JulesNsenda/claude-workflow
My global Claude Code config — a plan → gate → commit workflow with adversarial review, symlinked into ~/.claude
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit JulesNsenda/claude-workflow/.claude ./rig-claude-workflow # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit JulesNsenda/claude-workflow/skills/example-skill .claude/skills/example-skill $ npx degit JulesNsenda/claude-workflow/skills/plan-gates .claude/skills/plan-gates
$ curl -fsSL --create-dirs -o .claude/agents/architecture-critic.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/architecture-critic.md $ curl -fsSL --create-dirs -o .claude/agents/explore.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/explore.md $ curl -fsSL --create-dirs -o .claude/agents/implementer.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/implementer.md $ curl -fsSL --create-dirs -o .claude/agents/security-critic.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/security-critic.md $ curl -fsSL --create-dirs -o .claude/agents/test-runner.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/test-runner.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(.env)",
"Read(.env.*)",
"Read(**/.env)",
"Read(**/.env.*)",
"Read(secrets/**)",
"Read(**/secrets/**)",
"Read(*.pem)",
"Read(**/*.pem)",
"Read(*.key)",
"Read(**/*.key)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Bash(git push --force:*)",
"Bash(git push -f:*)"
],
"ask": [
"Bash(git push:*)"
]
}
} Skills (2)
Subagents (5)
| architecture-critic model: opus | >- |
| Explore model: haiku | >- |
| implementer model: sonnet | >- |
| security-critic model: opus | >- |
| test-runner model: sonnet | >- |
Permissions
deny (14)
Read(.env)
Read(.env.*)
Read(**/.env)
Read(**/.env.*)
Read(secrets/**)
Read(**/secrets/**)
Read(*.pem)
Read(**/*.pem)
Read(*.key)
Read(**/*.key)
Read(~/.ssh/**)
Read(~/.aws/**)
Bash(git push --force:*)
Bash(git push -f:*)
ask (1)
Bash(git push:*)
allow (6)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git add:*)
Bash(git commit:*)
Bash(shellcheck:*)
Similar rigs
Yassinekrn/claude-setup
Personal Claude Code setup — orchestrator/subagent delegation policy, custom agents, and a colored PowerShell statusline (git branch, model+effort, tokens, cost, rate limits).
Orchestrator 1.2k tok ·
lukasz-fedor/claude-memory-template
Starter template for Claude Code memory system: modular rules with glob patterns, persistent memory, session continuity with auto-handover hook, and .claudeignore setup.
Minimalist 1.2k tok ·
GGPrompts/TFE
—
Pragmatist 3.9k tok ·
vinipx/ai-architecture-explorer
—
Pragmatist 22 tok ·