0xAX/dotfiles
A set of .emacs, .bash, git and other configuration files
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit 0xAX/dotfiles/.claude ./rig-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit 0xAX/dotfiles/.claude/skills/linux-insides .claude/skills/linux-insides $ npx degit 0xAX/dotfiles/.claude/skills/ux330uak-hardware .claude/skills/ux330uak-hardware
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(sudo *)",
"Bash(su *)",
"Bash(rm -rf /*)",
"Bash(rm -rf ~*)",
"Bash(rm -rf $HOME*)",
"Bash(rm -rf .*)",
"Bash(rm -rf ../*)",
"Bash(chmod 777 *)",
"Bash(chmod -R 777 *)",
"Bash(dd *)",
"Bash(env)",
"Bash(mkfs *)",
"Bash(shutdown *)",
"Bash(reboot *)",
"Bash(launchctl *)",
"Bash(defaults *)",
"Bash(nvram *)",
"Bash(scutil *)",
"Bash(pfctl *)",
"Bash(softwareupdate *)",
"Read(**/.env)",
"Edit(**/.env)",
"Read(**/.env.*)",
"Edit(**/.env.*)",
"Read(**/*.pem)",
"Edit(**/*.pem)",
"Read(**/*.key)",
"Edit(**/*.key)",
"Read(**/*.pfx)",
"Edit(**/*.pfx)",
"Read(**/*.p12)",
"Edit(**/*.p12)",
"Read(**/id_rsa)",
"Edit(**/id_rsa)",
"Read(**/id_ed25519)",
"Edit(**/id_ed25519)",
"Read(**/id_ecdsa)",
"Edit(**/id_ecdsa)",
"Read(~/.ssh/**)",
"Edit(~/.ssh/**)",
"Read(~/.gnupg/**)",
"Edit(~/.gnupg/**)",
"Read(~/.aws/credentials)",
"Edit(~/.aws/credentials)",
"Read(~/.aws/config)",
"Edit(~/.aws/config)",
"Read(~/.docker/config.json)",
"Edit(~/.docker/config.json)",
"Read(~/.config/gh/hosts.yml)",
"Edit(~/.config/gh/hosts.yml)",
"Read(~/.netrc)",
"Edit(~/.netrc)",
"Read(~/.pgpass)",
"Edit(~/.pgpass)",
"Read(~/.npmrc)",
"Edit(~/.npmrc)",
"Read(~/Library/Keychains/**)",
"Edit(~/Library/Keychains/**)",
"Read(~/.pypirc)",
"Edit(~/.pypirc)",
"Read(~/.cargo/credentials)",
"Edit(~/.cargo/credentials)",
"Read(~/.gem/credentials)",
"Edit(~/.gem/credentials)"
],
"ask": [
"Bash(sudo dnf:*)",
"Bash(cargo install:*)",
"Bash(cargo uninstall:*)",
"Bash(cargo publish:*)",
"Bash(curl *)",
"Bash(gh auth:*)",
"Bash(gh pr close:*)",
"Bash(gh pr merge:*)",
"Bash(gh release create:*)",
"Bash(gh release delete:*)",
"Bash(gh repo create:*)",
"Bash(gh repo delete:*)",
"Bash(gh repo rename:*)",
"Bash(gh ssh-key:*)",
"Bash(git branch -D:*)",
"Bash(git branch -d:*)",
"Bash(git clean:*)",
"Bash(git commit --amend:*)",
"Bash(git rebase:*)",
"Bash(git reflog expire:*)",
"Bash(git reset:*)",
"Bash(git tag -d:*)",
"Bash(git -C * branch -D *)",
"Bash(git -C * branch -d *)",
"Bash(git -C * clean *)",
"Bash(git -C * commit --amend *)",
"Bash(git -C * rebase *)",
"Bash(git -C * reflog expire *)",
"Bash(git -C * reset *)",
"Bash(git -C * tag -d *)",
"Bash(npm audit fix:*)",
"Bash(npm install:*)",
"Bash(npm i:*)",
"Bash(npm link:*)",
"Bash(npm publish:*)",
"Bash(npm rm:*)",
