~ / rigs / DiegoOya / expense_tracker

DiegoOya/expense_tracker

Expense tracker MCP server built spec-first with Claude Code: hooks, skills, subagents and an honest log of what went wrong.

↗ GitHub ★ 0 MIT updated today project Claude CodeCodex
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~21.5k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add --transport http github https://api.githubcopilot.com/mcp/ -H 'Authorization: YOUR_VALUE'
$ npx degit DiegoOya/expense_tracker/.claude ./rig-expense_tracker  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add --transport http github https://api.githubcopilot.com/mcp/ -H 'Authorization: YOUR_VALUE'
$ npx degit DiegoOya/expense_tracker/.claude/skills/add-mcp-tool .claude/skills/add-mcp-tool
$ npx degit DiegoOya/expense_tracker/.claude/skills/write-spec .claude/skills/write-spec
$ curl -fsSL --create-dirs -o .claude/agents/spec-reviewer.md https://raw.githubusercontent.com/DiegoOya/expense_tracker/main/.claude/agents/spec-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/test-writer.md https://raw.githubusercontent.com/DiegoOya/expense_tracker/main/.claude/agents/test-writer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Edit(./.env)",
      "Edit(./.env.*)",
      "Edit(./secrets/**)",
      "Bash(git push *)",
      "Bash(git push)",
      "Bash(rm -rf *)",
      "Bash(curl *)",
      "Bash(wget *)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "python3"
          }
        ]
      }
    ]
  }
}

MCP servers (2)

serversourceest. tokens
expense-tracker
env: EXPENSE_TRACKER_DB
local / custom 2.5k
GitHub MCP · "github" remote · remote 18.0k

Skills (2)

Subagents (2)

spec-reviewer
model: inherit
Independent read-only reviewer. Checks a spec for verifiable criteria, or a finished feature for spec compliance, test coverage per acceptance criterion and the domain purity rule. Use before committi
test-writer
model: inherit
Writes pytest tests for a feature from its spec and plan only, without reading the implementation. Use in the red step of the SDD flow, before implementing a feature.

Hooks (3)

eventmatcherruns
PreToolUseBashpython3
PostToolUseEdit|Writepython3
Stop*python3

Permissions

deny (11)
Read(./.env)
Read(./.env.*)
Read(./secrets/**)
Edit(./.env)
Edit(./.env.*)
Edit(./secrets/**)
Bash(git push *)
Bash(git push)
Bash(rm -rf *)
Bash(curl *)
Bash(wget *)
ask (0)
—
allow (17)
Bash(.venv/bin/pytest *)
Bash(.venv/bin/pytest)
Bash(.venv/bin/ruff *)
Bash(.venv/bin/mypy *)
Bash(.venv/bin/mypy)
Bash(.venv/bin/python scripts/check_specs.py)
Bash(git status *)
Bash(git status)
Bash(git diff *)
Bash(git diff)
Bash(git log *)
Bash(git add *)
Bash(git commit *)
Edit(./src/**)
Edit(./tests/**)
Edit(./specs/**)
Edit(./docs/**)

Similar rigs

copied ✓