~ / rigs / nirecom / agents

nirecom/agents

Self-driving dev harness for Claude Code — hook-enforced workflow, two-AI-provider review loop, Windows-native PowerShell support (macOS and Linux too)

↗ GitHub ★ 3 mit updated 5d ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~3.9k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit nirecom/agents/agents ./rig-agents/agents
$ npx degit nirecom/agents/skills ./rig-agents/skills
$ npx degit nirecom/agents/hooks ./rig-agents/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit nirecom/agents/skills/aws-scan-apps .claude/skills/aws-scan-apps
$ npx degit nirecom/agents/skills/aws-scan-cost .claude/skills/aws-scan-cost
$ npx degit nirecom/agents/skills/aws-scan-resources .claude/skills/aws-scan-resources
$ npx degit nirecom/agents/skills/aws-scan-security .claude/skills/aws-scan-security
$ npx degit nirecom/agents/skills/aws-scan .claude/skills/aws-scan
$ npx degit nirecom/agents/skills/clarify-intent .claude/skills/clarify-intent
$ npx degit nirecom/agents/skills/commit-push .claude/skills/commit-push
$ npx degit nirecom/agents/skills/create-key .claude/skills/create-key
$ npx degit nirecom/agents/skills/deep-research .claude/skills/deep-research
$ npx degit nirecom/agents/skills/enforce-workflow-off .claude/skills/enforce-workflow-off
$ npx degit nirecom/agents/skills/enforce-workflow-on .claude/skills/enforce-workflow-on
$ npx degit nirecom/agents/skills/issue-close-finalize .claude/skills/issue-close-finalize
$ npx degit nirecom/agents/skills/issue-close-migrated .claude/skills/issue-close-migrated
$ npx degit nirecom/agents/skills/issue-close-stage .claude/skills/issue-close-stage
$ npx degit nirecom/agents/skills/issue-close-verified .claude/skills/issue-close-verified
$ npx degit nirecom/agents/skills/issue-create .claude/skills/issue-create
$ npx degit nirecom/agents/skills/issue-reconcile .claude/skills/issue-reconcile
$ npx degit nirecom/agents/skills/issue-setup .claude/skills/issue-setup
$ npx degit nirecom/agents/skills/make-detail-plan .claude/skills/make-detail-plan
$ npx degit nirecom/agents/skills/make-outline-plan .claude/skills/make-outline-plan
$ npx degit nirecom/agents/skills/migrate-repo .claude/skills/migrate-repo
$ npx degit nirecom/agents/skills/refactor-prompts .claude/skills/refactor-prompts
$ npx degit nirecom/agents/skills/resume-session .claude/skills/resume-session
$ npx degit nirecom/agents/skills/review-code-codex .claude/skills/review-code-codex
$ npx degit nirecom/agents/skills/review-code-security .claude/skills/review-code-security
$ npx degit nirecom/agents/skills/review-docs .claude/skills/review-docs
$ npx degit nirecom/agents/skills/review-plan-codex .claude/skills/review-plan-codex
$ npx degit nirecom/agents/skills/review-plan-security .claude/skills/review-plan-security
$ npx degit nirecom/agents/skills/review-tests .claude/skills/review-tests
$ npx degit nirecom/agents/skills/run-tests .claude/skills/run-tests
$ npx degit nirecom/agents/skills/save-research .claude/skills/save-research
$ npx degit nirecom/agents/skills/scan-offensive .claude/skills/scan-offensive
$ npx degit nirecom/agents/skills/session-close .claude/skills/session-close
$ npx degit nirecom/agents/skills/supervisor-report .claude/skills/supervisor-report
$ npx degit nirecom/agents/skills/survey-code .claude/skills/survey-code
$ npx degit nirecom/agents/skills/survey-history .claude/skills/survey-history
$ npx degit nirecom/agents/skills/sweep-branches .claude/skills/sweep-branches
$ npx degit nirecom/agents/skills/sweep-issues .claude/skills/sweep-issues
$ npx degit nirecom/agents/skills/sweep-plans .claude/skills/sweep-plans
$ npx degit nirecom/agents/skills/sweep-shell-snapshots .claude/skills/sweep-shell-snapshots
$ curl -fsSL --create-dirs -o .claude/agents/complexity-judge.md https://raw.githubusercontent.com/nirecom/agents/main/agents/complexity-judge.md
