~ / rigs / Rene-Kuhm / claude-code-enterprise-config

Rene-Kuhm/claude-code-enterprise-config

Enterprise Claude Code configuration: 8 specialised agents, 20 invocable skills, 7 context rules, 6 commands, 8 automated hooks and 19 MCP server integrations, with an installer.

↗ GitHub ★ 1 MIT updated 2mo ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~75.1k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add --transport http context7 https://mcp.context7.com/mcp
$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem ~
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @github/github-mcp-server
$ claude mcp add duckduckgo -- npx -y @modelcontextprotocol/server-duckduckgo
$ claude mcp add sequentialthinking -- npx -y @modelcontextprotocol/server-sequential-thinking
$ claude mcp add fetch -- npx -y @modelcontextprotocol/server-fetch
$ claude mcp add playwright -- npx -y @microsoft/playwright-mcp
$ claude mcp add dockerhub -- npx -y @docker/dockerhub-mcp
$ claude mcp add semgrep -- npx -y @semgrep/semgrep-mcp
$ claude mcp add magic -e <redacted> -- npx -y @21st-dev/magic@latest
$ claude mcp add puppeteer -- npx -y @hisma/server-puppeteer
$ claude mcp add --transport http supabase https://mcp.supabase.com/mcp
$ claude mcp add postgres -- uvx postgres-mcp-pro
$ claude mcp add brave-search -e BRAVE_<redacted> -- npx -y @brave/brave-search-mcp-server
$ claude mcp add notion -e NOTION_<redacted> -- npx -y @notionhq/notion-mcp-server
$ claude mcp add --transport http sentry https://mcp.sentry.dev/mcp
$ claude mcp add memory -- npx -y @anthropic/memory-mcp-server
$ claude mcp add shadcn -- npx -y shadcn@canary mcp
$ claude mcp add shadcn-studio -- npx -y @shadcn-studio/mcp@latest
$ claude mcp add browser-tools -- npx -y @anthropic/mcp-server-browsertools
$ npx degit Rene-Kuhm/claude-code-enterprise-config/agents ./rig-claude-code-enterprise-config/agents
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills ./rig-claude-code-enterprise-config/skills
$ npx degit Rene-Kuhm/claude-code-enterprise-config/hooks ./rig-claude-code-enterprise-config/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add --transport http context7 https://mcp.context7.com/mcp
$ claude mcp add filesystem -- npx -y @modelcontextprotocol/server-filesystem ~
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @github/github-mcp-server
$ claude mcp add duckduckgo -- npx -y @modelcontextprotocol/server-duckduckgo
$ claude mcp add sequentialthinking -- npx -y @modelcontextprotocol/server-sequential-thinking
$ claude mcp add fetch -- npx -y @modelcontextprotocol/server-fetch
$ claude mcp add playwright -- npx -y @microsoft/playwright-mcp
$ claude mcp add dockerhub -- npx -y @docker/dockerhub-mcp
$ claude mcp add semgrep -- npx -y @semgrep/semgrep-mcp
$ claude mcp add magic -e <redacted> -- npx -y @21st-dev/magic@latest
$ claude mcp add puppeteer -- npx -y @hisma/server-puppeteer
$ claude mcp add --transport http supabase https://mcp.supabase.com/mcp
$ claude mcp add postgres -- uvx postgres-mcp-pro
$ claude mcp add brave-search -e BRAVE_<redacted> -- npx -y @brave/brave-search-mcp-server
$ claude mcp add notion -e NOTION_<redacted> -- npx -y @notionhq/notion-mcp-server
$ claude mcp add --transport http sentry https://mcp.sentry.dev/mcp
$ claude mcp add memory -- npx -y @anthropic/memory-mcp-server
$ claude mcp add shadcn -- npx -y shadcn@canary mcp
$ claude mcp add shadcn-studio -- npx -y @shadcn-studio/mcp@latest
$ claude mcp add browser-tools -- npx -y @anthropic/mcp-server-browsertools
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/api-docs .claude/skills/api-docs
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/audit .claude/skills/audit
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/auto-orchestrator .claude/skills/auto-orchestrator
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/code-review .claude/skills/code-review
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/commit .claude/skills/commit
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/db-migration .claude/skills/db-migration
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/docs .claude/skills/docs
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/expert-architect .claude/skills/expert-architect
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/incident-response .claude/skills/incident-response
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/k8s .claude/skills/k8s
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/monitor .claude/skills/monitor
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/performance .claude/skills/performance
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/pr .claude/skills/pr
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/preview .claude/skills/preview
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/refactor .claude/skills/refactor
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/release .claude/skills/release
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/scaffold .claude/skills/scaffold
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/security-review .claude/skills/security-review
$ npx degit Rene-Kuhm/claude-code-enterprise-config/skills/terraform .claude/skills/terraform
$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/architect.md
$ curl -fsSL --create-dirs -o .claude/agents/builder.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/builder.md
$ curl -fsSL --create-dirs -o .claude/agents/debugger.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/debugger.md
$ curl -fsSL --create-dirs -o .claude/agents/devops.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/devops.md
$ curl -fsSL --create-dirs -o .claude/agents/docs-writer.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/docs-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/general-architect.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/general-architect.md
$ curl -fsSL --create-dirs -o .claude/agents/orchestrator.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/orchestrator.md
$ curl -fsSL --create-dirs -o .claude/agents/security-auditor.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/security-auditor.md
$ curl -fsSL --create-dirs -o .claude/agents/test-engineer.md https://raw.githubusercontent.com/Rene-Kuhm/claude-code-enterprise-config/main/agents/test-engineer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf /)",
      "Bash(rm -rf /*)",
      "Bash(rm -rf ~)",
      "Bash(git push --force origin main)",
      "Bash(git push --force origin master)",
      "Bash(git push -f origin main)",
      "Bash(git push -f origin master)",
      "Bash(sudo:*)",
      "Bash(pnpm publish)",
      "Bash(npm publish)",
      "Bash(bun publish)",
      "Bash(terraform:destroy)",
      "Bash(kubectl:delete:*)",
      "Bash(DROP TABLE:*)",
      "Bash(DELETE FROM:*)",
      "Bash(TRUNCATE:*)",
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./.env.local)",
      "Read(./.env.production)",
      "Read(./secrets/**)",
      "Read(~/.aws/**)",
      "Read(~/.ssh/**)",
      "Read(./.git/config)",
      "Edit(./.env)",
      "Edit(./.env.*)",
      "Edit(./secrets/**)",
      "Write(./.env)",
      "Write(./.env.*)",
      "Write(./secrets/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/bash-validator.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/pre-commit-validation.sh"
          }
        ]
      },
      {
        "matcher": "Edit|Write|Read",
        "hooks": [
          {
            "type": "command",
            "command": "python3 ~/.claude/hooks/file-protection.py"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/compliance-check.sh"
          }
        ]
      },
      {
        "matcher": "*",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/audit-log.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/cost-estimator.sh"
          }
        ]
      }
    ]
  }
}

