~ / rigs / 0xAX / dotfiles

0xAX/dotfiles

A set of .emacs, .bash, git and other configuration files

↗ GitHub ★ 60 MIT updated 6d ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~173 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit 0xAX/dotfiles/.claude ./rig-dotfiles  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit 0xAX/dotfiles/.claude/skills/linux-insides .claude/skills/linux-insides
$ npx degit 0xAX/dotfiles/.claude/skills/ux330uak-hardware .claude/skills/ux330uak-hardware

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(sudo *)",
      "Bash(su *)",
      "Bash(rm -rf /*)",
      "Bash(rm -rf ~*)",
      "Bash(rm -rf $HOME*)",
      "Bash(rm -rf .*)",
      "Bash(rm -rf ../*)",
      "Bash(chmod 777 *)",
      "Bash(chmod -R 777 *)",
      "Bash(dd *)",
      "Bash(env)",
      "Bash(mkfs *)",
      "Bash(shutdown *)",
      "Bash(reboot *)",
      "Bash(launchctl *)",
      "Bash(defaults *)",
      "Bash(nvram *)",
      "Bash(scutil *)",
      "Bash(pfctl *)",
      "Bash(softwareupdate *)",
      "Read(**/.env)",
      "Edit(**/.env)",
      "Read(**/.env.*)",
      "Edit(**/.env.*)",
      "Read(**/*.pem)",
      "Edit(**/*.pem)",
      "Read(**/*.key)",
      "Edit(**/*.key)",
      "Read(**/*.pfx)",
      "Edit(**/*.pfx)",
      "Read(**/*.p12)",
      "Edit(**/*.p12)",
      "Read(**/id_rsa)",
      "Edit(**/id_rsa)",
      "Read(**/id_ed25519)",
      "Edit(**/id_ed25519)",
      "Read(**/id_ecdsa)",
      "Edit(**/id_ecdsa)",
      "Read(~/.ssh/**)",
      "Edit(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Edit(~/.gnupg/**)",
      "Read(~/.aws/credentials)",
      "Edit(~/.aws/credentials)",
      "Read(~/.aws/config)",
      "Edit(~/.aws/config)",
      "Read(~/.docker/config.json)",
      "Edit(~/.docker/config.json)",
      "Read(~/.config/gh/hosts.yml)",
      "Edit(~/.config/gh/hosts.yml)",
      "Read(~/.netrc)",
      "Edit(~/.netrc)",
      "Read(~/.pgpass)",
      "Edit(~/.pgpass)",
      "Read(~/.npmrc)",
      "Edit(~/.npmrc)",
      "Read(~/Library/Keychains/**)",
      "Edit(~/Library/Keychains/**)",
      "Read(~/.pypirc)",
      "Edit(~/.pypirc)",
      "Read(~/.cargo/credentials)",
      "Edit(~/.cargo/credentials)",
      "Read(~/.gem/credentials)",
      "Edit(~/.gem/credentials)"
    ],
    "ask": [
      "Bash(sudo dnf:*)",
      "Bash(cargo install:*)",
      "Bash(cargo uninstall:*)",
      "Bash(cargo publish:*)",
      "Bash(curl *)",
      "Bash(gh auth:*)",
      "Bash(gh pr close:*)",
      "Bash(gh pr merge:*)",
      "Bash(gh release create:*)",
      "Bash(gh release delete:*)",
      "Bash(gh repo create:*)",
      "Bash(gh repo delete:*)",
      "Bash(gh repo rename:*)",
      "Bash(gh ssh-key:*)",
      "Bash(git branch -D:*)",
      "Bash(git branch -d:*)",
      "Bash(git clean:*)",
      "Bash(git commit --amend:*)",
      "Bash(git rebase:*)",
      "Bash(git reflog expire:*)",
      "Bash(git reset:*)",
      "Bash(git tag -d:*)",
      "Bash(git -C * branch -D *)",
      "Bash(git -C * branch -d *)",
      "Bash(git -C * clean *)",
      "Bash(git -C * commit --amend *)",
      "Bash(git -C * rebase *)",
      "Bash(git -C * reflog expire *)",
      "Bash(git -C * reset *)",
      "Bash(git -C * tag -d *)",
      "Bash(npm audit fix:*)",
      "Bash(npm install:*)",
      "Bash(npm i:*)",
      "Bash(npm link:*)",
      "Bash(npm publish:*)",
      "Bash(npm rm:*)",
      "Bash(npm uninstall:*)",
      "Bash(npm update:*)",
      "Bash(open *)",
      "Bash(pnpm add:*)",
      "Bash(pnpm remove:*)",
      "Bash(pnpm update:*)",
      "Bash(pnpm publish:*)",
      "Bash(pnpm link:*)",
      "Bash(psql *)",
      "Bash(mysql *)",
      "Bash(nats *)",
      "Bash(redis-cli *)",
      "Bash(rm *)",
      "Bash(rmdir *)",
      "Bash(rustup update:*)",
      "Bash(rustup install:*)",
      "Bash(wget *)"
    ]
  }
}

