liatrio-labs/claude-code-gauntlet
Adversarial code review for Claude Code: each GitHub PR or GitLab MR runs a gauntlet of up to seven specialist agents for bugs, security, tests and cross-file impact, and every finding must survive verification, a skeptical validator, and a
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
Copy this rig
# review before running: this installs third-party code
$ npx degit liatrio-labs/claude-code-gauntlet/.claude ./rig-claude-code-gauntlet # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit liatrio-labs/claude-code-gauntlet/.claude/skills/next-issue .claude/skills/next-issue $ npx degit liatrio-labs/claude-code-gauntlet/skills/build-review-md .claude/skills/build-review-md $ npx degit liatrio-labs/claude-code-gauntlet/skills/code-gauntlet .claude/skills/code-gauntlet
$ curl -fsSL --create-dirs -o .claude/agents/artifact-writer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/artifact-writer.md $ curl -fsSL --create-dirs -o .claude/agents/bug-detector.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/bug-detector.md $ curl -fsSL --create-dirs -o .claude/agents/challenger.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/challenger.md $ curl -fsSL --create-dirs -o .claude/agents/change-summarizer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/change-summarizer.md $ curl -fsSL --create-dirs -o .claude/agents/code-simplifier.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/code-simplifier.md $ curl -fsSL --create-dirs -o .claude/agents/conventions-and-intent.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/conventions-and-intent.md $ curl -fsSL --create-dirs -o .claude/agents/cross-file-impact.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/cross-file-impact.md $ curl -fsSL --create-dirs -o .claude/agents/executor.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/executor.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/test-analyzer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/test-analyzer.md $ curl -fsSL --create-dirs -o .claude/agents/type-design-analyzer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/type-design-analyzer.md $ curl -fsSL --create-dirs -o .claude/agents/validator.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/validator.md
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (3)
Subagents (12)
| artifact-writer model: sonnet | Persists code-gauntlet artifacts (findings JSON, report markdown, checkpoint JSON) to the output directory. Mechanical — writes exactly what it is given. |
| bug-detector model: sonnet | Detects correctness bugs, logic errors, edge cases, API misuse, and error handling issues in code changes |
| challenger model: sonnet | Blindly challenges a single review finding — attempts to disprove the claim using only the finding title, description, and file:line location, reading the code itself (no original reasoning or evidenc |
| change-summarizer model: sonnet | Produces a concise semantic summary of PR/MR changes for shared context across all review agents |
| code-simplifier model: sonnet | Simplifies complex code for clarity and maintainability while preserving functionality |
| conventions-and-intent model: sonnet | Verifies code changes comply with project conventions, match documented intent, and maintain comment accuracy |
| cross-file-impact model: sonnet | Analyzes how changes in one file affect consumers across the codebase, catching cross-file breakage from signature changes, interface violations, and broken references |
| executor model: sonnet | Runs a single pinned command and returns its output — the receipt and delta fields for verify_findings.py, the whole stdout line verbatim for assemble_artifacts.py. No interpretation. |
| security-reviewer model: opus | Reviews code changes for security vulnerabilities, focusing on OWASP top 10, auth issues, data exposure, and cryptographic problems |
| test-analyzer model: sonnet | Analyzes test coverage quality and identifies critical gaps in the test suite relative to code changes |
| type-design-analyzer model: sonnet | Analyzes type design for encapsulation quality, invariant expression, enforcement, and usefulness |
| validator model: sonnet | Validates review findings by attempting to disprove them — assesses whether each finding is real, reachable, and correctly described |
Hooks (1)
| event | matcher | runs |
|---|---|---|
| SessionStart | * | python3 "$CLAUDE_PROJECT_DIR"/scripts/emit_style_context.py |
Similar rigs
Iski08/dotclaude
Multi-agent config for Claude Code with specialized agents and templates to speed code review, refactoring, security audits, tech-lead guidance, and UX evaluations across CI pipelines. 🐙
Orchestrator 677 tok ·
MiguelAxcar/ai-rpi-protocol
Repo-native protocol for AI-assisted coding that enforces a simple discipline: research first, plan second, code last. Drop it into any repository to reduce wrong implementations, cut rewrite cycles, and improve decisions earlier in the wor
Orchestrator 2.3k tok ·
RohiRIK/claude-code-config
Personal Claude Code global config — hooks, agents, skills, commands
YOLO Cowboy 2.8k tok ·
Seme4eg/dotfiles
My $HOME
Pragmatist 681 tok ·