~ / starters / mobile

Mobile apps starter

iOS, Android, React Native, Flutter

1.7kcontext tax / turn · Featherweight
5/5guardrails
1 · 4MCP servers · skills
ARCHETYPEFort Knox

Install

Run in your project root. Existing files are never overwritten (unzip -n / [ -e … ] skip them). Review AGENTS.md and fill in the <placeholders>.

$ curl -fsSL https://agentrigs.dev/starters/agentrigs-mobile.zip -o agentrigs-starter.zip && unzip -n agentrigs-starter.zip && chmod +x .claude/hooks/guard.sh && rm agentrigs-starter.zip
$ npx degit vercel-labs/agent-skills/skills/react-native-skills .claude/skills/vercel-react-native-skills
$ npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development
$ npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging
$ npx degit obra/superpowers/skills/verification-before-completion .claude/skills/verification-before-completion

Or download agentrigs-mobile.zip (6 files). Skills are fetched from their source repos with npx degit.

mkdir -p .claude/hooks
[ -e AGENTS.md ] && echo "skip AGENTS.md (exists)" || cat > AGENTS.md <<'AGENTRIGS_EOF'
# App
<one paragraph: platforms, framework (Swift/Kotlin/RN/Flutter), min OS versions>

## Commands
- Build: `<cmd>` · Unit tests: `<cmd>` · Lint: `<cmd>` · Run on simulator: `<cmd>`

## Conventions
- Follow platform guidelines (HIG / Material); support dynamic type, dark mode and accessibility labels.
- No new permissions (camera, location, contacts) without asking; explain why in the PR.
- Keep business logic out of views so it can be unit-tested.
- Never commit signing keys, provisioning profiles or keystores; never touch release config.

## Checks before done
Build + unit tests pass; describe what you checked on a simulator and on which OS version.

## Workflow
1. Restate the task in one line and list the files you expect to touch.
2. Make the smallest change that works; keep diffs reviewable.
3. Run the checks below before saying you're done, and show the output.
4. If something is ambiguous, ask one precise question instead of guessing.

## Safety
- Never read or print secrets (.env, keys, ~/.ssh). Ask for values instead.
- No destructive commands (rm -rf, force-push, reset --hard) without explicit approval; the guard hook blocks them anyway.
- Don't add dependencies, services or paid APIs without asking.
AGENTRIGS_EOF
[ -e CLAUDE.md ] && echo "skip CLAUDE.md (exists)" || cat > CLAUDE.md <<'AGENTRIGS_EOF'
@AGENTS.md

# Claude Code notes
- Use plan mode for multi-file changes. Prefer the installed skills over ad-hoc procedures.
AGENTRIGS_EOF
[ -e .claude/settings.json ] && echo "skip .claude/settings.json (exists)" || cat > .claude/settings.json <<'AGENTRIGS_EOF'
{
  "permissions": {
    "deny": [
      "Bash(rm -rf:*)",
      "Bash(rm -fr:*)",
      "Bash(sudo:*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(git clean -fd:*)",
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./**/.env)",
      "Read(./secrets/**)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(./**/*.pem)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(npm publish:*)",
      "Bash(docker:*)",
      "Bash(curl:*)"
    ],
    "defaultMode": "default"
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|Read|Edit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard.sh"
          }
        ]
      }
    ]
  }
}
AGENTRIGS_EOF
[ -e .claude/hooks/guard.sh ] && echo "skip .claude/hooks/guard.sh (exists)" || cat > .claude/hooks/guard.sh <<'AGENTRIGS_EOF'
#!/usr/bin/env bash
# .claude/hooks/guard.sh: PreToolUse guard. Exit code 2 blocks the tool call and shows the reason to the model.
# Requires jq. Make executable: chmod +x .claude/hooks/guard.sh
input=$(cat)
tool=$(printf '%s' "$input" | jq -r '.tool_name // empty')
cmd=$(printf '%s' "$input" | jq -r '.tool_input.command // empty')
path=$(printf '%s' "$input" | jq -r '.tool_input.file_path // .tool_input.path // empty')
if [ "$tool" = "Bash" ]; then
  if printf '%s' "$cmd" | grep -Eq '(^|[;&| ])(sudo|mkfs|dd if=)|rm -[a-zA-Z]*r[a-zA-Z]*f|rm -[a-zA-Z]*f[a-zA-Z]*r|git push .*(--force|-f( |$))|git reset --hard|git clean -[a-z]*f|curl[^|]*\|[[:space:]]*(ba)?sh|chmod 777'; then
    echo "Blocked by guard.sh: destructive command ($cmd). Ask the user to run it manually." >&2; exit 2
  fi
fi
if printf '%s %s' "$path" "$cmd" | grep -Eq '(^|/|[[:space:]])\.env($|\.|[[:space:]])|id_rsa|\.pem($|[[:space:]])|\.ssh/|\.aws/credentials'; then
  echo "Blocked by guard.sh: secrets file ($path$cmd)." >&2; exit 2
fi
exit 0
AGENTRIGS_EOF
[ -e .mcp.json ] && echo "skip .mcp.json (exists)" || cat > .mcp.json <<'AGENTRIGS_EOF'
{
  "mcpServers": {
    "context7": {
      "type": "http",
      "url": "https://mcp.context7.com/mcp"
    }
  }
}
AGENTRIGS_EOF
[ -e AGENTRIGS-STARTER.md ] && echo "skip AGENTRIGS-STARTER.md (exists)" || cat > AGENTRIGS-STARTER.md <<'AGENTRIGS_EOF'
# AgentRigs starter: Mobile apps

