~ / rigs / sonishrey9 / kiwi_control

sonishrey9/kiwi_control

Local-first, repo-first control plane for coding agents. Better repo context, less drift, clearer execution state.

↗ GitHub ★ 3 NOASSERTION updated 3mo ago project Claude CodeCodexCursorGemini CLICopilot
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~7.9k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
1/5
No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add code-review-graph -- uvx code-review-graph serve
$ npx degit sonishrey9/kiwi_control/.claude ./rig-kiwi_control  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add code-review-graph -- uvx code-review-graph serve

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

MCP servers (1)

serversourceest. tokens
code-review-graph pypi 2.5k

Permissions

deny (0)
—
ask (0)
—
allow (7)
Bash(/bin/bash -c 'cat ~/.gitconfig')
Bash(/bin/bash -c 'git config --list --show-origin 2>/dev/null | grep -Ei "user\\.name|user\\.email|include" || echo "NONE"')
Bash(/bin/bash -c 'find "/Volumes/shrey ssd" ~/Desktop ~/Documents ~/Code ~ -maxdepth 5 -name ".git" -type d 2>/dev/null | grep -v "node_modules\\|\\.Trash\\|Li
Bash(/bin/bash -c 'find ~ -maxdepth 5 -name ".git" -type d 2>/dev/null | grep -v "node_modules\\|\\.Trash\\|Library" | sort')
Bash(/bin/bash -c 'find "/Volumes/shrey ssd" -maxdepth 4 -name ".git" -type d 2>/dev/null | head -30')
Bash(/bin/bash -c 'find ~ -maxdepth 4 -name ".git" -type d 2>/dev/null | grep -v "Library\\|\\.Trash\\|node_modules" | head -30')
Bash(/bin/bash -c ':*)

Similar rigs

copied ✓