$ curl -fsSL --create-dirs -o .claude/agents/detail-planner.md https://raw.githubusercontent.com/nirecom/agents/main/agents/detail-planner.md
$ curl -fsSL --create-dirs -o .claude/agents/procedure.md https://raw.githubusercontent.com/nirecom/agents/main/agents/detail-planner/procedure.md
$ curl -fsSL --create-dirs -o .claude/agents/supplementary-rules.md https://raw.githubusercontent.com/nirecom/agents/main/agents/detail-planner/supplementary-rules.md
$ curl -fsSL --create-dirs -o .claude/agents/detail-reviewer.md https://raw.githubusercontent.com/nirecom/agents/main/agents/detail-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/concern-identifiers.md https://raw.githubusercontent.com/nirecom/agents/main/agents/detail-reviewer/concern-identifiers.md
$ curl -fsSL --create-dirs -o .claude/agents/issue-create-survey-worker.md https://raw.githubusercontent.com/nirecom/agents/main/agents/issue-create-survey-worker.md
$ curl -fsSL --create-dirs -o .claude/agents/codegraph-usage.md https://raw.githubusercontent.com/nirecom/agents/main/agents/lib/codegraph-usage.md
$ curl -fsSL --create-dirs -o .claude/agents/nfr-severity-calibration.md https://raw.githubusercontent.com/nirecom/agents/main/agents/lib/nfr-severity-calibration.md
$ curl -fsSL --create-dirs -o .claude/agents/planner-review-loop-protocol.md https://raw.githubusercontent.com/nirecom/agents/main/agents/lib/planner-review-loop-protocol.md
$ curl -fsSL --create-dirs -o .claude/agents/triage-legacy-compat.md https://raw.githubusercontent.com/nirecom/agents/main/agents/lib/triage-legacy-compat.md
$ curl -fsSL --create-dirs -o .claude/agents/outline-planner.md https://raw.githubusercontent.com/nirecom/agents/main/agents/outline-planner.md
$ curl -fsSL --create-dirs -o .claude/agents/output-format.md https://raw.githubusercontent.com/nirecom/agents/main/agents/outline-planner/output-format.md
$ curl -fsSL --create-dirs -o .claude/agents/outline-reviewer.md https://raw.githubusercontent.com/nirecom/agents/main/agents/outline-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/concern-identifiers.md https://raw.githubusercontent.com/nirecom/agents/main/agents/outline-reviewer/concern-identifiers.md
$ curl -fsSL --create-dirs -o .claude/agents/plan-security-reviewer.md https://raw.githubusercontent.com/nirecom/agents/main/agents/plan-security-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/refactor-prompts-judge.md https://raw.githubusercontent.com/nirecom/agents/main/agents/refactor-prompts-judge.md
$ curl -fsSL --create-dirs -o .claude/agents/security-scanner.md https://raw.githubusercontent.com/nirecom/agents/main/agents/security-scanner.md
$ curl -fsSL --create-dirs -o .claude/agents/skip-verifier.md https://raw.githubusercontent.com/nirecom/agents/main/agents/skip-verifier.md
$ curl -fsSL --create-dirs -o .claude/agents/supervisor-audit.md https://raw.githubusercontent.com/nirecom/agents/main/agents/supervisor-audit.md
$ curl -fsSL --create-dirs -o .claude/agents/supervisor.md https://raw.githubusercontent.com/nirecom/agents/main/agents/supervisor.md
$ curl -fsSL --create-dirs -o .claude/agents/survey-code.md https://raw.githubusercontent.com/nirecom/agents/main/agents/survey-code.md
$ curl -fsSL --create-dirs -o .claude/agents/survey-history.md https://raw.githubusercontent.com/nirecom/agents/main/agents/survey-history.md
$ curl -fsSL --create-dirs -o .claude/agents/test-reviewer.md https://raw.githubusercontent.com/nirecom/agents/main/agents/test-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/web-researcher.md https://raw.githubusercontent.com/nirecom/agents/main/agents/web-researcher.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(echo \"<<WORKFLOW_MARK_STEP_user_verification*>>\")",
      "Bash(*Remove-Item*-Recurse*-Force*)",
      "Bash(*Remove-Item*-Force*-Recurse*)",
      "Bash(*rm -rf *)",
