~ / rigs / HarzerHeribert / sterna

HarzerHeribert/sterna

STERNA Trades Endless Round-trips for Nested Actions — a terminal coding agent: one program per turn, a flock of helpers, the longest run on the least.

↗ GitHub ★ 0 other updated 12d ago project Claude CodeCodex
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.6k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit HarzerHeribert/sterna/.claude ./rig-sterna  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(~/projects/glasshouse/.agent-runtime/provider-keys.env)",
      "Read(~/projects/glasshouse/.agent-runtime/*.env)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/scripts/hooks/guard-destructive-git.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/scripts/hooks/guard-expensive-gate.sh"
          }
        ]
      }
    ]
  }
}

Hooks (2)

eventmatcherruns
PreToolUseBash$CLAUDE_PROJECT_DIR/scripts/hooks/guard-destructive-git.sh
PreToolUseBash$CLAUDE_PROJECT_DIR/scripts/hooks/guard-expensive-gate.sh

Permissions

deny (2)
Read(~/projects/glasshouse/.agent-runtime/provider-keys.env)
Read(~/projects/glasshouse/.agent-runtime/*.env)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