kunko-ai-labs/agent-assurance
Declare what your AI agent may do. Verify it on every edit, PR and release — MCP configs, Claude Code permissions, tool definitions. Deterministic, OWASP-mapped, signed evidence.
ARCHETYPE
YOLO Cowboy
Permissions? Never heard of 'em. Ships at the speed of `--dangerously-skip-permissions`.
Copy this rig
# review before running: this installs third-party code $ claude mcp add postgres -- npx -y @modelcontextprotocol/server-postgres postgresql://localhost/analytics $ claude mcp add fetch -- uvx mcp-server-fetch $ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github $ claude mcp add slack -e SLACK_BOT_<redacted> -- npx -y @modelcontextprotocol/server-slack $ claude mcp add --transport http acme-erp https://mcp.acme-erp.example/v1 -H 'Authorization: YOUR_VALUE' $ claude mcp add --transport http acme-crm https://mcp.acme.example/crm $ npx degit kunko-ai-labs/agent-assurance/examples/repos/claude-code-approval-broken/.claude ./rig-agent-assurance # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add postgres -- npx -y @modelcontextprotocol/server-postgres postgresql://localhost/analytics $ claude mcp add fetch -- uvx mcp-server-fetch $ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github $ claude mcp add slack -e SLACK_BOT_<redacted> -- npx -y @modelcontextprotocol/server-slack $ claude mcp add --transport http acme-erp https://mcp.acme-erp.example/v1 -H 'Authorization: YOUR_VALUE' $ claude mcp add --transport http acme-crm https://mcp.acme.example/crm
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"WebFetch",
"Bash(rm -rf *)"
],
"ask": [
"Edit",
"Write",
"Bash(npm test)"
]
}
} MCP servers (6)
| server | source | est. tokens |
|---|---|---|
| Postgres | npm | 600 |
| Fetch | pypi | 450 |
| GitHub MCP · "github" env: GITHUB_PERSONAL_ACCESS_TOKEN | npm | 18.0k |
| Slack env: SLACK_BOT_TOKEN | npm | 3.5k |
| mcp.acme-erp.example · "acme-erp" | remote · remote | 2.5k |
| mcp.acme.example · "acme-crm" | remote · remote | 2.5k |
Permissions
deny (2)
WebFetch
Bash(rm -rf *)
ask (3)
Edit
Write
Bash(npm test)
allow (8)
Read
Edit
Write
Bash(*)
mcp__github
Read
Glob
Grep
Similar rigs
holt-web-ai/n8n-nodes-claudecode
—
Pragmatist 27.1k tok ·
sjrhee/claudeGuides
Claude Code environment guides - agents, skills, plugins, settings, hooks, workflows, and CLAUDE.md best practices
Pragmatist 21.4k tok ·
Cordycepsers/vscode-claude-setup-2025
Complete configuration for Python, Node.js, React, and TypeScript development with VS Code, Claude Desktop, and Claude Code
MCP Hoarder 53.0k tok ·
YoungXAI/Dotfiles
Cross-platform (macOS/Linux) dev environment bootstrap: Zsh + Zinit + P10k, Kitty, VSCode/Cursor, Claude Code, 80+ packages — one command setup. | 跨平台开发环境一键部署系统:Shell、编辑器、终端、AI 工具链全套配置,模块化、幂等、无需 root。
YOLO Cowboy 31.1k tok ·