0xM3R/secure-claude-config
Hardened Claude Code configuration: permission deny-lists, credential/wallet protection, secretless GitHub MCP wrapper, and a context-aware statusline.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit 0xM3R/secure-claude-config/hooks ./rig-secure-claude-config/hooks MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf *)",
"Bash(rm -fr *)",
"Bash(rm -Rf *)",
"Bash(rm -fR *)",
"Bash(sudo *)",
"Bash(mkfs *)",
"Bash(dd if=*)",
"Bash(shred *)",
"Bash(wget *|bash*)",
"Bash(wget *| bash*)",
"Bash(wget *|sh*)",
"Bash(wget *| sh*)",
"Bash(curl *|bash*)",
"Bash(curl *| bash*)",
"Bash(curl *|sh*)",
"Bash(curl *| sh*)",
"Bash(curl *|zsh*)",
"Bash(curl *| zsh*)",
"Bash(nc *)",
"Bash(ncat *)",
"Bash(netcat *)",
"Bash(eval *)",
"Bash(crontab *)",
"Bash(chmod +s *)",
"Bash(chmod 777 *)",
"Bash(chown root*)",
"Bash(git push --force*)",
"Bash(git push *--force*)",
"Bash(git reset --hard*)",
"Bash(history -c*)",
"Bash(unset HISTFILE*)",
"Edit(~/.bashrc)",
"Edit(~/.zshrc)",
"Edit(~/.profile)",
"Edit(~/.bash_profile)",
"Edit(~/.zprofile)",
"Edit(~/.ssh/**)",
"Edit(~/.gnupg/**)",
"Read(~/.ssh/**)",
"Read(~/.gnupg/**)",
"Read(~/.aws/**)",
"Read(~/.azure/**)",
"Read(~/.config/gh/**)",
"Read(~/.config/gcloud/**)",
"Read(~/.config/op/**)",
"Read(~/.git-credentials)",
"Read(~/.netrc)",
"Read(~/.vault-token)",
"Read(~/.docker/config.json)",
"Read(~/.kube/**)",
"Read(~/.npmrc)",
"Read(~/.npm/**)",
"Read(~/.pypirc)",
"Read(~/.gem/credentials)",
"Read(~/.terraform.d/**)",
"Read(~/Library/Keychains/**)",
"Read(~/Library/Application Support/**/metamask*/**)",
"Read(~/Library/Application Support/**/electrum*/**)",
"Read(~/Library/Application Support/**/exodus*/**)",
"Read(~/Library/Application Support/**/phantom*/**)",
"Read(~/Library/Application Support/**/solflare*/**)",
"Read(~/Library/Application Support/**/frame*/**)",
"Read(~/Library/Application Support/**/rainbow*/**)",
"Read(~/Library/Application Support/**/ledger*/**)",
"Read(~/Library/Application Support/**/trezor*/**)",
"Read(~/Library/Application Support/**/1password*/**)",
"Read(~/Library/Application Support/**/bitwarden*/**)",
"Read(~/Library/Application Support/**/keybase*/**)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo \"$CMD\" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo \"$CMD\" | grep -"
},
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi"
},
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(curl|wget|fetch)[[:space:]].*[|][[:space:]]*(bash|sh|zsh|ksh|fish|python[0-9.]?|node|perl|ruby)'; then echo 'BLOCKED: pipe-to-shell download pattern detected' >&2; exit 2; fi"
},
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE 'base64[[:space:]]+(--decode|-d)[[:space:]]*[|]|[|][[:space:]]*base64[[:space:]]+(--decode|-d).*[|]'; then echo 'BLOCKED: base64-decode-pipe pattern detected' >&2; exit 2; fi"
},
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(unset[[:space:]]+HISTFILE|history[[:space:]]+-[cw]|export[[:space:]]+HISTFILE=/dev/null)'; then echo 'BLOCKED: history-suppression pattern detected' >&2; exit 2; fi"
}
]
}
]
}
} MCP servers (1)
| server | source | est. tokens |
|---|---|---|
| github | local / custom | 2.5k |
Hooks (6)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo "$CMD" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo "$CMD" | grep - |
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi |
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(curl|wget|fetch)[[:space:]].*[|][[:space:]]*(bash|sh|zsh|ksh|fish|python[0-9.]?|node|perl|ruby)'; then echo 'BLOCKED: pipe-to-shell download pattern detected' >&2; exit 2; fi |
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE 'base64[[:space:]]+(--decode|-d)[[:space:]]*[|]|[|][[:space:]]*base64[[:space:]]+(--decode|-d).*[|]'; then echo 'BLOCKED: base64-decode-pipe pattern detected' >&2; exit 2; fi |
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(unset[[:space:]]+HISTFILE|history[[:space:]]+-[cw]|export[[:space:]]+HISTFILE=/dev/null)'; then echo 'BLOCKED: history-suppression pattern detected' >&2; exit 2; fi |
| SessionStart | * | $HOME/.claude/hooks/context-mode-cache-heal.mjs |
Plugins (4)
security-guidance@claude-plugins-officialgopls-lsp@claude-plugins-officialandrej-karpathy-skills@karpathy-skillscontext-mode@context-mode
Permissions
deny (68)
Bash(rm -rf *)
Bash(rm -fr *)
Bash(rm -Rf *)
Bash(rm -fR *)
Bash(sudo *)
Bash(mkfs *)
Bash(dd if=*)
Bash(shred *)
Bash(wget *|bash*)
Bash(wget *| bash*)
Bash(wget *|sh*)
Bash(wget *| sh*)
Bash(curl *|bash*)
Bash(curl *| bash*)
Bash(curl *|sh*)
Bash(curl *| sh*)
Bash(curl *|zsh*)
Bash(curl *| zsh*)
Bash(nc *)
Bash(ncat *)
Bash(netcat *)
Bash(eval *)
Bash(crontab *)
Bash(chmod +s *)
Bash(chmod 777 *)
Bash(chown root*)
Bash(git push --force*)
Bash(git push *--force*)
Bash(git reset --hard*)
Bash(history -c*)
Bash(unset HISTFILE*)
Edit(~/.bashrc)
Edit(~/.zshrc)
Edit(~/.profile)
Edit(~/.bash_profile)
Edit(~/.zprofile)
Edit(~/.ssh/**)
Edit(~/.gnupg/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.config/gh/**)
Read(~/.config/gcloud/**)
Read(~/.config/op/**)
Read(~/.git-credentials)
Read(~/.netrc)
Read(~/.vault-token)
Read(~/.docker/config.json)
Read(~/.kube/**)
Read(~/.npmrc)
Read(~/.npm/**)
Read(~/.pypirc)
Read(~/.gem/credentials)
Read(~/.terraform.d/**)
Read(~/Library/Keychains/**)
Read(~/Library/Application Support/**/metamask*/**)
Read(~/Library/Application Support/**/electrum*/**)
Read(~/Library/Application Support/**/exodus*/**)
Read(~/Library/Application Support/**/phantom*/**)
ask (0)
—
allow (0)
—
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·