~ / rigs / Droidzold / hardened-security-config

Droidzold/hardened-security-config

Hardened PreToolUse hooks for Claude Code, Cursor, and OpenClaw. Blocks pipe-to-shell, reverse shells, credential exfil, and destructive commands. Because settings.json deny rules have been broken across 4 versions.

↗ GitHub ★ 0 no license updated 6mo ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~792 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit Droidzold/hardened-security-config/.claude ./rig-hardened-security-config  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf *)",
      "Bash(rm -rf /)",
      "Bash(rm -rf ~*)",
      "Bash(rm -rf $HOME*)",
      "Bash(rm -rf ./*)",
      "Bash(rm -rf ../*)",
      "Bash(sudo rm *)",
      "Bash(chmod 777 *)",
      "Bash(chmod -R 777 *)",
      "Bash(curl * | bash*)",
      "Bash(curl * | sh*)",
      "Bash(wget * | bash*)",
      "Bash(wget * | sh*)",
      "Bash(curl *| bash*)",
      "Bash(curl *| sh*)",
      "Bash(wget *| sh*)",
      "Bash(cat */.env*)",
      "Bash(cat */.ssh/*)",
      "Bash(cat */.aws/*)",
      "Bash(cat */.gnupg/*)",
      "Bash(cat *credentials*)",
      "Bash(cat *secret*)",
      "Bash(cat */token*)",
      "Bash(cat */.anthropic*)",
      "Bash(cat */.openai*)",
      "Bash(cat */.config/gh/*)",
      "Bash(echo $ANTHROPIC_API_KEY*)",
      "Bash(echo $OPENAI_API_KEY*)",
      "Bash(echo $AWS_SECRET*)",
      "Bash(echo $GITHUB_TOKEN*)",
      "Bash(echo $STRIPE_SECRET*)",
      "Bash(printenv*)",
      "Bash(env | *)",
      "Bash(set | *)",
      "Bash(git push * --force*)",
      "Bash(git push *-f *)",
      "Bash(git reset --hard*)",
      "Bash(git clean -fdx*)",
      "Bash(docker run *--privileged*)",
      "Bash(docker run *-v /:/host*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/.env.local)",
      "Read(**/.env.production*)",
      "Read(**/.env.staging*)",
      "Read(**/*secret*)",
      "Read(**/.ssh/*)",
      "Read(**/.aws/*)",
      "Read(**/.gnupg/*)",
      "Read(**/.anthropic*)",
      "Read(**/.openai*)",
      "Edit(**/.env)",
      "Edit(**/.env.*)",
      "Edit(**/.env.local)",
      "Edit(**/.env.production*)",
      "Edit(**/.env.staging*)",
      "Write(**/.env)",
      "Write(**/.env.*)",
      "Write(**/.env.local)",
      "Write(**/.env.production*)",
      "Write(**/.env.staging*)"
    ],
    "ask": [
      "Bash(git push *)",
      "Bash(npm publish*)",
      "Bash(npx *)",
      "Bash(pip install *)",
      "Bash(brew install *)",
      "Bash(apt install *)",
      "Bash(curl *)",
      "Bash(wget *)",
      "WebFetch(*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/bash-firewall.sh"
          }
        ]
      },
      {
        "matcher": "Read|Edit|Write|MultiEdit",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/file-guard.sh"
          }
        ]
      }
    ]
  }
}

Hooks (3)

eventmatcherruns
PreToolUseBash$CLAUDE_PROJECT_DIR/.claude/hooks/bash-firewall.sh
PreToolUseRead|Edit|Write|MultiEdit$CLAUDE_PROJECT_DIR/.claude/hooks/file-guard.sh
PostToolUseBash|Edit|Write|MultiEdit|WebFetch$CLAUDE_PROJECT_DIR/.claude/hooks/audit-log.sh

Permissions

deny (61)
Bash(rm -rf *)
Bash(rm -rf /)
Bash(rm -rf ~*)
Bash(rm -rf $HOME*)
Bash(rm -rf ./*)
Bash(rm -rf ../*)
Bash(sudo rm *)
Bash(chmod 777 *)
Bash(chmod -R 777 *)
Bash(curl * | bash*)
Bash(curl * | sh*)
Bash(wget * | bash*)
Bash(wget * | sh*)
Bash(curl *| bash*)
Bash(curl *| sh*)
Bash(wget *| sh*)
Bash(cat */.env*)
Bash(cat */.ssh/*)
Bash(cat */.aws/*)
Bash(cat */.gnupg/*)
Bash(cat *credentials*)
Bash(cat *secret*)
Bash(cat */token*)
Bash(cat */.anthropic*)
Bash(cat */.openai*)
Bash(cat */.config/gh/*)
Bash(echo $ANTHROPIC_API_KEY*)
Bash(echo $OPENAI_API_KEY*)
Bash(echo $AWS_SECRET*)
Bash(echo $GITHUB_TOKEN*)
Bash(echo $STRIPE_SECRET*)
Bash(printenv*)
Bash(env | *)
Bash(set | *)
Bash(git push * --force*)
Bash(git push *-f *)
Bash(git reset --hard*)
Bash(git clean -fdx*)
Bash(docker run *--privileged*)
Bash(docker run *-v /:/host*)
Read(**/.env)
Read(**/.env.*)
Read(**/.env.local)
Read(**/.env.production*)
Read(**/.env.staging*)
Read(**/*secret*)
Read(**/.ssh/*)
Read(**/.aws/*)
Read(**/.gnupg/*)
Read(**/.anthropic*)
Read(**/.openai*)
Edit(**/.env)
Edit(**/.env.*)
Edit(**/.env.local)
Edit(**/.env.production*)
Edit(**/.env.staging*)
Write(**/.env)
Write(**/.env.*)
Write(**/.env.local)
Write(**/.env.production*)
ask (9)
Bash(git push *)
Bash(npm publish*)
Bash(npx *)
Bash(pip install *)
Bash(brew install *)
Bash(apt install *)
Bash(curl *)
Bash(wget *)
WebFetch(*)
allow (0)
—

Similar rigs

copied ✓