Droidzold/hardened-security-config
Hardened PreToolUse hooks for Claude Code, Cursor, and OpenClaw. Blocks pipe-to-shell, reverse shells, credential exfil, and destructive commands. Because settings.json deny rules have been broken across 4 versions.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit Droidzold/hardened-security-config/.claude ./rig-hardened-security-config # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf *)",
"Bash(rm -rf /)",
"Bash(rm -rf ~*)",
"Bash(rm -rf $HOME*)",
"Bash(rm -rf ./*)",
"Bash(rm -rf ../*)",
"Bash(sudo rm *)",
"Bash(chmod 777 *)",
"Bash(chmod -R 777 *)",
"Bash(curl * | bash*)",
"Bash(curl * | sh*)",
"Bash(wget * | bash*)",
"Bash(wget * | sh*)",
"Bash(curl *| bash*)",
"Bash(curl *| sh*)",
"Bash(wget *| sh*)",
"Bash(cat */.env*)",
"Bash(cat */.ssh/*)",
"Bash(cat */.aws/*)",
"Bash(cat */.gnupg/*)",
"Bash(cat *credentials*)",
"Bash(cat *secret*)",
"Bash(cat */token*)",
"Bash(cat */.anthropic*)",
"Bash(cat */.openai*)",
"Bash(cat */.config/gh/*)",
"Bash(echo $ANTHROPIC_API_KEY*)",
"Bash(echo $OPENAI_API_KEY*)",
"Bash(echo $AWS_SECRET*)",
"Bash(echo $GITHUB_TOKEN*)",
"Bash(echo $STRIPE_SECRET*)",
"Bash(printenv*)",
"Bash(env | *)",
"Bash(set | *)",
"Bash(git push * --force*)",
"Bash(git push *-f *)",
"Bash(git reset --hard*)",
"Bash(git clean -fdx*)",
"Bash(docker run *--privileged*)",
"Bash(docker run *-v /:/host*)",
"Read(**/.env)",
"Read(**/.env.*)",
"Read(**/.env.local)",
"Read(**/.env.production*)",
"Read(**/.env.staging*)",
"Read(**/*secret*)",
"Read(**/.ssh/*)",
"Read(**/.aws/*)",
"Read(**/.gnupg/*)",
"Read(**/.anthropic*)",
"Read(**/.openai*)",
"Edit(**/.env)",
"Edit(**/.env.*)",
"Edit(**/.env.local)",
"Edit(**/.env.production*)",
"Edit(**/.env.staging*)",
"Write(**/.env)",
"Write(**/.env.*)",
"Write(**/.env.local)",
"Write(**/.env.production*)",
"Write(**/.env.staging*)"
],
"ask": [
"Bash(git push *)",
"Bash(npm publish*)",
"Bash(npx *)",
"Bash(pip install *)",
"Bash(brew install *)",
"Bash(apt install *)",
"Bash(curl *)",
"Bash(wget *)",
"WebFetch(*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/bash-firewall.sh"
}
]
},
{
"matcher": "Read|Edit|Write|MultiEdit",
"hooks": [
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.claude/hooks/file-guard.sh"
}
]
}
]
}
} Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | $CLAUDE_PROJECT_DIR/.claude/hooks/bash-firewall.sh |
| PreToolUse | Read|Edit|Write|MultiEdit | $CLAUDE_PROJECT_DIR/.claude/hooks/file-guard.sh |
| PostToolUse | Bash|Edit|Write|MultiEdit|WebFetch | $CLAUDE_PROJECT_DIR/.claude/hooks/audit-log.sh |
Permissions
deny (61)
Bash(rm -rf *)
Bash(rm -rf /)
Bash(rm -rf ~*)
Bash(rm -rf $HOME*)
Bash(rm -rf ./*)
Bash(rm -rf ../*)
Bash(sudo rm *)
Bash(chmod 777 *)
Bash(chmod -R 777 *)
Bash(curl * | bash*)
Bash(curl * | sh*)
Bash(wget * | bash*)
Bash(wget * | sh*)
Bash(curl *| bash*)
Bash(curl *| sh*)
Bash(wget *| sh*)
Bash(cat */.env*)
Bash(cat */.ssh/*)
Bash(cat */.aws/*)
Bash(cat */.gnupg/*)
Bash(cat *credentials*)
Bash(cat *secret*)
Bash(cat */token*)
Bash(cat */.anthropic*)
Bash(cat */.openai*)
Bash(cat */.config/gh/*)
Bash(echo $ANTHROPIC_API_KEY*)
Bash(echo $OPENAI_API_KEY*)
Bash(echo $AWS_SECRET*)
Bash(echo $GITHUB_TOKEN*)
Bash(echo $STRIPE_SECRET*)
Bash(printenv*)
Bash(env | *)
Bash(set | *)
Bash(git push * --force*)
Bash(git push *-f *)
Bash(git reset --hard*)
Bash(git clean -fdx*)
Bash(docker run *--privileged*)
Bash(docker run *-v /:/host*)
Read(**/.env)
Read(**/.env.*)
Read(**/.env.local)
Read(**/.env.production*)
Read(**/.env.staging*)
Read(**/*secret*)
Read(**/.ssh/*)
Read(**/.aws/*)
Read(**/.gnupg/*)
Read(**/.anthropic*)
Read(**/.openai*)
Edit(**/.env)
Edit(**/.env.*)
Edit(**/.env.local)
Edit(**/.env.production*)
Edit(**/.env.staging*)
Write(**/.env)
Write(**/.env.*)
Write(**/.env.local)
Write(**/.env.production*)
ask (9)
Bash(git push *)
Bash(npm publish*)
Bash(npx *)
Bash(pip install *)
Bash(brew install *)
Bash(apt install *)
Bash(curl *)
Bash(wget *)
WebFetch(*)
allow (0)
—
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·