"Bash(npm uninstall:*)",
"Bash(npm update:*)",
"Bash(open *)",
"Bash(pnpm add:*)",
"Bash(pnpm remove:*)",
"Bash(pnpm update:*)",
"Bash(pnpm publish:*)",
"Bash(pnpm link:*)",
"Bash(psql *)",
"Bash(mysql *)",
"Bash(nats *)",
"Bash(redis-cli *)",
"Bash(rm *)",
"Bash(rmdir *)",
"Bash(rustup update:*)",
"Bash(rustup install:*)",
"Bash(wget *)"
]
}
} Skills (2)
Plugins (3)
docs@cennso-aidocs-private@cennso-aigopls-lsp@claude-plugins-official
Permissions
deny (64)
Bash(sudo *)
Bash(su *)
Bash(rm -rf /*)
Bash(rm -rf ~*)
Bash(rm -rf $HOME*)
Bash(rm -rf .*)
Bash(rm -rf ../*)
Bash(chmod 777 *)
Bash(chmod -R 777 *)
Bash(dd *)
Bash(env)
Bash(mkfs *)
Bash(shutdown *)
Bash(reboot *)
Bash(launchctl *)
Bash(defaults *)
Bash(nvram *)
Bash(scutil *)
Bash(pfctl *)
Bash(softwareupdate *)
Read(**/.env)
Edit(**/.env)
Read(**/.env.*)
Edit(**/.env.*)
Read(**/*.pem)
Edit(**/*.pem)
Read(**/*.key)
Edit(**/*.key)
Read(**/*.pfx)
Edit(**/*.pfx)
Read(**/*.p12)
Edit(**/*.p12)
Read(**/id_rsa)
Edit(**/id_rsa)
Read(**/id_ed25519)
Edit(**/id_ed25519)
Read(**/id_ecdsa)
Edit(**/id_ecdsa)
Read(~/.ssh/**)
Edit(~/.ssh/**)
Read(~/.gnupg/**)
Edit(~/.gnupg/**)
Read(~/.aws/credentials)
Edit(~/.aws/credentials)
Read(~/.aws/config)
Edit(~/.aws/config)
Read(~/.docker/config.json)
Edit(~/.docker/config.json)
Read(~/.config/gh/hosts.yml)
Edit(~/.config/gh/hosts.yml)
Read(~/.netrc)
Edit(~/.netrc)
Read(~/.pgpass)
Edit(~/.pgpass)
Read(~/.npmrc)
Edit(~/.npmrc)
Read(~/Library/Keychains/**)
Edit(~/Library/Keychains/**)
Read(~/.pypirc)
Edit(~/.pypirc)
ask (53)
Bash(sudo dnf:*)
Bash(cargo install:*)
Bash(cargo uninstall:*)
Bash(cargo publish:*)
Bash(curl *)
Bash(gh auth:*)
Bash(gh pr close:*)
Bash(gh pr merge:*)
Bash(gh release create:*)
Bash(gh release delete:*)
Bash(gh repo create:*)
Bash(gh repo delete:*)
Bash(gh repo rename:*)
Bash(gh ssh-key:*)
Bash(git branch -D:*)
Bash(git branch -d:*)
Bash(git clean:*)
Bash(git commit --amend:*)
Bash(git rebase:*)
Bash(git reflog expire:*)
Bash(git reset:*)
Bash(git tag -d:*)
Bash(git -C * branch -D *)
Bash(git -C * branch -d *)
Bash(git -C * clean *)
Bash(git -C * commit --amend *)
Bash(git -C * rebase *)
Bash(git -C * reflog expire *)
Bash(git -C * reset *)
Bash(git -C * tag -d *)
Bash(npm audit fix:*)
Bash(npm install:*)
Bash(npm i:*)
Bash(npm link:*)
Bash(npm publish:*)
Bash(npm rm:*)
Bash(npm uninstall:*)
Bash(npm update:*)
Bash(open *)
Bash(pnpm add:*)
Bash(pnpm remove:*)
Bash(pnpm update:*)
Bash(pnpm publish:*)
Bash(pnpm link:*)
Bash(psql *)
Bash(mysql *)
Bash(nats *)
Bash(redis-cli *)
Bash(rm *)
Bash(rmdir *)
Bash(rustup update:*)
Bash(rustup install:*)
Bash(wget *)
allow (0)
—
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·