Kalypsokichu-code/kalypso-claude-workflow
My Claude Code setup - three-tier permissions, hook router, slash commands, subagents, scaffolding. Opinionated.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ npx degit Kalypsokichu-code/kalypso-claude-workflow/agents ./rig-kalypso-claude-workflow/agents $ npx degit Kalypsokichu-code/kalypso-claude-workflow/commands ./rig-kalypso-claude-workflow/commands $ npx degit Kalypsokichu-code/kalypso-claude-workflow/hooks ./rig-kalypso-claude-workflow/hooks
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ curl -fsSL --create-dirs -o .claude/agents/pr-reviewer.md https://raw.githubusercontent.com/Kalypsokichu-code/kalypso-claude-workflow/main/agents/pr-reviewer.md Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf:*)",
"Bash(rm -rf /)",
"Bash(sudo rm:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git reset --hard:*)",
"Bash(git clean -fd:*)",
"Bash(git branch -D:*)",
"Read(.env)",
"Read(.env.*)",
"Read(**/.env)",
"Read(**/.env.*)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Read(~/.config/gcloud/**)",
"Read(**/credentials*)",
"Read(**/*.pem)"
],
"ask": [
"Bash(rm *)",
"Bash(rmdir *)",
"Bash(chmod *)",
"Bash(chown *)",
"Bash(npm install:*)",
"Bash(npm run *)",
"Bash(bun install:*)",
"Bash(pip install:*)",
"Bash(pip3 install:*)",
"Bash(brew install:*)",
"Bash(docker *)",
"Bash(kill *)",
"Bash(killall *)",
"Bash(git push:*)",
"Bash(git commit:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "$HOME/.claude/hooks/router.sh PreToolUse"
}
]
}
]
}
} Subagents (1)
| pr-reviewer model: opus | Use PROACTIVELY for reviewing pull requests or staged changes. Read-only critique focused on correctness, security, and clarity. Runs in a fresh context so it doesn't inherit the author's assumptions. |
Hooks (11)
| event | matcher | runs |
|---|---|---|
| PreToolUse | * | $HOME/.claude/hooks/router.sh PreToolUse |
| PostToolUse | * | $HOME/.claude/hooks/router.sh PostToolUse |
| PostToolUseFailure | * | $HOME/.claude/hooks/router.sh PostToolUseFailure |
| UserPromptSubmit | * | $HOME/.claude/hooks/router.sh UserPromptSubmit |
| Stop | * | $HOME/.claude/hooks/router.sh Stop |
| StopFailure | * | $HOME/.claude/hooks/router.sh StopFailure |
| Notification | * | $HOME/.claude/hooks/router.sh Notification |
| PermissionRequest | * | $HOME/.claude/hooks/router.sh PermissionRequest |
| SessionStart | * | $HOME/.claude/hooks/router.sh SessionStart |
| SessionEnd | * | $HOME/.claude/hooks/router.sh SessionEnd |
| PreCompact | * | $HOME/.claude/hooks/router.sh PreCompact |
Slash commands (5)
/audit-deps/commit-split/explain-repo/pr-ready/rotate-secrets
Permissions
deny (17)
Bash(rm -rf:*)
Bash(rm -rf /)
Bash(sudo rm:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(git clean -fd:*)
Bash(git branch -D:*)
Read(.env)
Read(.env.*)
Read(**/.env)
Read(**/.env.*)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(**/credentials*)
Read(**/*.pem)
ask (15)
Bash(rm *)
Bash(rmdir *)
Bash(chmod *)
Bash(chown *)
Bash(npm install:*)
Bash(npm run *)
Bash(bun install:*)
Bash(pip install:*)
Bash(pip3 install:*)
Bash(brew install:*)
Bash(docker *)
Bash(kill *)
Bash(killall *)
Bash(git push:*)
Bash(git commit:*)
allow (12)
Bash(bun run build:*)
Bash(bun run lint:*)
Bash(bun run test:*)
Bash(bun run typecheck:*)
Bash(bun test:*)
Bash(find:*)
Bash(gh:*)
Bash(git status)
Bash(git diff:*)
Bash(git log:*)
Bash(ls:*)
Bash(docker ps:*)
Similar rigs
lucasandradeb/my-claude-code-config
My personal Claude Code configuration — MCP servers, plugins, CLAUDE.md and setup guides
Pragmatist 1.1k tok ·
errpoulos/claude-sprint-workflow
Multi-agent Claude Code workflow for Jira-integrated sprint management — plan, implement, QA, and release with AI orchestration
Pragmatist 578 tok ·
kraulerson/solo-orchestrator
AI-assisted software development methodology for solo builders
Automator 10.1k tok ·
marcuslannister/claude-code-settings
Claude Code settings, hooks, and skills
YOLO Cowboy 1.7k tok ·