~ / rigs / liatrio-labs / claude-code-gauntlet

liatrio-labs/claude-code-gauntlet

Adversarial code review for Claude Code: each GitHub PR or GitLab MR runs a gauntlet of up to seven specialist agents for bugs, security, tests and cross-file impact, and every finding must survive verification, a skeptical validator, and a

↗ GitHub ★ 12 Apache-2.0 updated today project Claude CodeCodex Claude plugin
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~1.6k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
1/5
No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit liatrio-labs/claude-code-gauntlet/.claude ./rig-claude-code-gauntlet  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit liatrio-labs/claude-code-gauntlet/.claude/skills/next-issue .claude/skills/next-issue
$ npx degit liatrio-labs/claude-code-gauntlet/skills/build-review-md .claude/skills/build-review-md
$ npx degit liatrio-labs/claude-code-gauntlet/skills/code-gauntlet .claude/skills/code-gauntlet
$ curl -fsSL --create-dirs -o .claude/agents/artifact-writer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/artifact-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/bug-detector.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/bug-detector.md
$ curl -fsSL --create-dirs -o .claude/agents/challenger.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/challenger.md
$ curl -fsSL --create-dirs -o .claude/agents/change-summarizer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/change-summarizer.md
$ curl -fsSL --create-dirs -o .claude/agents/code-simplifier.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/code-simplifier.md
$ curl -fsSL --create-dirs -o .claude/agents/conventions-and-intent.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/conventions-and-intent.md
$ curl -fsSL --create-dirs -o .claude/agents/cross-file-impact.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/cross-file-impact.md
$ curl -fsSL --create-dirs -o .claude/agents/executor.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/executor.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/security-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/test-analyzer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/test-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/type-design-analyzer.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/type-design-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/validator.md https://raw.githubusercontent.com/liatrio-labs/claude-code-gauntlet/main/agents/validator.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

Skills (3)

Subagents (12)

artifact-writer
model: sonnet
Persists code-gauntlet artifacts (findings JSON, report markdown, checkpoint JSON) to the output directory. Mechanical — writes exactly what it is given.
bug-detector
model: sonnet
Detects correctness bugs, logic errors, edge cases, API misuse, and error handling issues in code changes
challenger
model: sonnet
Blindly challenges a single review finding — attempts to disprove the claim using only the finding title, description, and file:line location, reading the code itself (no original reasoning or evidenc
change-summarizer
model: sonnet
Produces a concise semantic summary of PR/MR changes for shared context across all review agents
code-simplifier
model: sonnet
Simplifies complex code for clarity and maintainability while preserving functionality
conventions-and-intent
model: sonnet
Verifies code changes comply with project conventions, match documented intent, and maintain comment accuracy
cross-file-impact
model: sonnet
Analyzes how changes in one file affect consumers across the codebase, catching cross-file breakage from signature changes, interface violations, and broken references
executor
model: sonnet
Runs a single pinned command and returns its output — the receipt and delta fields for verify_findings.py, the whole stdout line verbatim for assemble_artifacts.py. No interpretation.
security-reviewer
model: opus
Reviews code changes for security vulnerabilities, focusing on OWASP top 10, auth issues, data exposure, and cryptographic problems
test-analyzer
model: sonnet
Analyzes test coverage quality and identifies critical gaps in the test suite relative to code changes
type-design-analyzer
model: sonnet
Analyzes type design for encapsulation quality, invariant expression, enforcement, and usefulness
validator
model: sonnet
Validates review findings by attempting to disprove them — assesses whether each finding is real, reachable, and correctly described

Hooks (1)

eventmatcherruns
SessionStart*python3 "$CLAUDE_PROJECT_DIR"/scripts/emit_style_context.py

Similar rigs

copied ✓