      "Bash(*rm -fr *)",
      "Bash(*find *-exec *)",
      "Bash(*find *-execdir *)",
      "Bash(*find *-ok *)",
      "Bash(*find *-okdir *)",
      "Bash(*find *-delete*)",
      "Bash(*find *-fprint*)",
      "Bash(*find *-fls*)",
      "Bash(*sudo *)",
      "Bash(*mkfs *)",
      "Bash(dd *)",
      "Bash(*&& dd *)",
      "Bash(*; dd *)",
      "Bash(*| dd *)",
      "Bash(git push --force)",
      "Bash(git -C * push --force)",
      "Bash(git -c * push --force)",
      "Bash(git --no-pager push --force)",
      "Bash(git push --force *)",
      "Bash(git -C * push --force *)",
      "Bash(git -c * push --force *)",
      "Bash(git --no-pager push --force *)",
      "Bash(git push *--force)",
      "Bash(git -C * push *--force)",
      "Bash(git -c * push *--force)",
      "Bash(git --no-pager push *--force)",
      "Bash(git push *--force *)",
      "Bash(git -C * push *--force *)",
      "Bash(git -c * push *--force *)",
      "Bash(git --no-pager push *--force *)",
      "Bash(git push -f*)",
      "Bash(git -C * push -f*)",
      "Bash(git -c * push -f*)",
      "Bash(git --no-pager push -f*)",
      "Bash(git push *-f)",
      "Bash(git -C * push *-f)",
      "Bash(git -c * push *-f)",
      "Bash(git --no-pager push *-f)",
      "Bash(git push *-f *)",
      "Bash(git -C * push *-f *)",
      "Bash(git -c * push *-f *)",
      "Bash(git --no-pager push *-f *)",
      "Bash(git push *-f*)",
      "Bash(git -C * push *-f*)",
      "Bash(git -c * push *-f*)",
      "Bash(git --no-pager push *-f*)",
      "Bash(git push --mirror*)",
      "Bash(git -C * push --mirror*)",
      "Bash(git -c * push --mirror*)",
      "Bash(git --no-pager push --mirror*)",
      "Bash(git push *--mirror*)",
      "Bash(git -C * push *--mirror*)",
      "Bash(git -c * push *--mirror*)",
      "Bash(git --no-pager push *--mirror*)",
      "Bash(git push --delete*)",
      "Bash(git -C * push --delete*)",
      "Bash(git -c * push --delete*)",
      "Bash(git --no-pager push --delete*)",
      "Bash(git push *--delete*)",
      "Bash(git -C * push *--delete*)",
      "Bash(git -c * push *--delete*)",
      "Bash(git --no-pager push *--delete*)",
      "Bash(git push *+*)",
      "Bash(git -C * push *+*)",
      "Bash(git -c * push *+*)",
      "Bash(git --no-pager push *+*)",
      "Bash(git commit --amend*)",
      "Bash(git -C * commit --amend*)",
      "Bash(git -c * commit --amend*)",
      "Bash(git --no-pager commit --amend*)",
      "Bash(git commit *--amend*)",
      "Bash(git -C * commit *--amend*)",
      "Bash(git -c * commit *--amend*)",
      "Bash(git --no-pager commit *--amend*)",
      "Bash(git *--no-verify*)",
      "Bash(git -C * *--no-verify*)"
    ],
    "ask": [
      "Bash(echo \"<<WORKFLOW_USER_VERIFIED: *>>\")",
      "Bash(echo \"<<WORKFLOW_CLARIFY_INTENT_NOT_NEEDED: *>>\")",
      "Bash(echo \"<<WORKFLOW_WRITE_TESTS_NOT_NEEDED: *>>\")",
      "Bash(echo \"<<WORKFLOW_REVIEW_SECURITY_NOT_NEEDED: *>>\")",
      "Bash(echo \"<<WORKFLOW_RESET_FROM_*: *>>\")",
      "Bash(echo \"<<WORKFLOW_ENFORCE_WORKTREE_OFF: *>>\")",
      "Bash(echo \"<<WORKFLOW_ENFORCE_WORKFLOW_OFF: *>>\")",
      "Bash(echo \"<<WORKFLOW_ENFORCE_WORKTREE_OFF_EMERGENCY: *>>\")",
      "Bash(echo \"<<WORKFLOW_ENFORCE_WORKFLOW_OFF_EMERGENCY: *>>\")",
      "Bash(echo \"<<WORKFLOW_ISSUE_CLOSE_VERIFIED: *>>\")",
      "Bash(echo \"<<WORKFLOW_CONFIRM_INTENT: *>>\")",
      "Bash(echo \"<<WORKFLOW_CONFIRM_OUTLINE: *>>\")",
      "Bash(echo \"<<WORKFLOW_CONFIRM_DETAIL: *>>\")",
      "Bash(uv run bin/doc-rotate.py *)",
      "Bash(*aws * create*)",
      "Bash(*aws * put*)",
      "Bash(*aws * update*)",
      "Bash(*aws * set*)",
      "Bash(*aws * attach*)",
      "Bash(*aws * associate*)",
      "Bash(*aws * enable*)",
      "Bash(*aws * run*)",
      "Bash(*aws * start*)",
      "Bash(*aws * stop*)",