Generated by https://agentrigs.dev/starters/mobile from real, well-guarded public rigs:
- https://github.com/pixel-cellar/Claude-Code-Game-Studios
- https://github.com/cassiewallace/dotfiles
- https://github.com/MysticalNobody/alatyr_flutter

## Install
1. Unzip into your repo root (`unzip -n` won't overwrite existing files).
2. `chmod +x .claude/hooks/guard.sh` (needs `jq`).
3. Fill in the <placeholders> in AGENTS.md.
4. Install the recommended skills (third-party code, so review first):

```bash
npx degit vercel-labs/agent-skills/skills/react-native-skills .claude/skills/vercel-react-native-skills
npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development
npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging
npx degit obra/superpowers/skills/verification-before-completion .claude/skills/verification-before-completion
```

Codex / Cursor / other harnesses read AGENTS.md directly; Claude Code reads CLAUDE.md, which imports AGENTS.md.
AGENTRIGS_EOF
chmod +x .claude/hooks/guard.sh
npx degit vercel-labs/agent-skills/skills/react-native-skills .claude/skills/vercel-react-native-skills  # skill: vercel-react-native-skills
npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development  # skill: test-driven-development
npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging  # skill: systematic-debugging
npx degit obra/superpowers/skills/verification-before-completion .claude/skills/verification-before-completion  # skill: verification-before-completion

Context tax

Instructions: 339MCP tool schemas (est.): 1.2kSkill metadata: 147Subagent metadata: 0

Claude Code pays for CLAUDE.md plus the imported AGENTS.md (~339 tok of instructions); Codex reads AGENTS.md alone (~308 tok). Index median: 2.2k tok. How we measure.

Guardrails

✓
Blocks destructive commands 9 deny/ask rule(s) e.g. Bash(rm -rf:*)
✓
Protects secrets Denies reads like Read(./.env)
✓
Pre-tool screening hook 1 PreToolUse hook(s)
✓
No YOLO mode Permission prompts stay on
✓
Sandbox or ask-first rules 4 ask rule(s), e.g. Bash(git push:*)

Files

# App
<one paragraph: platforms, framework (Swift/Kotlin/RN/Flutter), min OS versions>

## Commands
- Build: `<cmd>` · Unit tests: `<cmd>` · Lint: `<cmd>` · Run on simulator: `<cmd>`

## Conventions
- Follow platform guidelines (HIG / Material); support dynamic type, dark mode and accessibility labels.
- No new permissions (camera, location, contacts) without asking; explain why in the PR.
- Keep business logic out of views so it can be unit-tested.
- Never commit signing keys, provisioning profiles or keystores; never touch release config.

