~ / rigs / PositiveControl / rails-rocket-sheep

PositiveControl/rails-rocket-sheep

Rails 8 application template for building with AI coding agents (Claude Code, Cursor, Codex): generated CLAUDE.md, one-rule-per-file conventions, gates in CI

↗ GitHub ★ 2 mit updated 5d ago project Claude Code Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~5.5k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit PositiveControl/rails-rocket-sheep/.claude ./rig-rails-rocket-sheep  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit PositiveControl/rails-rocket-sheep/templates/.claude/skills/rails-conventions .claude/skills/rails-conventions

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./config/master.key)",
      "Read(./config/credentials/*.key)",
      "Read(./.kamal/secrets)",
      "Read(./.env)",
      "Read(./.env.*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(git clean -fd:*)",
      "Read(./config/master.key)",
      "Read(./config/credentials/*.key)",
      "Read(./.kamal/secrets)",
      "Read(./.env)",
      "Read(./.env.*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(git clean -fd:*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|Edit|Write|MultiEdit|NotebookEdit",
        "hooks": [
          {
            "type": "command",
            "command": "bin/hooks/autopilot_guard"
          },
          {
            "type": "command",
            "command": "bin/hooks/autopilot_guard"
          }
        ]
      }
    ]
  }
}

Skills (1)

Hooks (6)

eventmatcherruns
PreToolUseBash|Edit|Write|MultiEdit|NotebookEditbin/hooks/autopilot_guard
PostToolUseEdit|Write|MultiEditbin/hooks/post_edit
Stop*bin/hooks/session_end
PreToolUseBash|Edit|Write|MultiEdit|NotebookEditbin/hooks/autopilot_guard
PostToolUseEdit|Write|MultiEditbin/hooks/post_edit
Stop*bin/hooks/session_end

Slash commands (50)

/diagnose/domain_model/feature_plan/grill/implement/pick/pr_comment_resolver/pr_fix_ci/pr_qa/pr_review/pr_submit/qa_walkthrough/rails_code_review/research/resolve_conflicts/run_lint/segue/segue_close/segue_kill/segue_merge/segue_resume/task_plan/test_fix/update_docs/workflow_setup/diagnose/domain_model/feature_plan/grill/implement/pick/pr_comment_resolver/pr_fix_ci/pr_qa/pr_review/pr_submit/qa_walkthrough/rails_code_review/research/resolve_conflicts/run_lint/segue/segue_close/segue_kill/segue_merge/segue_resume/task_plan/test_fix/update_docs/workflow_setup

Permissions

deny (18)
Read(./config/master.key)
Read(./config/credentials/*.key)
Read(./.kamal/secrets)
Read(./.env)
Read(./.env.*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(git clean -fd:*)
Read(./config/master.key)
Read(./config/credentials/*.key)
Read(./.kamal/secrets)
Read(./.env)
Read(./.env.*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(git clean -fd:*)
ask (0)
—
allow (92)
Bash(bin/test:*)
Bash(bin/rubocop:*)
Bash(bin/brakeman:*)
Bash(bin/gates:*)
Bash(bin/qa-walkthrough:*)
Bash(bin/rails routes:*)
Bash(bin/rails db:migrate:*)
Bash(bin/rails db:prepare:*)
Bash(bin/rails db:test:prepare:*)
Bash(bin/rails db:seed:*)
Bash(bin/rails db:queries:*)
Bash(bin/rails generate:*)
Bash(bin/rails test:*)
Bash(bin/rails about:*)
Bash(bin/rails stats:*)
Bash(bin/rails tailwindcss:build:*)
Bash(bin/rails zeitwerk:check:*)
Bash(bin/importmap:*)
Bash(bundle install:*)
Bash(bundle show:*)
Bash(bundle exec rubocop:*)
Bash(git status:*)
Bash(git log:*)
Bash(git diff:*)
Bash(git show:*)
Bash(git branch:*)
Bash(git remote -v:*)
Bash(git add:*)
Bash(git stash list:*)
Bash(gh pr view:*)
Bash(gh pr checks:*)
Bash(gh pr diff:*)
Bash(gh pr list:*)
Bash(gh issue view:*)
Bash(gh issue list:*)
Bash(gh run list:*)
Bash(gh run view:*)
Bash(ls:*)
Bash(find:*)
Bash(grep:*)
Bash(rg:*)
Bash(wc:*)
Bash(head:*)
Bash(tail:*)
Bash(pg_isready:*)
WebSearch
Bash(bin/test:*)
Bash(bin/rubocop:*)
Bash(bin/brakeman:*)
Bash(bin/gates:*)
Bash(bin/qa-walkthrough:*)
Bash(bin/rails routes:*)
Bash(bin/rails db:migrate:*)
Bash(bin/rails db:prepare:*)
Bash(bin/rails db:test:prepare:*)
Bash(bin/rails db:seed:*)
Bash(bin/rails db:queries:*)
Bash(bin/rails generate:*)
Bash(bin/rails test:*)
Bash(bin/rails about:*)

Similar rigs

copied ✓