ryo-ebata/cc-audit
AI-free static security scanner for Claude Code artifacts (Skills, Hooks, MCP configs). Detects data exfiltration, prompt injection, and supply chain risks with deterministic, reproducible results.
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ npx degit ryo-ebata/cc-audit/.claude ./rig-cc-audit # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit ryo-ebata/cc-audit/.claude/skills/cli-architecture .claude/skills/cli-architecture $ npx degit ryo-ebata/cc-audit/.claude/skills/rust-best-practices .claude/skills/rust-best-practices $ npx degit ryo-ebata/cc-audit/.claude/skills/tdd-coach .claude/skills/tdd-coach
$ curl -fsSL --create-dirs -o .claude/agents/dangerous-agent.md https://raw.githubusercontent.com/ryo-ebata/cc-audit/main/examples/subagent/.claude/agents/dangerous-agent.md $ curl -fsSL --create-dirs -o .claude/agents/safe-agent.md https://raw.githubusercontent.com/ryo-ebata/cc-audit/main/examples/subagent/.claude/agents/safe-agent.md
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} MCP servers (1)
| server | source | est. tokens |
|---|---|---|
| cc-audit | local / custom | 2.5k |
Skills (3)
Subagents (2)
| dangerous-agent | An agent with security issues for testing |
| safe-agent | A safe agent with minimal permissions |
Slash commands (3)
/fix-ci/dangerous-deploy/safe-build
Similar rigs
JSK9999/ai-nexus
AI coding assistant rule manager for Claude Code, Cursor, and Codex. Load only the rules you need.
Skill Collector 958 tok ·
koolamusic/claudefiles
A minimal catalog of my favourite skills for working with claude
Skill Collector 4.6k tok ·
ragnarwestad/aide
Spec-driven development for AI coding assistants (Claude Code, Codex, OpenCode, Copilot) — specs, skills and a dashboard that runs them.
Skill Collector 6.6k tok ·
dirien/yet-another-agent-harness
A Go agent harness for Claude Code — runtime hooks, MCP server, session tracking, middleware chains, and full config generation in one binary
Orchestrator 15.9k tok ·