scadastrangelove/agent-audit
Forensic auditor for local AI coding agents (Claude Code, Codex CLI, OpenClaw) and project-surface scanner for repos containing skills, plugins, and MCP manifests. Reads session logs, configs, and instruction files, detects known-bad patter
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ npx degit scadastrangelove/agent-audit/benchmarks/m2-calibration-corpus/c15-skills-only-no-approval-tag/project/.claude ./rig-agent-audit # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit scadastrangelove/agent-audit/benchmarks/m2-calibration-corpus/c15-skills-only-no-approval-tag/project/.claude/skills/format .claude/skills/format $ npx degit scadastrangelove/agent-audit/benchmarks/m2-calibration-corpus/c19-d3-high-advice-not-demoted/project/red-team/skills/lesson1 .claude/skills/lesson1 $ npx degit scadastrangelove/agent-audit/benchmarks/m2-calibration-corpus/c2-fetch-surface-injection-link/project/.claude/skills/fetch-installer .claude/skills/fetch-installer $ npx degit scadastrangelove/agent-audit/benchmarks/m2-calibration-corpus/c20-d3-critical-advice-not-demoted/project/red-team/skills/lesson-advanced .claude/skills/lesson-advanced $ npx degit scadastrangelove/agent-audit/benchmarks/m2-calibration-corpus/c4-educational-demotes-advice/project/red-team/skills/payload-101 .claude/skills/payload-101
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (5)
Similar rigs
platformplatform/PlatformPlatform
A platform designed for building enterprise-grade, multi-tenant products using Azure, .NET, React, TypeScript, Infrastructure as Code, etc.
Orchestrator 12.1k tok ·
managedcode/dotnet-skills
Installable .NET skill catalog and CLI for Codex, Claude Code, GitHub Copilot, and Gemini.
Skill Collector 22.9k tok ·
anomalyco/opencode
The open source coding agent.
Pragmatist 4.2k tok ·
DietrichGebert/ponytail
Makes your AI agent think like the laziest senior dev in the room. The best code is the code you never wrote.
Pragmatist 1.6k tok ·