~ / rigs / wstein / workharbor

wstein/workharbor

A self-hosted supervisor for AI coding agents: isolated workspaces, your approval for every push, one dashboard on every device. Pre-release; macOS (Apple silicon) first.

↗ GitHub ★ 1 eupl-1.2 updated 1d ago project Claude CodeCodex
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~6.0k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit wstein/workharbor/.claude ./rig-workharbor  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(gh issue:*)",
      "Bash(gh project:*)",
      "Bash(gh api graphql:*)",
      "Bash(gh api * graphql)",
      "Bash(gh api * graphql *)",
      "Bash(sudo:*)",
      "Bash(security:*)",
      "Bash(gh auth:*)",
      "Bash(git credential:*)",
      "Bash(git push*--force*)",
      "Bash(git push* -f*)",
      "Bash(git push* -uf*)",
      "Bash(git push* -fu*)",
      "Bash(git push*+*)",
      "Bash(git push*:**)",
      "Bash(git push*--delete*)",
      "Bash(git push* -d*)",
      "Bash(git push*--mirror*)",
      "Bash(git push*--all*)",
      "Bash(git push*--tags*)",
      "Bash(git push*--follow-tags*)",
      "Bash(git push*--prune*)",
      "Bash(git push*--no-verify*)",
      "Bash(git push* main*)",
      "Bash(git push* master*)",
      "Bash(git push*HEAD*)",
      "Bash(git push*refs/*)",
      "Bash(git push* tag *)",
      "Bash(git -C * push*)",
      "Bash(git -c * push*)",
      "Bash(git --git-dir* push*)",
      "Bash(git --work-tree* push*)",
      "Bash(git merge:*)",
      "Bash(git tag:*)",
      "Bash(git notes add:*)",
      "Bash(git notes append:*)",
      "Bash(git notes edit:*)",
      "Bash(git notes remove:*)",
      "Bash(git notes merge:*)",
      "Bash(git notes prune:*)",
      "Bash(git notes copy:*)",
      "Bash(git notes --ref *)",
      "Bash(git notes --ref=* add*)",
      "Bash(git notes --ref=* edit*)",
      "Bash(git notes --ref=* remove*)",
      "Bash(git notes --ref=* merge*)",
      "Bash(git notes --ref=* prune*)",
      "Bash(git notes --ref=* copy*)",
      "Bash(git notes --ref=review append* -F*)",
      "Bash(git notes --ref=review append* --f*)",
      "Bash(git notes --ref=review append* -C*)",
      "Bash(git notes --ref=review append* -c*)",
      "Bash(git notes --ref=review append* --re*)",
      "Bash(git notes --ref=review append* -e*)",
      "Bash(git notes --ref=review append* \"-*)",
      "Bash(git notes --ref=review append* '-*)",
      "Bash(git notes --ref=review append* \\-*)",
      "Bash(git notes --ref=confirm*)",
      "Bash(git notes --ref=refs/*)",
      "Bash(git update-ref:*)",
      "Bash(git worktree add:*)",
      "Bash(gh release create:*)",
      "Bash(gh release edit:*)",
      "Bash(gh release delete:*)",
      "Bash(gh release upload:*)",
      "Bash(gh pr merge:*)",
      "Bash(launchctl:*)",
      "Read(~/.ssh/**)",
      "Read(//**/.ssh/**)",
      "Read(~/.config/whr/**)",
      "Read(//**/.config/whr/**)",
      "Read(~/.config/gh/**)",
      "Read(//**/.config/gh/**)",
      "Read(~/Library/Keychains/**)",
      "Read(//**/Library/Keychains/**)",
      "Read(//Library/Keychains/**)",
      "Bash(cat */.ssh*)",
      "Bash(cat */.config/whr*)",
      "Bash(cat */.config/gh*)",
      "Bash(cat */Library/Keychains*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|Monitor|PowerShell",
        "hooks": [
          {
            "type": "command",
            "command": "cd \"$CLAUDE_PROJECT_DIR\" && go run ./cmd/ghguard"
          }
        ]
      }
    ]
  }
}