      "Bash(*aws * reboot*)",
      "Bash(*aws * restore*)",
      "Bash(*aws sts*)",
      "Bash(*aws configure*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|runInTerminal|runCommands",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/scan-outbound.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/enforce-issue-close.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/confirm-forge-target-ownership.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/enforce-system-ops.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-subagent-sentinels.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/gate-plan-skip-sentinel.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/check-cross-platform.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-capture-echo.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/check-japanese-in-docs.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-history-direct.js\""
          }
        ]
      },
      {
        "matcher": "Bash|Read|Grep|Glob|Edit|Write|MultiEdit|editFiles|runInTerminal|runCommands|mcp__codegraph__codegraph_explore",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-dotenv.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-credentials.js\""
          }
        ]
      },
      {
        "matcher": "Edit|Write|MultiEdit|editFiles",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-history-direct.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-shell-config.js\""
          }
        ]
      },
      {
        "matcher": "Edit|Write|MultiEdit|editFiles|Bash|runInTerminal|runCommands",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-memory-direct.js\""
          }
        ]
      },
      {
        "matcher": "Edit|Write|MultiEdit|editFiles|NotebookEdit|Bash|runInTerminal|runCommands|PowerShell",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/block-clearance-token-write.js\""
          }
        ]
      },
      {
        "matcher": "Edit|Write|MultiEdit|editFiles|NotebookEdit|Bash|runInTerminal|runCommands",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/enforce-worktree.js\""
          }
        ]
      },
      {
        "matcher": "Bash|Edit|Write|MultiEdit|editFiles|NotebookEdit|runInTerminal|runCommands",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/workflow-gate.js\""
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/bash-guard.js\""
          },
          {
            "type": "command",
            "command": "node \"$AGENTS_CONFIG_DIR/hooks/rtk-rewrite.js\""
          }
        ]
      }
    ]
  }
}

Skills (51)

Subagents (25)

complexity-judge
model: opus
Dedicated opus-fixed subagent for judging task complexity signals. Called by skills when no persisted evaluation exists. Returns exactly one SIGNALS: line.
detail-planner
model: sonnet
Drafts and revises implementation plans. Used by the make-detail-plan skill in a planner/reviewer discussion loop.
procedure—
supplementary-rules—
detail-reviewer
model: opus
CC fallback implementation-plan reviewer for make-detail-plan; invoked when codex CLI is unusable. Thorough — surfaces minor issues as well as major ones.
concern-identifiers—
issue-create-survey-worker
model: sonnet
3-pass GitHub issue dedupe survey. Classifies verdict (none/reopen/sub-of/make-parent/sibling) and writes a JSON artifact. Read-only — no issue creation, no comments.
codegraph-usage—
nfr-severity-calibration—
planner-review-loop-protocol—
triage-legacy-compat—
outline-planner
model: opus
Proposes 2-3 mutually-exclusive high-level approaches for a task. Used by the make-outline-plan skill. Inspired by Aider's architect/editor split and GitHub Spec Kit's /specify stage.
output-format—
outline-reviewer
model: opus
CC fallback approach reviewer for make-outline-plan; invoked when codex CLI is unusable. Checks direction and coverage only — never implementation details.
