DiegoOya/expense_tracker
Expense tracker MCP server built spec-first with Claude Code: hooks, skills, subagents and an honest log of what went wrong.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code $ claude mcp add --transport http github https://api.githubcopilot.com/mcp/ -H 'Authorization: YOUR_VALUE' $ npx degit DiegoOya/expense_tracker/.claude ./rig-expense_tracker # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add --transport http github https://api.githubcopilot.com/mcp/ -H 'Authorization: YOUR_VALUE' $ npx degit DiegoOya/expense_tracker/.claude/skills/add-mcp-tool .claude/skills/add-mcp-tool $ npx degit DiegoOya/expense_tracker/.claude/skills/write-spec .claude/skills/write-spec
$ curl -fsSL --create-dirs -o .claude/agents/spec-reviewer.md https://raw.githubusercontent.com/DiegoOya/expense_tracker/main/.claude/agents/spec-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/test-writer.md https://raw.githubusercontent.com/DiegoOya/expense_tracker/main/.claude/agents/test-writer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./secrets/**)",
"Edit(./.env)",
"Edit(./.env.*)",
"Edit(./secrets/**)",
"Bash(git push *)",
"Bash(git push)",
"Bash(rm -rf *)",
"Bash(curl *)",
"Bash(wget *)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "python3"
}
]
}
]
}
} MCP servers (2)
| server | source | est. tokens |
|---|---|---|
| expense-tracker env: EXPENSE_TRACKER_DB | local / custom | 2.5k |
| GitHub MCP · "github" | remote · remote | 18.0k |
Skills (2)
Subagents (2)
| spec-reviewer model: inherit | Independent read-only reviewer. Checks a spec for verifiable criteria, or a finished feature for spec compliance, test coverage per acceptance criterion and the domain purity rule. Use before committi |
| test-writer model: inherit | Writes pytest tests for a feature from its spec and plan only, without reading the implementation. Use in the red step of the SDD flow, before implementing a feature. |
Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | python3 |
| PostToolUse | Edit|Write | python3 |
| Stop | * | python3 |
Permissions
deny (11)
Read(./.env)
Read(./.env.*)
Read(./secrets/**)
Edit(./.env)
Edit(./.env.*)
Edit(./secrets/**)
Bash(git push *)
Bash(git push)
Bash(rm -rf *)
Bash(curl *)
Bash(wget *)
ask (0)
—
allow (17)
Bash(.venv/bin/pytest *)
Bash(.venv/bin/pytest)
Bash(.venv/bin/ruff *)
Bash(.venv/bin/mypy *)
Bash(.venv/bin/mypy)
Bash(.venv/bin/python scripts/check_specs.py)
Bash(git status *)
Bash(git status)
Bash(git diff *)
Bash(git diff)
Bash(git log *)
Bash(git add *)
Bash(git commit *)
Edit(./src/**)
Edit(./tests/**)
Edit(./specs/**)
Edit(./docs/**)
Similar rigs
lee-to/ai-workspace
AI Workspace - Give your AI agents memory that spans across projects.
Pragmatist 19.5k tok ·
heyong4725/claude-setup
Claude Code professional setup for Rust development
Pragmatist 19.1k tok ·
chewygumxx/zsh-config
My Zsh shell configuration dotfiles
Pragmatist 26.2k tok ·
heypoom/dotfiles
Poom's Neovim, Tmux, Fish and other configurations for macOS & Linux. Literally my entire world.
Pragmatist 24.3k tok ·