~ / rigs / JulesNsenda / claude-workflow

JulesNsenda/claude-workflow

My global Claude Code config — a plan → gate → commit workflow with adversarial review, symlinked into ~/.claude

↗ GitHub ★ 1 mit updated 3mo ago personal setup Claude Code Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~3.8k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit JulesNsenda/claude-workflow/.claude ./rig-claude-workflow  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit JulesNsenda/claude-workflow/skills/example-skill .claude/skills/example-skill
$ npx degit JulesNsenda/claude-workflow/skills/plan-gates .claude/skills/plan-gates
$ curl -fsSL --create-dirs -o .claude/agents/architecture-critic.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/architecture-critic.md
$ curl -fsSL --create-dirs -o .claude/agents/explore.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/explore.md
$ curl -fsSL --create-dirs -o .claude/agents/implementer.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/implementer.md
$ curl -fsSL --create-dirs -o .claude/agents/security-critic.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/security-critic.md
$ curl -fsSL --create-dirs -o .claude/agents/test-runner.md https://raw.githubusercontent.com/JulesNsenda/claude-workflow/main/agents/test-runner.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(.env)",
      "Read(.env.*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(secrets/**)",
      "Read(**/secrets/**)",
      "Read(*.pem)",
      "Read(**/*.pem)",
      "Read(*.key)",
      "Read(**/*.key)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)"
    ],
    "ask": [
      "Bash(git push:*)"
    ]
  }
}

Skills (2)

Subagents (5)

architecture-critic
model: opus
>-
Explore
model: haiku
>-
implementer
model: sonnet
>-
security-critic
model: opus
>-
test-runner
model: sonnet
>-

Permissions

deny (14)
Read(.env)
Read(.env.*)
Read(**/.env)
Read(**/.env.*)
Read(secrets/**)
Read(**/secrets/**)
Read(*.pem)
Read(**/*.pem)
Read(*.key)
Read(**/*.key)
Read(~/.ssh/**)
Read(~/.aws/**)
Bash(git push --force:*)
Bash(git push -f:*)
ask (1)
Bash(git push:*)
allow (6)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git add:*)
Bash(git commit:*)
Bash(shellcheck:*)

Similar rigs

copied ✓