~ / rigs / Anthonyhh / claude-code-power-user-kit

Anthonyhh/claude-code-power-user-kit

Production-ready Claude Code settings, security hooks, modularity enforcement & CLAUDE.md templates. 120 permissions, 20 deny rules, 17 OWASP patterns, 600-line hard limit. 5-minute setup.

↗ GitHub ★ 1 no license updated 6mo ago project Claude Code
share on X
ARCHETYPE
Minimalist
Lean instructions, few tools, tiny context tax. Lets the model think.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit Anthonyhh/claude-code-power-user-kit/.claude ./rig-claude-code-power-user-kit  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf /)",
      "Bash(rm -rf /*)",
      "Bash(rm -rf ~)",
      "Bash(rm -rf ~/*)",
      "Bash(git push --force origin main)",
      "Bash(git push --force origin master)",
      "Bash(git push -f origin main)",
      "Bash(git push -f origin master)",
      "Bash(git reset --hard)",
      "Bash(git clean -fdx)",
      "Bash(git checkout -- .)",
      "Bash(DROP TABLE:*)",
      "Bash(DROP DATABASE:*)",
      "Bash(TRUNCATE:*)",
      "Bash(chmod 777:*)",
      "Bash(chmod -R 777:*)",
      "Bash(:> /etc/*)",
      "Bash(mkfs:*)",
      "Bash(dd if=/dev/zero:*)",
      "Bash(:(){ :|:& };:)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Write",
        "hooks": [
          {
            "type": "command",
            "command": "node \".claude/hooks/pre-write-guard.js\""
          }
        ]
      }
    ]
  }
}

Hooks (3)

eventmatcherruns
PreToolUseWritenode ".claude/hooks/pre-write-guard.js"
PostToolUseWrite|Editnode ".claude/hooks/security-check.js"
PostToolUseWrite|Editnode ".claude/hooks/modularity-check.js"

Permissions

deny (20)
Bash(rm -rf /)
Bash(rm -rf /*)
Bash(rm -rf ~)
Bash(rm -rf ~/*)
Bash(git push --force origin main)
Bash(git push --force origin master)
Bash(git push -f origin main)
Bash(git push -f origin master)
Bash(git reset --hard)
Bash(git clean -fdx)
Bash(git checkout -- .)
Bash(DROP TABLE:*)
Bash(DROP DATABASE:*)
Bash(TRUNCATE:*)
Bash(chmod 777:*)
Bash(chmod -R 777:*)
Bash(:> /etc/*)
Bash(mkfs:*)
Bash(dd if=/dev/zero:*)
Bash(:(){ :|:& };:)
ask (0)
—
allow (120)
Read(*)
Edit(*)
Write(*)
Glob(*)
Grep(*)
WebFetch(*)
WebSearch(*)
NotebookEdit(*)
Agent(*)
Bash(pnpm:*)
Bash(npm:*)
Bash(npx:*)
Bash(yarn:*)
Bash(bun:*)
Bash(git:*)
Bash(node:*)
Bash(python:*)
Bash(python3:*)
Bash(pip:*)
Bash(pip3:*)
Bash(docker:*)
Bash(docker-compose:*)
Bash(ls:*)
Bash(cat:*)
Bash(head:*)
Bash(tail:*)
Bash(mkdir:*)
Bash(cp:*)
Bash(mv:*)
Bash(rm:*)
Bash(touch:*)
Bash(chmod:*)
Bash(chown:*)
Bash(tar:*)
Bash(zip:*)
Bash(unzip:*)
Bash(basename:*)
Bash(dirname:*)
Bash(realpath:*)
Bash(mktemp:*)
Bash(tee:*)
Bash(ln:*)
Bash(grep:*)
Bash(sort:*)
Bash(uniq:*)
Bash(wc:*)
Bash(diff:*)
Bash(sed:*)
Bash(awk:*)
Bash(tr:*)
Bash(cut:*)
Bash(xargs:*)
Bash(echo:*)
Bash(printf:*)
Bash(seq:*)
Bash(find:*)
Bash(findstr:*)
Bash(cd:*)
Bash(pwd:*)
Bash(which:*)

Similar rigs

copied ✓