Hooks (1)

eventmatcherruns
PreToolUseBash|Monitor|PowerShellcd "$CLAUDE_PROJECT_DIR" && go run ./cmd/ghguard

Permissions

deny (92)
Bash(gh issue:*)
Bash(gh project:*)
Bash(gh api graphql:*)
Bash(gh api * graphql)
Bash(gh api * graphql *)
Bash(sudo:*)
Bash(security:*)
Bash(gh auth:*)
Bash(git credential:*)
Bash(git push*--force*)
Bash(git push* -f*)
Bash(git push* -uf*)
Bash(git push* -fu*)
Bash(git push*+*)
Bash(git push*:**)
Bash(git push*--delete*)
Bash(git push* -d*)
Bash(git push*--mirror*)
Bash(git push*--all*)
Bash(git push*--tags*)
Bash(git push*--follow-tags*)
Bash(git push*--prune*)
Bash(git push*--no-verify*)
Bash(git push* main*)
Bash(git push* master*)
Bash(git push*HEAD*)
Bash(git push*refs/*)
Bash(git push* tag *)
Bash(git -C * push*)
Bash(git -c * push*)
Bash(git --git-dir* push*)
Bash(git --work-tree* push*)
Bash(git merge:*)
Bash(git tag:*)
Bash(git notes add:*)
Bash(git notes append:*)
Bash(git notes edit:*)
Bash(git notes remove:*)
Bash(git notes merge:*)
Bash(git notes prune:*)
Bash(git notes copy:*)
Bash(git notes --ref *)
Bash(git notes --ref=* add*)
Bash(git notes --ref=* edit*)
Bash(git notes --ref=* remove*)
Bash(git notes --ref=* merge*)
Bash(git notes --ref=* prune*)
Bash(git notes --ref=* copy*)
Bash(git notes --ref=review append* -F*)
Bash(git notes --ref=review append* --f*)
Bash(git notes --ref=review append* -C*)
Bash(git notes --ref=review append* -c*)
Bash(git notes --ref=review append* --re*)
Bash(git notes --ref=review append* -e*)
Bash(git notes --ref=review append* "-*)
Bash(git notes --ref=review append* '-*)
Bash(git notes --ref=review append* \-*)
Bash(git notes --ref=confirm*)
Bash(git notes --ref=refs/*)
Bash(git update-ref:*)
ask (0)
—
allow (45)
Grep
Glob
WebSearch
Bash(git status)
Bash(git status --short)
Bash(git rev-parse --abbrev-ref HEAD)
Bash(git rev-parse --short HEAD)
Bash(git worktree list)
Bash(git branch --list)
Bash(git ls-files)
Bash(make check)
Bash(make test)
Bash(make vet)
Bash(make lint)
Bash(make fmt-check)
Bash(make editorconfig)
Bash(make commitlint)
Bash(make race)
Bash(make temp-ls)
Bash(gh run list:*)
Bash(gh run view:*)
Bash(gh run watch:*)
Bash(gh pr checks:*)
Bash(gh release list:*)
Bash(df -h)
Bash(container ls)
Bash(container ls --all)
Bash(container image ls)
Bash(gh api repos/wstein/workharbor/code-scanning/alerts)
Bash(gh api repos/wstein/workharbor/dependabot/alerts)
Bash(gh api repos/wstein/workharbor/rulesets)
Bash(scripts/board-snapshot.sh)
Bash(scripts/board-snapshot.sh --refresh)
Bash(scripts/board-snapshot.sh card:*)
Bash(scripts/board-snapshot.sh queue:*)
Bash(git push origin docs/*)
Bash(git push -u origin docs/*)
Bash(git push origin fix/*)
Bash(git push -u origin fix/*)
Bash(git push origin feat/*)
Bash(git push -u origin feat/*)
Bash(git push origin chore/*)
Bash(git push -u origin chore/*)
Bash(git push origin ci/*)
Bash(git push -u origin ci/*)

Similar rigs

copied ✓