concern-identifiers—
plan-security-reviewer
model: opus
CC fallback security-plan reviewer for review-plan-security; invoked when codex CLI is unusable.
refactor-prompts-judge
model: sonnet
LLM judge for /refactor-prompts. Classifies hot regions from the lexical scan and emits an edit plan JSON.
security-scanner
model: opus
Scan code for security anti-patterns across three axes. Read-only, no web access. Used by review-code-security.
skip-verifier
model: sonnet
Verifies whether a speculative skip (outline or detail) is safe based on session intent and outline artifacts.
supervisor-audit
model: opus
EM Supervisor — audit mode review agent. Invoked by Stop-hook block at stage boundaries (CONFIRM_INTENT/OUTLINE/DETAIL) or when cumulative severity reaches the audit threshold. Reviews cross-stage coh
supervisor
model: sonnet
EM Supervisor — alert mode review agent. Invoked by Stop-hook block when a sentinel-hang, scheduled-review, or off-proposal condition is detected. Reviews the active session against JD checklist and w
survey-code
model: sonnet
Investigate the codebase to understand existing patterns, constraints, and relevant files. Writes a session-scoped survey-code.md artifact.
survey-history
model: sonnet
Investigate git history and GitHub issue/PR timeline since the relevant issue opened, to surface changes that may invalidate the issue's premises.
test-reviewer
model: opus
CC fallback test-coverage reviewer for review-tests; invoked when codex CLI is unusable.
web-researcher
model: sonnet
Research an external topic via WebSearch and WebFetch. Read-only. Used by deep-research.

Hooks (51)

eventmatcherruns
Notificationpermission_promptpowershell.exe -NoProfile -Command "[Windows.UI.Notifications.ToastNotificationManager, Windows.UI.Notifications, ContentType = WindowsRuntime] | Out-Null; [Windows.Data.Xml.Dom.XmlDocument, Windows.Data.Xml.Dom, ContentType = WindowsRuntim
Stop*node "$AGENTS_CONFIG_DIR/hooks/stop-confirm-plan-guard.js"
Stop*node "$AGENTS_CONFIG_DIR/hooks/stop-final-report-guard.js"
Stop*node "$AGENTS_CONFIG_DIR/hooks/stop-l2-findings-display.js"
Stop*node "$AGENTS_CONFIG_DIR/hooks/stop-premature-stop-guard.js"
Stop*node "$AGENTS_CONFIG_DIR/hooks/supervisor-guard.js"
Stop*node "$AGENTS_CONFIG_DIR/hooks/stop-enforce-worktree-on-warn.js"
Stop*node "$AGENTS_CONFIG_DIR/hooks/stop-exit-worktree-warn.js"
SessionStart*node "$AGENTS_CONFIG_DIR/hooks/session-start.js"
InstructionsLoaded*node "$AGENTS_CONFIG_DIR/hooks/instructions-loaded-audit.js"
UserPromptSubmit*node "$AGENTS_CONFIG_DIR/hooks/post-push-workflow-reset.js"
UserPromptSubmit*node "$AGENTS_CONFIG_DIR/hooks/lang-inject.js"
UserPromptSubmit*node "$AGENTS_CONFIG_DIR/hooks/record-off-skill-invocation.js"
UserPromptSubmit*node "$AGENTS_CONFIG_DIR/hooks/user-prompt-submit-mechanism-check.js"
UserPromptSubmit*node "$AGENTS_CONFIG_DIR/hooks/handoff-pressure-nudge.js"
UserPromptSubmit*node "$AGENTS_CONFIG_DIR/hooks/codegraph-context-inject.js"
PostCompact*node "$AGENTS_CONFIG_DIR/hooks/post-compact.js"
