plkarin/gitops-agentic-platform
Enterprise-grade agentic AI platform built on GitOps principles — immutable audit trails, FedRAMP-aligned compliance controls, and automated security pipelines for Claude Code deployments.
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
Copy this rig
# review before running: this installs third-party code
$ npx degit plkarin/gitops-agentic-platform/.claude ./rig-gitops-agentic-platform # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ curl -fsSL --create-dirs -o .claude/agents/backward-compatibility-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/backward-compatibility-check.md $ curl -fsSL --create-dirs -o .claude/agents/change-impact-assessment.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/change-impact-assessment.md $ curl -fsSL --create-dirs -o .claude/agents/runtime-risk-estimation.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/runtime-risk-estimation.md $ curl -fsSL --create-dirs -o .claude/agents/session-audit.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/audit/session-audit.md $ curl -fsSL --create-dirs -o .claude/agents/ansible-idempotency-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/ansible-idempotency-check.md $ curl -fsSL --create-dirs -o .claude/agents/bash-strict-mode-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/bash-strict-mode-check.md $ curl -fsSL --create-dirs -o .claude/agents/config-drift-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/config-drift-detection.md $ curl -fsSL --create-dirs -o .claude/agents/hardcoded-path-risk.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/hardcoded-path-risk.md $ curl -fsSL --create-dirs -o .claude/agents/repo-structure-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/infra/repo-structure-check.md $ curl -fsSL --create-dirs -o .claude/agents/invocation.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/invocation.md $ curl -fsSL --create-dirs -o .claude/agents/cli-ux-consistency.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/cli-ux-consistency.md $ curl -fsSL --create-dirs -o .claude/agents/complexity-hotspot-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/complexity-hotspot-detection.md $ curl -fsSL --create-dirs -o .claude/agents/dead-code-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/dead-code-detection.md $ curl -fsSL --create-dirs -o .claude/agents/docstring-quality.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/docstring-quality.md $ curl -fsSL --create-dirs -o .claude/agents/interface-contract-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/interface-contract-check.md $ curl -fsSL --create-dirs -o .claude/agents/layering-violation-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/layering-violation-check.md $ curl -fsSL --create-dirs -o .claude/agents/logging-consistency.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/logging-consistency.md $ curl -fsSL --create-dirs -o .claude/agents/refactor-safety-check.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/quality/refactor-safety-check.md $ curl -fsSL --create-dirs -o .claude/agents/dependency-vulnerability-audit.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/dependency-vulnerability-audit.md $ curl -fsSL --create-dirs -o .claude/agents/malware-scan.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/malware-scan.md $ curl -fsSL --create-dirs -o .claude/agents/privilege-escalation-risk.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/privilege-escalation-risk.md $ curl -fsSL --create-dirs -o .claude/agents/rootkit-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/rootkit-detection.md $ curl -fsSL --create-dirs -o .claude/agents/secrets-detection.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/secrets-detection.md $ curl -fsSL --create-dirs -o .claude/agents/supply-chain-risk.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/supply-chain-risk.md $ curl -fsSL --create-dirs -o .claude/agents/unsafe-tempfile-usage.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/unsafe-tempfile-usage.md $ curl -fsSL --create-dirs -o .claude/agents/vulnerability-scan.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/security/vulnerability-scan.md $ curl -fsSL --create-dirs -o .claude/agents/checkpoint.md https://raw.githubusercontent.com/plkarin/gitops-agentic-platform/main/.claude/agents/workflow/checkpoint.md
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Subagents (27)
| backward-compatibility-check model: claude-haiku-4-5-20251001 | > |
| change-impact-assessment model: claude-haiku-4-5-20251001 | > |
| runtime-risk-estimation model: claude-haiku-4-5-20251001 | > |
| session-audit model: claude-haiku-4-5-20251001 | > |
| ansible-idempotency-check model: claude-haiku-4-5-20251001 | > |
| bash-strict-mode-check model: claude-haiku-4-5-20251001 | > |
| config-drift-detection model: claude-haiku-4-5-20251001 | > |
| hardcoded-path-risk model: claude-haiku-4-5-20251001 | > |
| repo-structure-check model: claude-haiku-4-5-20251001 | > |
| invocation | — |
| cli-ux-consistency model: claude-haiku-4-5-20251001 | > |
| complexity-hotspot-detection model: claude-haiku-4-5-20251001 | > |
| dead-code-detection model: claude-haiku-4-5-20251001 | > |
| docstring-quality model: claude-haiku-4-5-20251001 | > |
| interface-contract-check model: claude-haiku-4-5-20251001 | > |
| layering-violation-check model: claude-haiku-4-5-20251001 | > |
| logging-consistency model: claude-haiku-4-5-20251001 | > |
| refactor-safety-check model: claude-haiku-4-5-20251001 | > |
| dependency-vulnerability-audit model: claude-haiku-4-5-20251001 | > |
| malware-scan model: claude-haiku-4-5-20251001 | > |
| privilege-escalation-risk model: claude-haiku-4-5-20251001 | > |
| rootkit-detection model: claude-haiku-4-5-20251001 | > |
| secrets-detection model: claude-haiku-4-5-20251001 | > |
| supply-chain-risk model: claude-haiku-4-5-20251001 | > |
| unsafe-tempfile-usage model: claude-haiku-4-5-20251001 | > |
| vulnerability-scan model: claude-haiku-4-5-20251001 | > |
| checkpoint model: claude-sonnet-4-6 | > |
Similar rigs
rtk-ai/rtk
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
Orchestrator 2.6k tok ·
Yeachan-Heo/oh-my-claudecode
Teams-first Multi-agent orchestration for Claude Code
Orchestrator 14.5k tok ·
alirezarezvani/claude-skills
380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8 more coding agents — engineering, marketing, product, complian
Orchestrator 48.5k tok ·
czlonkowski/n8n-mcp
A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you
Orchestrator 3.8k tok ·