~ / rigs / Markuysa / vibe-coding-template

Markuysa/vibe-coding-template

Claude Code project template: five agent roles with tool-level permission boundaries, four workflow commands, and a permission baseline that keeps secrets and build noise out of context. Built on native worktrees and subagents — no third-pa

↗ GitHub ★ 1 MIT updated 3mo ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.2k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit Markuysa/vibe-coding-template/.claude ./rig-vibe-coding-template  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit Markuysa/vibe-coding-template/.claude/skills/autopilot .claude/skills/autopilot
$ npx degit Markuysa/vibe-coding-template/.claude/skills/board .claude/skills/board
$ npx degit Markuysa/vibe-coding-template/.claude/skills/execute-ticket .claude/skills/execute-ticket
$ npx degit Markuysa/vibe-coding-template/.claude/skills/next-ticket .claude/skills/next-ticket
$ npx degit Markuysa/vibe-coding-template/.claude/skills/plan .claude/skills/plan
$ npx degit Markuysa/vibe-coding-template/.claude/skills/ponytail .claude/skills/ponytail
$ npx degit Markuysa/vibe-coding-template/.claude/skills/retro .claude/skills/retro
$ npx degit Markuysa/vibe-coding-template/.claude/skills/ship .claude/skills/ship
$ npx degit Markuysa/vibe-coding-template/.claude/skills/spec .claude/skills/spec
$ npx degit Markuysa/vibe-coding-template/.claude/skills/unblock .claude/skills/unblock
$ curl -fsSL --create-dirs -o .claude/agents/backend.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/backend.md
$ curl -fsSL --create-dirs -o .claude/agents/designer.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/designer.md
$ curl -fsSL --create-dirs -o .claude/agents/dev.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/dev.md
$ curl -fsSL --create-dirs -o .claude/agents/frontend.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/frontend.md
$ curl -fsSL --create-dirs -o .claude/agents/lead.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/lead.md
$ curl -fsSL --create-dirs -o .claude/agents/qa.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/qa.md
$ curl -fsSL --create-dirs -o .claude/agents/researcher.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/researcher.md
$ curl -fsSL --create-dirs -o .claude/agents/reviewer.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/validator.md https://raw.githubusercontent.com/Markuysa/vibe-coding-template/main/.claude/agents/validator.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(.env)",
      "Read(.env.*)",
      "Edit(.env)",
      "Edit(.env.*)",
      "Read(secrets/**)",
      "Edit(secrets/**)",
      "Read(*.pem)",
      "Read(*.key)",
      "Read(*.p12)",
      "Read(*.keystore)",
      "Read(id_rsa*)",
      "Read(.npmrc)",
      "Read(.pypirc)",
      "Read(.netrc)",
      "Read(credentials.json)",
      "Read(service-account*.json)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(~/.config/gcloud/**)",
      "Read(~/.kube/config)",
      "Read(node_modules/**)",
      "Read(vendor/**)",
      "Read(dist/**)",
      "Read(build/**)",
      "Read(.next/**)",
      "Read(target/**)",
      "Read(coverage/**)",
      "Read(.git/objects/**)",
      "Read(package-lock.json)",
      "Read(pnpm-lock.yaml)",
      "Read(yarn.lock)",
      "Read(poetry.lock)",
      "Read(Cargo.lock)",
      "Read(*.png)",
      "Read(*.jpg)",
      "Read(*.jpeg)",
      "Read(*.gif)",
      "Read(*.webp)",
      "Read(*.ico)",
      "Read(*.pdf)",
      "Read(*.mp4)",
      "Read(*.woff2)",
      "Bash(git push --force *)",
      "Bash(git push -f *)",
      "Bash(git reset --hard *)",
      "Bash(git clean -fd *)",
      "Bash(terraform apply *)",
      "Bash(terraform destroy *)",
      "Bash(kubectl delete *)",
      "Bash(npm publish *)",
      "Bash(npm publish)",
      "Bash(pnpm publish *)",
      "Bash(docker system prune *)",
      "Bash(* migrate deploy *)",
      "Bash(* db push *)",
      "Bash(gh release create *)",
      "Bash(git merge *)",
      "Bash(git rebase *)"
    ],
    "ask": [
      "Bash(git push *)",
      "Bash(rm -rf *)",
      "Bash(gh repo delete *)",
      "Bash(git worktree remove --force *)",
      "Bash(gh pr merge *)",
      "Bash(gh pr merge --admin *)"
    ]
  }
}

Skills (10)

