~ / rigs / niksavis / basicly

niksavis/basicly

A harness that ships a development process to coding agents and enforces it. One YAML catalog projects instructions, skills, subagents and permissions to Claude, Codex and Copilot. Git hooks refuse bad work at commit time. A loop drives eac

↗ GitHub ★ 0 MIT updated today project Claude CodeCodexCopilot
share on X
ARCHETYPE
YOLO Cowboy
Permissions? Never heard of 'em. Ships at the speed of `--dangerously-skip-permissions`.
CONTEXT TAX · EVERY TURN
~5.5k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · details

Copy this rig

# review before running: this installs third-party code
$ npx degit niksavis/basicly/.claude ./rig-basicly  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit niksavis/basicly/.agents/skills/best-practices-audit .claude/skills/best-practices-audit
$ npx degit niksavis/basicly/.agents/skills/catalog-authoring .claude/skills/catalog-authoring
$ npx degit niksavis/basicly/.agents/skills/cli-tools .claude/skills/cli-tools
$ npx degit niksavis/basicly/.agents/skills/conventional-commits .claude/skills/conventional-commits
$ npx degit niksavis/basicly/.agents/skills/decompose-plan .claude/skills/decompose-plan
$ npx degit niksavis/basicly/.agents/skills/falsify-first .claude/skills/falsify-first
$ npx degit niksavis/basicly/.agents/skills/find-skills .claude/skills/find-skills
$ npx degit niksavis/basicly/.agents/skills/harness-client .claude/skills/harness-client
$ npx degit niksavis/basicly/.agents/skills/harness-loop .claude/skills/harness-loop
$ npx degit niksavis/basicly/.agents/skills/interface-facts .claude/skills/interface-facts
$ npx degit niksavis/basicly/.agents/skills/no-comments .claude/skills/no-comments
$ npx degit niksavis/basicly/.agents/skills/node .claude/skills/node
$ npx degit niksavis/basicly/.agents/skills/plain-english .claude/skills/plain-english
$ npx degit niksavis/basicly/.agents/skills/python .claude/skills/python
$ npx degit niksavis/basicly/.agents/skills/release-process .claude/skills/release-process
$ npx degit niksavis/basicly/.agents/skills/repair-in-place .claude/skills/repair-in-place
$ npx degit niksavis/basicly/.agents/skills/retention-probe .claude/skills/retention-probe
$ npx degit niksavis/basicly/.agents/skills/root-cause .claude/skills/root-cause
$ npx degit niksavis/basicly/.agents/skills/session-finish .claude/skills/session-finish
$ npx degit niksavis/basicly/.agents/skills/skill-creator .claude/skills/skill-creator
$ npx degit niksavis/basicly/.agents/skills/test-discipline .claude/skills/test-discipline
$ npx degit niksavis/basicly/.agents/skills/tier-injection .claude/skills/tier-injection
$ npx degit niksavis/basicly/.agents/skills/validate-as-consumer .claude/skills/validate-as-consumer
$ npx degit niksavis/basicly/.agents/skills/work-tracker .claude/skills/work-tracker
$ npx degit niksavis/basicly/.agents/skills/worktree-isolation .claude/skills/worktree-isolation
$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/architect.md
$ curl -fsSL --create-dirs -o .claude/agents/auditor.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/auditor.md
$ curl -fsSL --create-dirs -o .claude/agents/curator.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/curator.md
$ curl -fsSL --create-dirs -o .claude/agents/decider.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/decider.md
$ curl -fsSL --create-dirs -o .claude/agents/decomposer.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/decomposer.md
$ curl -fsSL --create-dirs -o .claude/agents/implementer.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/implementer.md
$ curl -fsSL --create-dirs -o .claude/agents/researcher.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/researcher.md
$ curl -fsSL --create-dirs -o .claude/agents/retrospector.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/retrospector.md
$ curl -fsSL --create-dirs -o .claude/agents/reviewer.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/tester.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/tester.md
$ curl -fsSL --create-dirs -o .claude/agents/validator.md https://raw.githubusercontent.com/niksavis/basicly/main/.claude/agents/validator.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf*)",
      "Bash(rm -fr*)",
      "Bash(rm -r -f*)",
      "Bash(rm -f -r*)",
      "Bash(git push --force*)",
      "Bash(git push --force-with-lease*)",
      "Bash(git push -f*)",
      "Bash(git push*--force*)",
      "Bash(git push*--no-verify*)",
      "Bash(git push*--no-gpg-sign*)",
      "Bash(git commit*--no-verify*)",
      "Bash(git commit*--no-gpg-sign*)",
      "Bash(git reset --hard*)",
      "Bash(git clean*-f*)",
      "Bash(git filter-branch*)",
      "Bash(git filter-repo*)",
      "Read(.env)",
      "Read(.env.*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/.env.local)",
      "Edit(.env)",
      "Edit(.env.*)",
      "Edit(**/.env)",
      "Edit(**/.env.*)",
      "Bash(git *push*--no-verify*)",
      "Bash(git *push*--no-gpg-sign*)",
      "Bash(git *commit*--no-verify*)",
      "Bash(git *commit*--no-gpg-sign*)",
      "Bash(git *-c core.hooksPath*)",
      "Bash(git *-c core.hookspath*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Edit|Write|NotebookEdit",
        "hooks": [
          {
            "type": "command",
            "command": "uv run --no-project --no-python-downloads python \"${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/protect-generated.py\""
          },
          {
            "type": "command",
            "command": "uv run --no-project --no-python-downloads python \"${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/headroom-guard.py\""
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "uv run --no-project --no-python-downloads python \"${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/unsplit-loop-guard.py\""
          },
          {
            "type": "command",
            "command": "uv run --no-project --no-python-downloads python \"${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/pipe-status-guard.py\""
          },
          {
            "type": "command",
            "command": "uv run --no-project --no-python-downloads python \"${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/bare-var-guard.py\""
          },
          {
            "type": "command",
            "command": "uv run --no-project --no-python-downloads python \"${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/rg-replace-guard.py\""
          }
        ]
      },
      {
        "matcher": "Agent",
        "hooks": [
          {
            "type": "command",
            "command": "uv run --no-project --no-python-downloads python \"${CLAUDE_PROJECT_DIR}/.basicly/core/kit/tier/claude_tier_hook.py\""
          }
        ]
      }
    ]
  }
}