SubagentStart*node "$AGENTS_CONFIG_DIR/hooks/subagent-start.js"
PreToolUseBash|runInTerminal|runCommandsnode "$AGENTS_CONFIG_DIR/hooks/scan-outbound.js"
PreToolUseBash|Read|Grep|Glob|Edit|Write|MultiEdit|editFiles|runInTerminal|runCommands|mcp__codegraph__codegraph_explorenode "$AGENTS_CONFIG_DIR/hooks/block-dotenv.js"
PreToolUseBash|Read|Grep|Glob|Edit|Write|MultiEdit|editFiles|runInTerminal|runCommands|mcp__codegraph__codegraph_explorenode "$AGENTS_CONFIG_DIR/hooks/block-credentials.js"
PreToolUseEdit|Write|MultiEdit|editFilesnode "$AGENTS_CONFIG_DIR/hooks/block-history-direct.js"
PreToolUseEdit|Write|MultiEdit|editFilesnode "$AGENTS_CONFIG_DIR/hooks/block-shell-config.js"
PreToolUseEdit|Write|MultiEdit|editFiles|Bash|runInTerminal|runCommandsnode "$AGENTS_CONFIG_DIR/hooks/block-memory-direct.js"
PreToolUseEdit|Write|MultiEdit|editFiles|NotebookEdit|Bash|runInTerminal|runCommands|PowerShellnode "$AGENTS_CONFIG_DIR/hooks/block-clearance-token-write.js"
PreToolUseEdit|Write|MultiEdit|editFiles|NotebookEdit|Bash|runInTerminal|runCommandsnode "$AGENTS_CONFIG_DIR/hooks/enforce-worktree.js"
PreToolUseBash|runInTerminal|runCommandsnode "$AGENTS_CONFIG_DIR/hooks/enforce-issue-close.js"
PreToolUseBash|runInTerminal|runCommandsnode "$AGENTS_CONFIG_DIR/hooks/confirm-forge-target-ownership.js"
PreToolUseBash|runInTerminal|runCommandsnode "$AGENTS_CONFIG_DIR/hooks/enforce-system-ops.js"
PreToolUseBash|runInTerminal|runCommandsnode "$AGENTS_CONFIG_DIR/hooks/block-subagent-sentinels.js"

Permissions

deny (120)
Bash(echo "<<WORKFLOW_MARK_STEP_user_verification*>>")
Bash(*Remove-Item*-Recurse*-Force*)
Bash(*Remove-Item*-Force*-Recurse*)
Bash(*rm -rf *)
Bash(*rm -fr *)
Bash(*find *-exec *)
Bash(*find *-execdir *)
Bash(*find *-ok *)
Bash(*find *-okdir *)
Bash(*find *-delete*)
Bash(*find *-fprint*)
Bash(*find *-fls*)
Bash(*sudo *)
Bash(*mkfs *)
Bash(dd *)
Bash(*&& dd *)
Bash(*; dd *)
Bash(*| dd *)
Bash(git push --force)
Bash(git -C * push --force)
Bash(git -c * push --force)
Bash(git --no-pager push --force)
Bash(git push --force *)
Bash(git -C * push --force *)
Bash(git -c * push --force *)
Bash(git --no-pager push --force *)
Bash(git push *--force)
Bash(git -C * push *--force)
Bash(git -c * push *--force)
Bash(git --no-pager push *--force)
Bash(git push *--force *)
Bash(git -C * push *--force *)
Bash(git -c * push *--force *)
Bash(git --no-pager push *--force *)
Bash(git push -f*)
Bash(git -C * push -f*)
Bash(git -c * push -f*)
Bash(git --no-pager push -f*)
Bash(git push *-f)
Bash(git -C * push *-f)
Bash(git -c * push *-f)
Bash(git --no-pager push *-f)
Bash(git push *-f *)
Bash(git -C * push *-f *)
Bash(git -c * push *-f *)
Bash(git --no-pager push *-f *)
Bash(git push *-f*)
Bash(git -C * push *-f*)
Bash(git -c * push *-f*)
Bash(git --no-pager push *-f*)
Bash(git push --mirror*)
Bash(git -C * push --mirror*)
Bash(git -c * push --mirror*)
Bash(git --no-pager push --mirror*)
Bash(git push *--mirror*)
Bash(git -C * push *--mirror*)
Bash(git -c * push *--mirror*)
