~ / rigs / Kalypsokichu-code / kalypso-claude-workflow

Kalypsokichu-code/kalypso-claude-workflow

My Claude Code setup - three-tier permissions, hook router, slash commands, subagents, scaffolding. Opinionated.

↗ GitHub ★ 18 MIT updated 6mo ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~549 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit Kalypsokichu-code/kalypso-claude-workflow/agents ./rig-kalypso-claude-workflow/agents
$ npx degit Kalypsokichu-code/kalypso-claude-workflow/commands ./rig-kalypso-claude-workflow/commands
$ npx degit Kalypsokichu-code/kalypso-claude-workflow/hooks ./rig-kalypso-claude-workflow/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/pr-reviewer.md https://raw.githubusercontent.com/Kalypsokichu-code/kalypso-claude-workflow/main/agents/pr-reviewer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf:*)",
      "Bash(rm -rf /)",
      "Bash(sudo rm:*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(git clean -fd:*)",
      "Bash(git branch -D:*)",
      "Read(.env)",
      "Read(.env.*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(~/.config/gcloud/**)",
      "Read(**/credentials*)",
      "Read(**/*.pem)"
    ],
    "ask": [
      "Bash(rm *)",
      "Bash(rmdir *)",
      "Bash(chmod *)",
      "Bash(chown *)",
      "Bash(npm install:*)",
      "Bash(npm run *)",
      "Bash(bun install:*)",
      "Bash(pip install:*)",
      "Bash(pip3 install:*)",
      "Bash(brew install:*)",
      "Bash(docker *)",
      "Bash(kill *)",
      "Bash(killall *)",
      "Bash(git push:*)",
      "Bash(git commit:*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "*",
        "hooks": [
          {
            "type": "command",
            "command": "$HOME/.claude/hooks/router.sh PreToolUse"
          }
        ]
      }
    ]
  }
}

Subagents (1)

pr-reviewer
model: opus
Use PROACTIVELY for reviewing pull requests or staged changes. Read-only critique focused on correctness, security, and clarity. Runs in a fresh context so it doesn't inherit the author's assumptions.

Hooks (11)

eventmatcherruns
PreToolUse*$HOME/.claude/hooks/router.sh PreToolUse
PostToolUse*$HOME/.claude/hooks/router.sh PostToolUse
PostToolUseFailure*$HOME/.claude/hooks/router.sh PostToolUseFailure
UserPromptSubmit*$HOME/.claude/hooks/router.sh UserPromptSubmit
Stop*$HOME/.claude/hooks/router.sh Stop
StopFailure*$HOME/.claude/hooks/router.sh StopFailure
Notification*$HOME/.claude/hooks/router.sh Notification
PermissionRequest*$HOME/.claude/hooks/router.sh PermissionRequest
SessionStart*$HOME/.claude/hooks/router.sh SessionStart
SessionEnd*$HOME/.claude/hooks/router.sh SessionEnd
PreCompact*$HOME/.claude/hooks/router.sh PreCompact

Slash commands (5)

/audit-deps/commit-split/explain-repo/pr-ready/rotate-secrets

Permissions

deny (17)
Bash(rm -rf:*)
Bash(rm -rf /)
Bash(sudo rm:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(git clean -fd:*)
Bash(git branch -D:*)
Read(.env)
Read(.env.*)
Read(**/.env)
Read(**/.env.*)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(**/credentials*)
Read(**/*.pem)
ask (15)
Bash(rm *)
Bash(rmdir *)
Bash(chmod *)
Bash(chown *)
Bash(npm install:*)
Bash(npm run *)
Bash(bun install:*)
Bash(pip install:*)
Bash(pip3 install:*)
Bash(brew install:*)
Bash(docker *)
Bash(kill *)
Bash(killall *)
Bash(git push:*)
Bash(git commit:*)
allow (12)
Bash(bun run build:*)
Bash(bun run lint:*)
Bash(bun run test:*)
Bash(bun run typecheck:*)
Bash(bun test:*)
Bash(find:*)
Bash(gh:*)
Bash(git status)
Bash(git diff:*)
Bash(git log:*)
Bash(ls:*)
Bash(docker ps:*)

Similar rigs

copied ✓