~ / rigs / kunko-ai-labs / agent-assurance

kunko-ai-labs/agent-assurance

Declare what your AI agent may do. Verify it on every edit, PR and release — MCP configs, Claude Code permissions, tool definitions. Deterministic, OWASP-mapped, signed evidence.

↗ GitHub ★ 3 NOASSERTION updated 2d ago project Claude CodeCodex
share on X
ARCHETYPE
YOLO Cowboy
Permissions? Never heard of 'em. Ships at the speed of `--dangerously-skip-permissions`.
CONTEXT TAX · EVERY TURN
~28.5k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
2/5
Blocks destructive commands · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add postgres -- npx -y @modelcontextprotocol/server-postgres postgresql://localhost/analytics
$ claude mcp add fetch -- uvx mcp-server-fetch
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github
$ claude mcp add slack -e SLACK_BOT_<redacted> -- npx -y @modelcontextprotocol/server-slack
$ claude mcp add --transport http acme-erp https://mcp.acme-erp.example/v1 -H 'Authorization: YOUR_VALUE'
$ claude mcp add --transport http acme-crm https://mcp.acme.example/crm
$ npx degit kunko-ai-labs/agent-assurance/examples/repos/claude-code-approval-broken/.claude ./rig-agent-assurance  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add postgres -- npx -y @modelcontextprotocol/server-postgres postgresql://localhost/analytics
$ claude mcp add fetch -- uvx mcp-server-fetch
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github
$ claude mcp add slack -e SLACK_BOT_<redacted> -- npx -y @modelcontextprotocol/server-slack
$ claude mcp add --transport http acme-erp https://mcp.acme-erp.example/v1 -H 'Authorization: YOUR_VALUE'
$ claude mcp add --transport http acme-crm https://mcp.acme.example/crm

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "WebFetch",
      "Bash(rm -rf *)"
    ],
    "ask": [
      "Edit",
      "Write",
      "Bash(npm test)"
    ]
  }
}

MCP servers (6)

serversourceest. tokens
Postgres npm 600
Fetch pypi 450
GitHub MCP · "github"
env: GITHUB_PERSONAL_ACCESS_TOKEN
npm 18.0k
Slack
env: SLACK_BOT_TOKEN
npm 3.5k
mcp.acme-erp.example · "acme-erp" remote · remote 2.5k
mcp.acme.example · "acme-crm" remote · remote 2.5k

Permissions

deny (2)
WebFetch
Bash(rm -rf *)
ask (3)
Edit
Write
Bash(npm test)
allow (8)
Read
Edit
Write
Bash(*)
mcp__github
Read
Glob
Grep

Similar rigs

copied ✓