LasseJacobsen/claude-dotfiles
Reusable Claude Code configuration: hooks, commands, skills, and MCP server setup. One install.sh for a new machine.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit LasseJacobsen/claude-dotfiles/.claude ./rig-claude-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit LasseJacobsen/claude-dotfiles/.claude/skills/writing-for-agents .claude/skills/writing-for-agents $ npx degit LasseJacobsen/claude-dotfiles/skills/book-to-skill .claude/skills/book-to-skill $ npx degit LasseJacobsen/claude-dotfiles/skills/domain-modeling .claude/skills/domain-modeling $ npx degit LasseJacobsen/claude-dotfiles/skills/grill-with-docs .claude/skills/grill-with-docs $ npx degit LasseJacobsen/claude-dotfiles/skills/iso-24495-code .claude/skills/iso-24495-code $ npx degit LasseJacobsen/claude-dotfiles/skills/pyspark-audit .claude/skills/pyspark-audit $ npx degit LasseJacobsen/claude-dotfiles/skills/pyspark-style .claude/skills/pyspark-style
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(sudo *)",
"Bash(rm -rf ~*)",
"Bash(rm -rf /*)",
"Read(.env)",
"Read(.env.*)",
"Read(secrets/**)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/*.p12)",
"Read(**/*.pfx)",
"Read(**/credentials.json)",
"Read(**/.mcp.local.json)",
"Read(~/.ssh/**)",
"Edit(.env*)",
"Edit(secrets/**)"
],
"ask": [
"Bash(git push *)",
"Edit(pyproject.toml)",
"Edit(uv.lock)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/block-destructive.sh\""
},
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/enforce-uv.sh\""
},
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/block-git-main.sh\""
},
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/block-big-binaries.sh\""
},
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/protect-secrets.sh\""
}
]
}
]
}
} Skills (7)
writing-for-agentsbook-to-skilldomain-modelinggrill-with-docsiso-24495-codepyspark-auditpyspark-style
Hooks (8)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | bash "$HOME/.claude/hooks/block-destructive.sh" |
| PreToolUse | Bash | bash "$HOME/.claude/hooks/enforce-uv.sh" |
| PreToolUse | Bash | bash "$HOME/.claude/hooks/block-git-main.sh" |
| PreToolUse | Bash | bash "$HOME/.claude/hooks/block-big-binaries.sh" |
| PreToolUse | Bash | bash "$HOME/.claude/hooks/protect-secrets.sh" |
| PostToolUse | Write|Edit|MultiEdit | bash "$HOME/.claude/hooks/ruff-after-edit.sh" |
| PostToolUse | Write|NotebookEdit | bash "$HOME/.claude/hooks/nbstripout.sh" |
| Notification | * | bash "$HOME/.claude/hooks/notify.sh" |
Permissions
deny (15)
Bash(sudo *)
Bash(rm -rf ~*)
Bash(rm -rf /*)
Read(.env)
Read(.env.*)
Read(secrets/**)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/credentials.json)
Read(**/.mcp.local.json)
Read(~/.ssh/**)
Edit(.env*)
Edit(secrets/**)
ask (3)
Bash(git push *)
Edit(pyproject.toml)
Edit(uv.lock)
allow (0)
—
Similar rigs
MPV/dotfiles
MPV's dotfiles
Pragmatist 290 tok ·
mediocrebaby/dot-file
个人 dotfiles 仓库,集中管理 Claude Code 与 WezTerm 的配置,便于在多台机器之间同步、备份与回滚。
Skill Collector 456 tok ·
aleconf/claude-code-spec-scaffold
Opinionated scaffolding for spec-driven AI coding — so your sessions leave behind artefacts, not scrollback.
Minimalist 1.1k tok ·
drlinggg/claude-dotfiles
—
Skill Collector 623 tok ·