wstein/workharbor
A self-hosted supervisor for AI coding agents: isolated workspaces, your approval for every push, one dashboard on every device. Pre-release; macOS (Apple silicon) first.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit wstein/workharbor/.claude ./rig-workharbor # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(gh issue:*)",
"Bash(gh project:*)",
"Bash(gh api graphql:*)",
"Bash(gh api * graphql)",
"Bash(gh api * graphql *)",
"Bash(sudo:*)",
"Bash(security:*)",
"Bash(gh auth:*)",
"Bash(git credential:*)",
"Bash(git push*--force*)",
"Bash(git push* -f*)",
"Bash(git push* -uf*)",
"Bash(git push* -fu*)",
"Bash(git push*+*)",
"Bash(git push*:**)",
"Bash(git push*--delete*)",
"Bash(git push* -d*)",
"Bash(git push*--mirror*)",
"Bash(git push*--all*)",
"Bash(git push*--tags*)",
"Bash(git push*--follow-tags*)",
"Bash(git push*--prune*)",
"Bash(git push*--no-verify*)",
"Bash(git push* main*)",
"Bash(git push* master*)",
"Bash(git push*HEAD*)",
"Bash(git push*refs/*)",
"Bash(git push* tag *)",
"Bash(git -C * push*)",
"Bash(git -c * push*)",
"Bash(git --git-dir* push*)",
"Bash(git --work-tree* push*)",
"Bash(git merge:*)",
"Bash(git tag:*)",
"Bash(git notes add:*)",
"Bash(git notes append:*)",
"Bash(git notes edit:*)",
"Bash(git notes remove:*)",
"Bash(git notes merge:*)",
"Bash(git notes prune:*)",
"Bash(git notes copy:*)",
"Bash(git notes --ref *)",
"Bash(git notes --ref=* add*)",
"Bash(git notes --ref=* edit*)",
"Bash(git notes --ref=* remove*)",
"Bash(git notes --ref=* merge*)",
"Bash(git notes --ref=* prune*)",
"Bash(git notes --ref=* copy*)",
"Bash(git notes --ref=review append* -F*)",
"Bash(git notes --ref=review append* --f*)",
"Bash(git notes --ref=review append* -C*)",
"Bash(git notes --ref=review append* -c*)",
"Bash(git notes --ref=review append* --re*)",
"Bash(git notes --ref=review append* -e*)",
"Bash(git notes --ref=review append* \"-*)",
"Bash(git notes --ref=review append* '-*)",
"Bash(git notes --ref=review append* \\-*)",
"Bash(git notes --ref=confirm*)",
"Bash(git notes --ref=refs/*)",
"Bash(git update-ref:*)",
"Bash(git worktree add:*)",
"Bash(gh release create:*)",
"Bash(gh release edit:*)",
"Bash(gh release delete:*)",
"Bash(gh release upload:*)",
"Bash(gh pr merge:*)",
"Bash(launchctl:*)",
"Read(~/.ssh/**)",
"Read(//**/.ssh/**)",
"Read(~/.config/whr/**)",
"Read(//**/.config/whr/**)",
"Read(~/.config/gh/**)",
"Read(//**/.config/gh/**)",
"Read(~/Library/Keychains/**)",
"Read(//**/Library/Keychains/**)",
"Read(//Library/Keychains/**)",
"Bash(cat */.ssh*)",
"Bash(cat */.config/whr*)",
"Bash(cat */.config/gh*)",
"Bash(cat */Library/Keychains*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash|Monitor|PowerShell",
"hooks": [
{
"type": "command",
"command": "cd \"$CLAUDE_PROJECT_DIR\" && go run ./cmd/ghguard"
}
]
}
]
}
} Hooks (1)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash|Monitor|PowerShell | cd "$CLAUDE_PROJECT_DIR" && go run ./cmd/ghguard |
Permissions
deny (92)
Bash(gh issue:*)
Bash(gh project:*)
Bash(gh api graphql:*)
Bash(gh api * graphql)
Bash(gh api * graphql *)
Bash(sudo:*)
Bash(security:*)
Bash(gh auth:*)
Bash(git credential:*)
Bash(git push*--force*)
Bash(git push* -f*)
Bash(git push* -uf*)
Bash(git push* -fu*)
Bash(git push*+*)
Bash(git push*:**)
Bash(git push*--delete*)
Bash(git push* -d*)
Bash(git push*--mirror*)
Bash(git push*--all*)
Bash(git push*--tags*)
Bash(git push*--follow-tags*)
Bash(git push*--prune*)
Bash(git push*--no-verify*)
Bash(git push* main*)
Bash(git push* master*)
Bash(git push*HEAD*)
Bash(git push*refs/*)
Bash(git push* tag *)
Bash(git -C * push*)
Bash(git -c * push*)
Bash(git --git-dir* push*)
Bash(git --work-tree* push*)
Bash(git merge:*)
Bash(git tag:*)
Bash(git notes add:*)
Bash(git notes append:*)
Bash(git notes edit:*)
Bash(git notes remove:*)
Bash(git notes merge:*)
Bash(git notes prune:*)
Bash(git notes copy:*)
Bash(git notes --ref *)
Bash(git notes --ref=* add*)
Bash(git notes --ref=* edit*)
Bash(git notes --ref=* remove*)
Bash(git notes --ref=* merge*)
Bash(git notes --ref=* prune*)
Bash(git notes --ref=* copy*)
Bash(git notes --ref=review append* -F*)
Bash(git notes --ref=review append* --f*)
Bash(git notes --ref=review append* -C*)
Bash(git notes --ref=review append* -c*)
Bash(git notes --ref=review append* --re*)
Bash(git notes --ref=review append* -e*)
Bash(git notes --ref=review append* "-*)
Bash(git notes --ref=review append* '-*)
Bash(git notes --ref=review append* \-*)
Bash(git notes --ref=confirm*)
Bash(git notes --ref=refs/*)
Bash(git update-ref:*)
ask (0)
—
allow (45)
Grep
Glob
WebSearch
Bash(git status)
Bash(git status --short)
Bash(git rev-parse --abbrev-ref HEAD)
Bash(git rev-parse --short HEAD)
Bash(git worktree list)
Bash(git branch --list)
Bash(git ls-files)
Bash(make check)
Bash(make test)
Bash(make vet)
Bash(make lint)
Bash(make fmt-check)
Bash(make editorconfig)
Bash(make commitlint)
Bash(make race)
Bash(make temp-ls)
Bash(gh run list:*)
Bash(gh run view:*)
Bash(gh run watch:*)
Bash(gh pr checks:*)
Bash(gh release list:*)
Bash(df -h)
Bash(container ls)
Bash(container ls --all)
Bash(container image ls)
Bash(gh api repos/wstein/workharbor/code-scanning/alerts)
Bash(gh api repos/wstein/workharbor/dependabot/alerts)
Bash(gh api repos/wstein/workharbor/rulesets)
Bash(scripts/board-snapshot.sh)
Bash(scripts/board-snapshot.sh --refresh)
Bash(scripts/board-snapshot.sh card:*)
Bash(scripts/board-snapshot.sh queue:*)
Bash(git push origin docs/*)
Bash(git push -u origin docs/*)
Bash(git push origin fix/*)
Bash(git push -u origin fix/*)
Bash(git push origin feat/*)
Bash(git push -u origin feat/*)
Bash(git push origin chore/*)
Bash(git push -u origin chore/*)
Bash(git push origin ci/*)
Bash(git push -u origin ci/*)
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·