
Bash(git push -f:*)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