## Checks before done
Build + unit tests pass; describe what you checked on a simulator and on which OS version.

## Workflow
1. Restate the task in one line and list the files you expect to touch.
2. Make the smallest change that works; keep diffs reviewable.
3. Run the checks below before saying you're done, and show the output.
4. If something is ambiguous, ask one precise question instead of guessing.

## Safety
- Never read or print secrets (.env, keys, ~/.ssh). Ask for values instead.
- No destructive commands (rm -rf, force-push, reset --hard) without explicit approval; the guard hook blocks them anyway.
- Don't add dependencies, services or paid APIs without asking.
@AGENTS.md

# Claude Code notes
- Use plan mode for multi-file changes. Prefer the installed skills over ad-hoc procedures.
{
  "permissions": {
    "deny": [
      "Bash(rm -rf:*)",
      "Bash(rm -fr:*)",
      "Bash(sudo:*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(git clean -fd:*)",
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./**/.env)",
      "Read(./secrets/**)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(./**/*.pem)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(npm publish:*)",
      "Bash(docker:*)",
      "Bash(curl:*)"
    ],
    "defaultMode": "default"
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|Read|Edit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard.sh"
          }
        ]
      }
    ]
  }
}
#!/usr/bin/env bash
# .claude/hooks/guard.sh: PreToolUse guard. Exit code 2 blocks the tool call and shows the reason to the model.
# Requires jq. Make executable: chmod +x .claude/hooks/guard.sh
input=$(cat)
tool=$(printf '%s' "$input" | jq -r '.tool_name // empty')
cmd=$(printf '%s' "$input" | jq -r '.tool_input.command // empty')
path=$(printf '%s' "$input" | jq -r '.tool_input.file_path // .tool_input.path // empty')
if [ "$tool" = "Bash" ]; then
  if printf '%s' "$cmd" | grep -Eq '(^|[;&| ])(sudo|mkfs|dd if=)|rm -[a-zA-Z]*r[a-zA-Z]*f|rm -[a-zA-Z]*f[a-zA-Z]*r|git push .*(--force|-f( |$))|git reset --hard|git clean -[a-z]*f|curl[^|]*\|[[:space:]]*(ba)?sh|chmod 777'; then
    echo "Blocked by guard.sh: destructive command ($cmd). Ask the user to run it manually." >&2; exit 2
  fi
fi
if printf '%s %s' "$path" "$cmd" | grep -Eq '(^|/|[[:space:]])\.env($|\.|[[:space:]])|id_rsa|\.pem($|[[:space:]])|\.ssh/|\.aws/credentials'; then
  echo "Blocked by guard.sh: secrets file ($path$cmd)." >&2; exit 2
fi
exit 0
{
  "mcpServers": {
    "context7": {
      "type": "http",
      "url": "https://mcp.context7.com/mcp"
    }
  }
}
# AgentRigs starter: Mobile apps

Generated by https://agentrigs.dev/starters/mobile from real, well-guarded public rigs:
- https://github.com/pixel-cellar/Claude-Code-Game-Studios
- https://github.com/cassiewallace/dotfiles
- https://github.com/MysticalNobody/alatyr_flutter

## Install
1. Unzip into your repo root (`unzip -n` won't overwrite existing files).
2. `chmod +x .claude/hooks/guard.sh` (needs `jq`).
3. Fill in the <placeholders> in AGENTS.md.
4. Install the recommended skills (third-party code, so review first):

```bash
npx degit vercel-labs/agent-skills/skills/react-native-skills .claude/skills/vercel-react-native-skills
npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development
npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging
npx degit obra/superpowers/skills/verification-before-completion .claude/skills/verification-before-completion
```

Codex / Cursor / other harnesses read AGENTS.md directly; Claude Code reads CLAUDE.md, which imports AGENTS.md.

Recommended skills

test-driven-development used in 85 rigs · from obra/superpowers

Use when implementing any feature or bugfix, before writing implementation code

systematic-debugging used in 102 rigs · from obra/superpowers

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes

verification-before-completion used in 67 rigs · from obra/superpowers

Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence

Built from these rigs

The rules, permissions and hook pattern were distilled from well-guarded public rigs that match this use case (guardrail score ≥ 3, lean context):

Customised it? Paste your files into the Rig Doctor to re-check the tax and guardrails.

Other starters

copied ✓