Subagents (9)

backend
model: sonnet
Builds server-side code — APIs, storage, pipelines, integrations. Use for tickets whose role is backend, anything behind the API contract.
designer
model: sonnet
Owns the visual layer — design tokens, primitives, component states, mockup-to-component translation. Use for tickets whose role is designer, or any work that defines how the product looks rather than
dev
model: sonnet
Generalist implementer for tickets that fit no specialist — cross-cutting changes, tooling, docs, small full-stack fixes. Specialist roles (designer, frontend, backend, qa) take their own tickets; dev
frontend
model: sonnet
Builds UI screens and client logic on top of the design system and the frozen API contract. Use for tickets whose role is frontend — pages, flows, client state, data wiring.
lead
model: opus
Breaks a spec into independent tickets with acceptance criteria, routes them to dev/validator/reviewer, and synthesizes results. Use for planning a sprint or decomposing a feature too large for one ag
qa
model: sonnet
Writes the tests that prove acceptance criteria — e2e flows, integration suites, regression cases. Use for tickets whose role is qa, or when a feature exists but its criteria have no automated proof.
researcher
model: haiku
Scouts the codebase and external docs, returning a compact summary instead of a wall of files and search results. Use to answer "how does X work here" or "what do the docs say about Y" before a decisi
reviewer
model: sonnet
Reviews a diff for security, correctness, and style. Reads and inspects git diff only, changes nothing. Use after the validator returns green, before a human merges.
validator
model: sonnet
CI gate. Runs tests, lint, and type checks against a ticket's acceptance criteria and returns a green/red verdict. Never edits code. Use after dev reports a feature as done.

Permissions

deny (58)
Read(.env)
Read(.env.*)
Edit(.env)
Edit(.env.*)
Read(secrets/**)
Edit(secrets/**)
Read(*.pem)
Read(*.key)
Read(*.p12)
Read(*.keystore)
Read(id_rsa*)
Read(.npmrc)
Read(.pypirc)
Read(.netrc)
Read(credentials.json)
Read(service-account*.json)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(~/.kube/config)
Read(node_modules/**)
Read(vendor/**)
Read(dist/**)
Read(build/**)
Read(.next/**)
Read(target/**)
Read(coverage/**)
Read(.git/objects/**)
Read(package-lock.json)
Read(pnpm-lock.yaml)
Read(yarn.lock)
Read(poetry.lock)
Read(Cargo.lock)
Read(*.png)
Read(*.jpg)
Read(*.jpeg)
Read(*.gif)
Read(*.webp)
Read(*.ico)
Read(*.pdf)
Read(*.mp4)
Read(*.woff2)
Bash(git push --force *)
Bash(git push -f *)
Bash(git reset --hard *)
Bash(git clean -fd *)
Bash(terraform apply *)
Bash(terraform destroy *)
Bash(kubectl delete *)
Bash(npm publish *)
Bash(npm publish)
Bash(pnpm publish *)
Bash(docker system prune *)
Bash(* migrate deploy *)
Bash(* db push *)
Bash(gh release create *)
Bash(git merge *)
Bash(git rebase *)
ask (6)
Bash(git push *)
Bash(rm -rf *)
Bash(gh repo delete *)
Bash(git worktree remove --force *)
Bash(gh pr merge *)
Bash(gh pr merge --admin *)
allow (39)
Read(docs/**)
Read(src/**)
Read(tests/**)
Bash(git diff *)
Bash(git log *)
Bash(git status *)
Bash(git worktree list)
Bash(git branch *)
Bash(gh issue view *)
Bash(gh issue list *)
Bash(gh issue create *)
Bash(gh issue edit *)
Bash(gh issue comment *)
Bash(gh issue close *)
Bash(gh label list *)
Bash(gh label create *)
Bash(gh pr view *)
Bash(gh pr diff *)
Bash(gh pr list *)
Bash(gh pr create *)
Bash(gh repo view *)
Bash(gh run list *)
Bash(gh run view *)
Bash(git add *)
Bash(git commit *)
Bash(git checkout *)
Bash(git switch *)
Bash(git restore *)
Bash(git stash *)
Bash(git show *)
Bash(git rev-parse *)
Bash(git symbolic-ref *)
Bash(git worktree add *)
Bash(git worktree remove *)
Bash(git fetch *)
Bash(git remote -v)
Bash(gh api repos/*)
Read(.claude/autopilot.json)
Bash(gh pr merge --auto --squash *)

Similar rigs

copied ✓