~ / rigs / AntoineMahe / claude-config

AntoineMahe/claude-config

minimal security settings for claude code

↗ GitHub ★ 1 GPL-3.0 updated 14d ago personal setup Claude Code
share on X
ARCHETYPE
Minimalist
Lean instructions, few tools, tiny context tax. Lets the model think.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Protects secrets · No YOLO mode · details

Copy this rig

$ git clone --depth 1 https://github.com/AntoineMahe/claude-config

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Edit(**/.env)",
      "Edit(**/.env.*)",
      "Bash(sudo:*)",
      "Read(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.local/share/keyrings/**)",
      "Read(~/.bash_history)"
    ]
  }
}

Permissions

deny (9)
Read(**/.env)
Read(**/.env.*)
Edit(**/.env)
Edit(**/.env.*)
Bash(sudo:*)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.local/share/keyrings/**)
Read(~/.bash_history)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