Skills (2)

Plugins (3)

docs@cennso-aidocs-private@cennso-aigopls-lsp@claude-plugins-official

Permissions

deny (64)
Bash(sudo *)
Bash(su *)
Bash(rm -rf /*)
Bash(rm -rf ~*)
Bash(rm -rf $HOME*)
Bash(rm -rf .*)
Bash(rm -rf ../*)
Bash(chmod 777 *)
Bash(chmod -R 777 *)
Bash(dd *)
Bash(env)
Bash(mkfs *)
Bash(shutdown *)
Bash(reboot *)
Bash(launchctl *)
Bash(defaults *)
Bash(nvram *)
Bash(scutil *)
Bash(pfctl *)
Bash(softwareupdate *)
Read(**/.env)
Edit(**/.env)
Read(**/.env.*)
Edit(**/.env.*)
Read(**/*.pem)
Edit(**/*.pem)
Read(**/*.key)
Edit(**/*.key)
Read(**/*.pfx)
Edit(**/*.pfx)
Read(**/*.p12)
Edit(**/*.p12)
Read(**/id_rsa)
Edit(**/id_rsa)
Read(**/id_ed25519)
Edit(**/id_ed25519)
Read(**/id_ecdsa)
Edit(**/id_ecdsa)
Read(~/.ssh/**)
Edit(~/.ssh/**)
Read(~/.gnupg/**)
Edit(~/.gnupg/**)
Read(~/.aws/credentials)
Edit(~/.aws/credentials)
Read(~/.aws/config)
Edit(~/.aws/config)
Read(~/.docker/config.json)
Edit(~/.docker/config.json)
Read(~/.config/gh/hosts.yml)
Edit(~/.config/gh/hosts.yml)
Read(~/.netrc)
Edit(~/.netrc)
Read(~/.pgpass)
Edit(~/.pgpass)
Read(~/.npmrc)
Edit(~/.npmrc)
Read(~/Library/Keychains/**)
Edit(~/Library/Keychains/**)
Read(~/.pypirc)
Edit(~/.pypirc)
ask (53)
Bash(sudo dnf:*)
Bash(cargo install:*)
Bash(cargo uninstall:*)
Bash(cargo publish:*)
Bash(curl *)
Bash(gh auth:*)
Bash(gh pr close:*)
Bash(gh pr merge:*)
Bash(gh release create:*)
Bash(gh release delete:*)
Bash(gh repo create:*)
Bash(gh repo delete:*)
Bash(gh repo rename:*)
Bash(gh ssh-key:*)
Bash(git branch -D:*)
Bash(git branch -d:*)
Bash(git clean:*)
Bash(git commit --amend:*)
Bash(git rebase:*)
Bash(git reflog expire:*)
Bash(git reset:*)
Bash(git tag -d:*)
Bash(git -C * branch -D *)
Bash(git -C * branch -d *)
Bash(git -C * clean *)
Bash(git -C * commit --amend *)
Bash(git -C * rebase *)
Bash(git -C * reflog expire *)
Bash(git -C * reset *)
Bash(git -C * tag -d *)
Bash(npm audit fix:*)
Bash(npm install:*)
Bash(npm i:*)
Bash(npm link:*)
Bash(npm publish:*)
Bash(npm rm:*)
Bash(npm uninstall:*)
Bash(npm update:*)
Bash(open *)
Bash(pnpm add:*)
Bash(pnpm remove:*)
Bash(pnpm update:*)
Bash(pnpm publish:*)
Bash(pnpm link:*)
Bash(psql *)
Bash(mysql *)
Bash(nats *)
Bash(redis-cli *)
Bash(rm *)
Bash(rmdir *)
Bash(rustup update:*)
Bash(rustup install:*)
Bash(wget *)
allow (0)
—

Similar rigs

copied ✓