trailofbits/coop
Isolated VM environment for running Claude Code and Codex
ARCHETYPE
Orchestrator
A bench of specialised subagents. The main agent mostly delegates.
Copy this rig
# review before running: this installs third-party code
$ npx degit trailofbits/coop/.claude ./rig-coop # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit trailofbits/coop/.agents/skills/babysit-my-prs .claude/skills/babysit-my-prs $ npx degit trailofbits/coop/.agents/skills/babysit-pr .claude/skills/babysit-pr $ npx degit trailofbits/coop/.agents/skills/closeout-review .claude/skills/closeout-review $ npx degit trailofbits/coop/.agents/skills/integration .claude/skills/integration $ npx degit trailofbits/coop/.agents/skills/mutation-check .claude/skills/mutation-check $ npx degit trailofbits/coop/.agents/skills/review .claude/skills/review
$ curl -fsSL --create-dirs -o .claude/agents/review-api-usage.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-api-usage.md $ curl -fsSL --create-dirs -o .claude/agents/review-comments.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-comments.md $ curl -fsSL --create-dirs -o .claude/agents/review-conventions.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-conventions.md $ curl -fsSL --create-dirs -o .claude/agents/review-correctness.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-correctness.md $ curl -fsSL --create-dirs -o .claude/agents/review-design.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-design.md $ curl -fsSL --create-dirs -o .claude/agents/review-docs.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-docs.md $ curl -fsSL --create-dirs -o .claude/agents/review-security.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-security.md $ curl -fsSL --create-dirs -o .claude/agents/review-tests.md https://raw.githubusercontent.com/trailofbits/coop/main/.claude/agents/review-tests.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "${CLAUDE_PROJECT_DIR}/.claude/hooks/no-pipe-test-output.sh"
},
{
"type": "command",
"command": "${CLAUDE_PROJECT_DIR}/.claude/hooks/closeout-review-gate.sh"
}
]
}
]
}
} Skills (6)
Subagents (8)
| review-api-usage | Verifies the diff's use of external crate APIs against current documentation — signatures, parameter types, return values, deprecations, version-specific behavior, error semantics. |
| review-comments | Aggressively reviews inline code comments in the diff — flags comments that are unnecessary, redundant, stale, or too verbose. Comments must earn their place by explaining why, not what. |
| review-conventions | Reviews the Rust diff for convention violations, rename consistency, drift in shared constants, cross-file infra sync (Cargo.toml/config.example.toml/pre-commit/CI/installers), and diff noise. |
| review-correctness | Reviews a Rust diff for correctness and runtime safety — logic errors, missing edge cases, error handling and `Result`/`?` propagation, panics on fallible input, process/SSH lifecycle, resource cleanu |
| review-design | Reviews the Rust diff for design and complexity — local simplifications, phantom features (docs/flags without implementation), type-design opportunities, and at most one structural finding when the ov |
| review-docs | Reviews documentation quality, correctness, and style in the diff — doc-comments and prose docs (README/docs/AGENTS.md/--help text). Flags docs that are outdated, unnecessary, or too verbose. |
| review-security | Reviews a diff against coop's trust model — the VM isolation boundary, credential/secret injection, guest→host input flow, host-side command construction on tainted bytes, network binds, and `coop upd |
| review-tests | Reviews the diff for test coverage and quality — changed behavior without tests, untested error paths and edges, integration-test phase gaps, mutation-scope regressions, and tautological or over-mocke |
Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | ${CLAUDE_PROJECT_DIR}/.claude/hooks/no-pipe-test-output.sh |
| PreToolUse | Bash | ${CLAUDE_PROJECT_DIR}/.claude/hooks/closeout-review-gate.sh |
| PostToolUse | Write|Edit | ${CLAUDE_PROJECT_DIR}/.claude/hooks/cargo-fmt.sh |
Slash commands (4)
/babysit-my-prs/babysit-pr/integration/my-review
Permissions
deny (0)
—
ask (0)
—
allow (76)
Bash(ls:*)
Bash(pwd)
Bash(which:*)
Bash(type:*)
Bash(tree:*)
Bash(wc:*)
Bash(sort:*)
Bash(uniq:*)
Bash(head:*)
Bash(tail:*)
Bash(cat:*)
Bash(file:*)
Bash(stat:*)
Bash(du:*)
Bash(df:*)
Bash(env)
Bash(printenv:*)
Bash(echo:*)
Bash(date:*)
Bash(rg:*)
Bash(fd:*)
Bash(ast-grep:*)
Bash(jq:*)
Bash(git status)
Bash(git status:*)
Bash(git diff)
Bash(git diff:*)
Bash(git log)
Bash(git log:*)
Bash(git show)
Bash(git show:*)
Bash(git blame:*)
Bash(git branch)
Bash(git stash list)
Bash(git stash show:*)
Bash(git add:*)
Bash(git restore --staged:*)
Bash(git commit:*)
Bash(git fetch:*)
Bash(git remote show:*)
Bash(git remote get-url:*)
Bash(git tag)
Bash(git tag -l:*)
Bash(git rev-parse:*)
Bash(git rev-list:*)
Bash(git ls-files:*)
Bash(git ls-tree:*)
Bash(git describe:*)
Bash(git worktree list:*)
Bash(gh pr view:*)
Bash(gh pr list:*)
Bash(gh pr diff:*)
Bash(gh pr checks:*)
Bash(gh pr status:*)
Bash(gh issue view:*)
Bash(gh issue list:*)
Bash(gh run view:*)
Bash(gh run list:*)
Bash(gh workflow view:*)
Bash(gh workflow list:*)
Similar rigs
JDevlieghere/dotfiles
⚙ Dotfiles for Linux & macOS
Orchestrator 1.5k tok ·
AlexisBalayre/agentspine
One shared agent setup for Claude Code, Codex, opencode, Mistral Vibe and Cursor: AGENTS.md, skills and blocking hooks stored once in .agents/ and wired into every tool.
Orchestrator 3.3k tok ·
gilles-g/localpr
Claude Code plugin: review a local git diff in a pull-request-style page, comment on lines, and let Claude apply the review. Python stdlib only, offline.
Pragmatist 5.4k tok ·
AlexisBalayre/claude-code-config
Opinionated Claude Code config: path-scoped rules, 34 skills, 12 subagents, deterministic hooks, and a multi-agent PR review. Stack-agnostic; run /adapt-to-project to fit any repo.
Fort Knox 6.4k tok ·