Bash(git --no-pager push *--mirror*)
Bash(git push --delete*)
Bash(git -C * push --delete*)
ask (28)
Bash(echo "<<WORKFLOW_USER_VERIFIED: *>>")
Bash(echo "<<WORKFLOW_CLARIFY_INTENT_NOT_NEEDED: *>>")
Bash(echo "<<WORKFLOW_WRITE_TESTS_NOT_NEEDED: *>>")
Bash(echo "<<WORKFLOW_REVIEW_SECURITY_NOT_NEEDED: *>>")
Bash(echo "<<WORKFLOW_RESET_FROM_*: *>>")
Bash(echo "<<WORKFLOW_ENFORCE_WORKTREE_OFF: *>>")
Bash(echo "<<WORKFLOW_ENFORCE_WORKFLOW_OFF: *>>")
Bash(echo "<<WORKFLOW_ENFORCE_WORKTREE_OFF_EMERGENCY: *>>")
Bash(echo "<<WORKFLOW_ENFORCE_WORKFLOW_OFF_EMERGENCY: *>>")
Bash(echo "<<WORKFLOW_ISSUE_CLOSE_VERIFIED: *>>")
Bash(echo "<<WORKFLOW_CONFIRM_INTENT: *>>")
Bash(echo "<<WORKFLOW_CONFIRM_OUTLINE: *>>")
Bash(echo "<<WORKFLOW_CONFIRM_DETAIL: *>>")
Bash(uv run bin/doc-rotate.py *)
Bash(*aws * create*)
Bash(*aws * put*)
Bash(*aws * update*)
Bash(*aws * set*)
Bash(*aws * attach*)
Bash(*aws * associate*)
Bash(*aws * enable*)
Bash(*aws * run*)
Bash(*aws * start*)
Bash(*aws * stop*)
Bash(*aws * reboot*)
Bash(*aws * restore*)
Bash(*aws sts*)
Bash(*aws configure*)
allow (67)
Read(**/.env.example)
Read(**/.env.sample)
Read(**/.env.template)
Read(**/.env.dist)
Grep(**/.env.example)
Grep(**/.env.sample)
Grep(**/.env.template)
Grep(**/.env.dist)
Bash(git add .)
Bash(git add -A)
Bash(git add *)
Bash(git -C * add *)
Bash(git push)
Bash(git push origin *)
Bash(git -C * push)
Bash(git -C * push origin *)
Bash(git -C * push -u origin *)
Bash(git push -u origin *)
Bash(git push *--force-with-lease*)
Bash(git -C * push *--force-with-lease*)
Bash(git fetch origin *)
Bash(git -C * fetch origin *)
Bash(git fetch --prune origin)
Bash(git -C * fetch --prune origin)
Bash(git pull --rebase --autostash origin *)
Bash(git -C * pull --rebase --autostash origin *)
Write(**/.git/info/pending-branch-delete)
Bash(Remove-Item -LiteralPath "**\.git\info\pending-branch-delete")
Bash(rm "**/.git/info/pending-branch-delete")
Bash(git commit *)
Bash(git -C * commit *)
Bash(cd * && git commit *)
Bash(chmod +x *.sh)
Bash(chmod +x */hooks/*)
Bash(echo "<<WORKFLOW_MARK_STEP_*>>")
Bash(echo '<<WORKFLOW_MARK_STEP_*>>')
Bash(echo "<<WORKFLOW_RESEARCH_NOT_NEEDED: *>>")
Bash(echo "<<WORKFLOW_OUTLINE_NOT_NEEDED: *>>")
Bash(echo "<<WORKFLOW_DETAIL_NOT_NEEDED: *>>")
Bash(echo "<<WORKFLOW_RUN_TESTS_NOT_NEEDED: *>>")
Bash(echo "<<WORKFLOW_ENFORCE_WORKTREE_ON: *>>")
Bash(echo "<<WORKFLOW_ENFORCE_WORKFLOW_ON: *>>")
Bash(echo "<<WORKFLOW_NEXT_STEP_PAUSE: *>>")
Bash(echo "<<WORKFLOW_NEXT_STEP_RESUME: *>>")
Bash(echo "<<WORKFLOW_ISSUE_CLOSE_VERIFIED_END: *>>")
Bash(doc-append *)
Write(**/tests/**)
Edit(**/tests/**)
WebSearch
WebFetch(domain:developer.mozilla.org)
WebFetch(domain:docs.python.org)
WebFetch(domain:learn.microsoft.com)
WebFetch(domain:man7.org)
WebFetch(domain:docs.anthropic.com)
WebFetch(domain:platform.openai.com)
WebFetch(domain:ai.google.dev)
WebFetch(domain:docs.github.com)
WebFetch(domain:github.com)
WebFetch(domain:code.claude.com)
WebFetch(domain:platform.claude.com)

Similar rigs

copied ✓