~ / rigs / radozaprazny / attest

radozaprazny/attest

A Claude Code kit: a push guard that holds a push until a leak scan and one audit have cleared HEAD.

↗ GitHub ★ 0 MIT updated today project Claude Code
share on X
ARCHETYPE
Automator
Hooks on every lifecycle event: format, lint, notify, log.
CONTEXT TAX · EVERY TURN
~259 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit radozaprazny/attest/.claude ./rig-attest  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit radozaprazny/attest/.claude/skills/business .claude/skills/business
$ npx degit radozaprazny/attest/.claude/skills/checkpoint .claude/skills/checkpoint
$ npx degit radozaprazny/attest/.claude/skills/compliance .claude/skills/compliance
$ npx degit radozaprazny/attest/.claude/skills/decision .claude/skills/decision
$ npx degit radozaprazny/attest/.claude/skills/gate .claude/skills/gate
$ curl -fsSL --create-dirs -o .claude/agents/auditor.md https://raw.githubusercontent.com/radozaprazny/attest/main/.claude/agents/auditor.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|PowerShell",
        "hooks": [
          {
            "type": "command",
            "command": "sh \"${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/ship_guard.sh\""
          }
        ]
      },
      {
        "matcher": "mcp__github__(push_files|create_or_update_file|create_pull_request|create_repository)",
        "hooks": [
          {
            "type": "command",
            "command": "sh \"${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/ship_guard.sh\""
          }
        ]
      },
      {
        "matcher": "Write|Edit",
        "hooks": [
          {
            "type": "command",
            "command": "sh \"${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/record_guard.sh\""
          }
        ]
      }
    ]
  }
}

Skills (5)

Subagents (1)

auditor
model: inherit
>-

Hooks (4)

eventmatcherruns
SessionStart*sh "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/session_declaration.sh"
PreToolUseBash|PowerShellsh "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/ship_guard.sh"
PreToolUsemcp__github__(push_files|create_or_update_file|create_pull_request|create_repository)sh "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/ship_guard.sh"
PreToolUseWrite|Editsh "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/record_guard.sh"

Similar rigs

copied ✓