~ / rigs / r3dlight / phantom

r3dlight/phantom

Forensic CLI for AI-era supply-chain attacks: XZ tarball diffs, prompt injection scans, MCP/CLAUDE.md/Cursor config audits. SARIF for GitHub Code Scanning.

↗ GitHub ★ 5 Apache-2.0 updated 2mo ago project Claude Code
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~7.7k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
2/5
Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit r3dlight/phantom/examples/aiconfig-trap/.claude ./rig-phantom  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "true"
          }
        ]
      }
    ]
  }
}

MCP servers (3)

serversourceest. tokens
fs-utils local / custom 2.5k
remote-helper local / custom 2.5k
mock local / custom 2.5k

Hooks (1)

eventmatcherruns
PreToolUseBashtrue

Similar rigs

copied ✓