~ / rigs / trailofbits / coop

trailofbits/coop

Isolated VM environment for running Claude Code and Codex

↗ GitHub ★ 741 apache-2.0 updated 7d ago project Claude CodeCodex
share on X
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
CONTEXT TAX · EVERY TURN
~2.7k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
2/5
Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit trailofbits/coop/.claude ./rig-coop  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit trailofbits/coop/.agents/skills/babysit-my-prs .claude/skills/babysit-my-prs
$ npx degit trailofbits/coop/.agents/skills/babysit-pr .claude/skills/babysit-pr
$ npx degit trailofbits/coop/.agents/skills/closeout-review .claude/skills/closeout-review
$ npx degit trailofbits/coop/.agents/skills/integration .claude/skills/integration
$ npx degit trailofbits/coop/.agents/skills/mutation-check .claude/skills/mutation-check
$ npx degit trailofbits/coop/.agents/skills/review .claude/skills/review
$ curl -fsSL --create-dirs -o .claude/agents/review-api-usage.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-api-usage.md
$ curl -fsSL --create-dirs -o .claude/agents/review-comments.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-comments.md
$ curl -fsSL --create-dirs -o .claude/agents/review-conventions.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-conventions.md
$ curl -fsSL --create-dirs -o .claude/agents/review-correctness.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-correctness.md
$ curl -fsSL --create-dirs -o .claude/agents/review-design.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-design.md
$ curl -fsSL --create-dirs -o .claude/agents/review-docs.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-docs.md
$ curl -fsSL --create-dirs -o .claude/agents/review-security.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-security.md
$ curl -fsSL --create-dirs -o .claude/agents/review-tests.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-tests.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "${CLAUDE_PROJECT_DIR}/.claude/hooks/no-pipe-test-output.sh"
          },
          {
            "type": "command",
            "command": "${CLAUDE_PROJECT_DIR}/.claude/hooks/closeout-review-gate.sh"
          }
        ]
      }
    ]
  }
}

Skills (6)

Subagents (8)

review-api-usageVerifies the diff's use of external crate APIs against current documentation — signatures, parameter types, return values, deprecations, version-specific behavior, error semantics.
review-commentsAggressively reviews inline code comments in the diff — flags comments that are unnecessary, redundant, stale, or too verbose. Comments must earn their place by explaining why, not what.
review-conventionsReviews the Rust diff for convention violations, rename consistency, drift in shared constants, cross-file infra sync (Cargo.toml/config.example.toml/pre-commit/CI/installers), and diff noise.
review-correctnessReviews a Rust diff for correctness and runtime safety — logic errors, missing edge cases, error handling and `Result`/`?` propagation, panics on fallible input, process/SSH lifecycle, resource cleanu
review-designReviews the Rust diff for design and complexity — local simplifications, phantom features (docs/flags without implementation), type-design opportunities, and at most one structural finding when the ov
review-docsReviews documentation quality, correctness, and style in the diff — doc-comments and prose docs (README/docs/AGENTS.md/--help text). Flags docs that are outdated, unnecessary, or too verbose.
review-securityReviews a diff against coop's trust model — the VM isolation boundary, credential/secret injection, guest→host input flow, host-side command construction on tainted bytes, network binds, and `coop upd
review-testsReviews the diff for test coverage and quality — changed behavior without tests, untested error paths and edges, integration-test phase gaps, mutation-scope regressions, and tautological or over-mocke

Hooks (3)

eventmatcherruns
PreToolUseBash${CLAUDE_PROJECT_DIR}/.claude/hooks/no-pipe-test-output.sh
PreToolUseBash${CLAUDE_PROJECT_DIR}/.claude/hooks/closeout-review-gate.sh
PostToolUseWrite|Edit${CLAUDE_PROJECT_DIR}/.claude/hooks/cargo-fmt.sh

Slash commands (4)

/babysit-my-prs/babysit-pr/integration/my-review

Permissions

deny (0)
—
ask (0)
—
allow (76)
Bash(ls:*)
Bash(pwd)
Bash(which:*)
Bash(type:*)
Bash(tree:*)
Bash(wc:*)
Bash(sort:*)
Bash(uniq:*)
Bash(head:*)
Bash(tail:*)
Bash(cat:*)
Bash(file:*)
Bash(stat:*)
Bash(du:*)
Bash(df:*)
Bash(env)
Bash(printenv:*)
Bash(echo:*)
Bash(date:*)
Bash(rg:*)
Bash(fd:*)
Bash(ast-grep:*)
Bash(jq:*)
Bash(git status)
Bash(git status:*)
Bash(git diff)
Bash(git diff:*)
Bash(git log)
Bash(git log:*)
Bash(git show)
Bash(git show:*)
Bash(git blame:*)
Bash(git branch)
Bash(git stash list)
Bash(git stash show:*)
Bash(git add:*)
Bash(git restore --staged:*)
Bash(git commit:*)
Bash(git fetch:*)
Bash(git remote show:*)
Bash(git remote get-url:*)
Bash(git tag)
Bash(git tag -l:*)
Bash(git rev-parse:*)
Bash(git rev-list:*)
Bash(git ls-files:*)
Bash(git ls-tree:*)
Bash(git describe:*)
Bash(git worktree list:*)
Bash(gh pr view:*)
Bash(gh pr list:*)
Bash(gh pr diff:*)
Bash(gh pr checks:*)
Bash(gh pr status:*)
Bash(gh issue view:*)
Bash(gh issue list:*)
Bash(gh run view:*)
Bash(gh run list:*)
Bash(gh workflow view:*)
Bash(gh workflow list:*)

Similar rigs

copied ✓