~ / rigs / stacklok / toolhive

stacklok/toolhive

ToolHive is an enterprise-grade platform for running and managing Model Context Protocol (MCP) servers.

↗ GitHub ★ 2,235 apache-2.0 updated 5d ago project Claude CodeCodex
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~2.6k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
1/5
No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit stacklok/toolhive/.claude ./rig-toolhive  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit stacklok/toolhive/.claude/skills/add-rule .claude/skills/add-rule
$ npx degit stacklok/toolhive/.claude/skills/check-contribution .claude/skills/check-contribution
$ npx degit stacklok/toolhive/.claude/skills/code-review-assist .claude/skills/code-review-assist
$ npx degit stacklok/toolhive/.claude/skills/deflake .claude/skills/deflake
$ npx degit stacklok/toolhive/.claude/skills/deploy-otel .claude/skills/deploy-otel
$ npx degit stacklok/toolhive/.claude/skills/deploying-vmcp-locally .claude/skills/deploying-vmcp-locally
$ npx degit stacklok/toolhive/.claude/skills/doc-review .claude/skills/doc-review
$ npx degit stacklok/toolhive/.claude/skills/implement-story .claude/skills/implement-story
$ npx degit stacklok/toolhive/.claude/skills/release-notes .claude/skills/release-notes
$ npx degit stacklok/toolhive/.claude/skills/split-pr .claude/skills/split-pr
$ npx degit stacklok/toolhive/.claude/skills/toolhive-release .claude/skills/toolhive-release
$ npx degit stacklok/toolhive/.claude/skills/vmcp-review .claude/skills/vmcp-review
$ npx degit stacklok/toolhive/skills/toolhive-cli-user .claude/skills/toolhive-cli-user
$ curl -fsSL --create-dirs -o .claude/agents/bug-triage.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/bug-triage.md
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/documentation-writer.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/documentation-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/golang-code-writer.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/golang-code-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/kubernetes-expert.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/kubernetes-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/mcp-protocol-expert.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/mcp-protocol-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/oauth-expert.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/oauth-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/security-advisor.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/security-advisor.md
$ curl -fsSL --create-dirs -o .claude/agents/site-reliability-engineer.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/site-reliability-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/tech-lead-orchestrator.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/tech-lead-orchestrator.md
$ curl -fsSL --create-dirs -o .claude/agents/toolhive-expert.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/toolhive-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/unit-test-writer.md https://raw.githubusercontent.com/stacklok/toolhive/main/.claude/agents/unit-test-writer.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,974 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(~/.aws/**)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(.env)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/.env.*)",
      "Read(**/*.key)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(npm publish:*)",
      "Bash(wget *)",
      "Bash(git rebase *)",
      "Bash(gh pr merge *)",
      "Bash(git commit *)"
    ]
  }
}

Skills (13)

Subagents (12)

bug-triage
model: inherit
Triages GitHub issues by investigating whether they've been resolved in the codebase, recommending closures, and helping craft polite closure messages. Use when doing bug triage sessions or cleaning u
code-reviewer
model: inherit
Reviews code for ToolHive best practices, security patterns, Go conventions, and architectural consistency
documentation-writer
model: inherit
Maintains consistent documentation, updates CLI docs, and ensures documentation matches code behavior
golang-code-writer
model: inherit
Write, generate, or create new Go code — functions, structs, interfaces, methods, or complete packages
kubernetes-expert
model: inherit
Specialized in Kubernetes operator patterns, CRDs, controllers, and cloud-native architecture for ToolHive
mcp-protocol-expert
model: inherit
PROACTIVELY use for MCP protocol questions, transport implementations, JSON-RPC debugging, and spec compliance verification. Expert in the current stable MCP specification.
oauth-expert
model: inherit
Specialized in OAuth 2.0, OIDC, token exchange, and authentication flows for ToolHive
security-advisor
model: inherit
Security guidance for code reviews, architecture decisions, auth implementations, and threat modeling
site-reliability-engineer
model: inherit
Observability and monitoring guidance — OpenTelemetry instrumentation, metrics, tracing, and monitoring stack configuration
tech-lead-orchestrator
model: inherit
Architectural oversight, task breakdown, and delegation for complex multi-component features
toolhive-expert
model: inherit
Codebase knowledge, navigation, and implementation guidance — use for understanding existing code and patterns
unit-test-writer
model: inherit
Write comprehensive unit tests for Go code — functions, methods, or components that need thorough test coverage

Hooks (1)

eventmatcherruns
PostToolUseEdit|Writecd "$CLAUDE_PROJECT_DIR" && changed_file="$CLAUDE_TOOL_ARG_file_path"; if [ -n "$changed_file" ] && echo "$changed_file" | grep -q '\.go$'; then task lint-fix 2>/dev/null; task license-fix 2>/dev/null; fi; exit 0

Permissions

deny (0)
—
ask (0)
—
allow (29)
Bash(go test:*)
Bash(task test)
Bash(task lint)
Bash(task lint-fix)
Bash(task license-fix)
Bash(golangci-lint run:*)
Bash(go doc:*)
WebFetch(domain:modelcontextprotocol.io)
Bash(pre-commit:*)
Bash(pre-commit run:*)
Bash(pre-commit install:*)
Bash(pre-commit autoupdate:*)
Bash(helm-docs:*)
Bash(codespell:*)
Bash(task operator-install-crds)
Bash(task operator-uninstall-crds)
Bash(task operator-deploy-latest)
Bash(task operator-deploy-local)
Bash(task operator-undeploy)
Bash(task operator-generate)
Bash(task operator-manifests)
Bash(task operator-test)
Bash(task operator-e2e-test)
Bash(task crdref-install)
Bash(task crdref-gen)
Bash(helm template:*)
Bash(git log:*)
Bash(ct lint:*)
Bash(helm-docs --dry-run)

Similar rigs

copied ✓