~ / rigs / yaniv-golan / cowork-harness

yaniv-golan/cowork-harness

Scriptable, CI-friendly harness for Claude Cowork's runtime contract for testing skills across scenarios — same agent, mounts, egress allowlist, permission protocol, and sandbox limitations.

↗ GitHub ★ 2 MIT updated today personal setup Claude CodeCodex Claude plugin
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~8.3k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add example-fs -- npx -y @modelcontextprotocol/server-filesystem /sessions/local/mnt
$ npx degit yaniv-golan/cowork-harness/.claude ./rig-cowork-harness  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add example-fs -- npx -y @modelcontextprotocol/server-filesystem /sessions/local/mnt
$ npx degit yaniv-golan/cowork-harness/.claude/skills/cowork-harness .claude/skills/cowork-harness
$ npx degit yaniv-golan/cowork-harness/examples/hillclimb/plugin/skills/sales-brief .claude/skills/sales-brief
$ npx degit yaniv-golan/cowork-harness/examples/probes/gated-probe/skills/gated-probe .claude/skills/gated-probe
$ npx degit yaniv-golan/cowork-harness/examples/probes/l0-plugin-delivery/skills/delivery-marker .claude/skills/delivery-marker
$ npx degit yaniv-golan/cowork-harness/examples/probes/resume-continuity-probe/skills/resume-continuity-probe .claude/skills/resume-continuity-probe
$ npx degit yaniv-golan/cowork-harness/examples/skills/csv-fx-normalize/skills/csv-fx-normalize .claude/skills/csv-fx-normalize
$ npx degit yaniv-golan/cowork-harness/examples/skills/csv-metrics/skills/csv-metrics .claude/skills/csv-metrics
$ npx degit yaniv-golan/cowork-harness/examples/skills/my-pdf-skill/skills/my-pdf-skill .claude/skills/my-pdf-skill

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(.env)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(~/.aws/**)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/*.key)",
      "Read(**/.env.*)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(git rebase *)",
      "Bash(wget *)",
      "Bash(npm publish:*)",
      "Bash(git commit *)",
      "Bash(gh pr merge *)"
    ]
  }
}

MCP servers (1)

serversourceest. tokens
Filesystem · "example-fs" npm 4.2k

Skills (8)

Similar rigs

copied ✓