Skills (25)

Subagents (11)

architectSurveys a whole codebase for structural decay and returns a remediation backlog ordered by dependency. Use at a release boundary, or when a measure that no ratchet sees has moved, such as module count
auditorAudits a diff or a component for security weaknesses at trust boundaries. Use before you ship a change that touches input handling, credentials, subprocess calls or network calls. Returns severity-rat
curatorBinds every claim that a release makes to the evidence for it, and refuses each claim that has none. Invoked by the engine at SHIP, once verify and validate are green. Returns a `release-record` in wh
deciderAssigns an integrity level and a loop depth to a classified unit, and disposes the escalations that the engine routes to it. Invoked by the engine at CLASSIFY for L2 and above, and when an escalation
decomposerCuts a classified unit of work into children that can each be built, verified and demonstrated end to end. Invoked by the engine at DECOMPOSE, once `classification` and `change-shape` validate and the
implementerBuilds one planned child to green, and in repair mode fixes the named defect in the same worktree without a new plan. Invoked by the engine at BUILD when the plan gate is green and downstream work in
researcherEstablishes a fact about an external interface or a claimed best practice from primary sources, not from recall. Use before you write code, a design note, a rule or a claim that depends on how a third
retrospectorFinds why a special-cause failure happened and names the control that would have refused it. Invoked when the gate-failure ledger fires a special-cause signal, which is a point beyond three sigma, or
reviewerReviews a change along one named lens and reports findings on that lens only. Invoked by the engine at VALIDATE once per lens beside the validator, and by a person on any diff or component. Name the l
testerRuns the repository's documented test suite or a named subset and reports the outcome. Use after a code change when you need a pass or fail verdict without reading raw test output. Returns the counts
validatorRuns a verified change the way a consumer would, in the operational environment, against the requirement that asked for it. Invoked by the engine at VALIDATE, once `verification-evidence` is green. Re

Hooks (9)

eventmatcherruns
PreToolUseEdit|Write|NotebookEdituv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/protect-generated.py"
PreToolUseBashuv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/unsplit-loop-guard.py"
PreToolUseBashuv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/pipe-status-guard.py"
PreToolUseBashuv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/bare-var-guard.py"
PreToolUseBashuv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/rg-replace-guard.py"
PreToolUseEdit|Write|NotebookEdituv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/headroom-guard.py"
PreToolUseAgentuv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/kit/tier/claude_tier_hook.py"
PostToolUseBash|Skilluv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/tool-usage.py"
SessionStart*uv run --no-project --no-python-downloads python "${CLAUDE_PROJECT_DIR}/.basicly/core/hooks/session-start.py"

Permissions

deny (31)
Bash(rm -rf*)
Bash(rm -fr*)
Bash(rm -r -f*)
Bash(rm -f -r*)
Bash(git push --force*)
Bash(git push --force-with-lease*)
Bash(git push -f*)
Bash(git push*--force*)
Bash(git push*--no-verify*)
Bash(git push*--no-gpg-sign*)
Bash(git commit*--no-verify*)
Bash(git commit*--no-gpg-sign*)
Bash(git reset --hard*)
Bash(git clean*-f*)
Bash(git filter-branch*)
Bash(git filter-repo*)
Read(.env)
Read(.env.*)
Read(**/.env)
Read(**/.env.*)
Read(**/.env.local)
Edit(.env)
Edit(.env.*)
Edit(**/.env)
Edit(**/.env.*)
Bash(git *push*--no-verify*)
Bash(git *push*--no-gpg-sign*)
Bash(git *commit*--no-verify*)
Bash(git *commit*--no-gpg-sign*)
Bash(git *-c core.hooksPath*)
Bash(git *-c core.hookspath*)
ask (0)
—
allow (30)
Bash
Edit
Write
Read
Glob
Grep
WebSearch
WebFetch
Bash(git status *)
Bash(git rev-parse *)
Bash(git ls-files *)
Bash(git worktree list *)
Bash(git branch)
Bash(git branch --show-current)
Bash(basicly status *)
Bash(basicly tracker show *)
Bash(basicly tracker list *)
Bash(basicly tracker ready *)
Bash(basicly tracker stats *)
Bash(basicly check)
Bash(basicly skills-check *)
Bash(basicly styles-check *)
Bash(basicly agents-check)
Bash(basicly hooks-check)
Bash(basicly permissions-check)
Bash(basicly catalog lint)
Bash(basicly verify)
Bash(basicly verify --mode fast)
Bash(basicly verify --mode full)
Bash(basicly verify --mode staged)

Similar rigs

copied ✓