MCP servers (20)

serversourceest. tokens
Context7 remote · remote 1.2k
Filesystem npm 4.2k
GitHub MCP · "github"
env: GITHUB_PERSONAL_ACCESS_TOKEN
npm 18.0k
@modelcontextprotocol/server-duckduckgo · "duckduckgo" npm 2.5k
Sequential Thinking · "sequentialthinking" npm 900
Fetch npm 450
Playwright MCP · "playwright" npm 7.5k
@docker/dockerhub-mcp · "dockerhub" npm 2.5k
@semgrep/semgrep-mcp · "semgrep" npm 2.5k
21st.dev Magic · "magic"
env: API_KEY
npm 1.5k
Puppeteer npm 2.2k
Supabase remote · remote 7.0k
postgres-mcp-pro · "postgres" pypi 2.5k
Brave Search · "brave-search"
env: BRAVE_API_KEY
npm 900
Notion
env: NOTION_API_KEY
npm 6.0k
Sentry remote · remote 4.5k
@anthropic/memory-mcp-server · "memory" npm 2.5k
shadcn/ui · "shadcn" npm 2.0k
@shadcn-studio/mcp · "shadcn-studio" npm 2.5k
@anthropic/mcp-server-browsertools · "browser-tools" npm 2.5k

Skills (19)

Subagents (9)

architect
model: inherit
Arquitecto de Software Senior - Análisis SOLID, patrones de diseño, DDD, arquitectura enterprise. Solo lectura y análisis, no implementa código.
builder
model: inherit
Desarrollador Full Stack Expert - Implementación y ejecución de código production-ready con TypeScript estricto, Next.js, React, testing y mejores prácticas.
debugger
model: inherit
Especialista en debugging y resolución de errores - Stack traces, TypeScript errors, React/Next.js issues, database errors.
devops—
docs-writerGenerador de documentación técnica. READMEs, API docs, guías de usuario, JSDoc/TSDoc.
general-architect
model: inherit
Arquitecto de Software Senior especializado en Next.js 16, React 19.2, Framer Motion, GSAP, Lenis y aplicaciones web de alto impacto visual. Usar para arquitectura, commits, SQL, APIs REST, seguridad,
orchestrator
model: haiku
Meta-orquestador inteligente que detecta el tipo de tarea y delega automáticamente al agente especializado correcto. Se activa en cada interacción para maximizar eficiencia.
security-auditor
model: inherit
Auditor de Seguridad OWASP - Code review, análisis de vulnerabilidades, OWASP Top 10. Solo lectura y análisis de seguridad.
test-engineerEspecialista en testing. Unit tests, integration tests, E2E, TDD, coverage.

Hooks (13)

eventmatcherruns
PreToolUseBash~/.claude/hooks/bash-validator.sh
PreToolUseBash~/.claude/hooks/pre-commit-validation.sh
PreToolUseEdit|Write|Readpython3 ~/.claude/hooks/file-protection.py
PreToolUseEdit|Write|Read~/.claude/hooks/compliance-check.sh
PreToolUse*~/.claude/hooks/audit-log.sh
PreToolUse*~/.claude/hooks/cost-estimator.sh
PostToolUseBash~/.claude/hooks/team-notification.sh
PostToolUseEdit|Write~/.claude/hooks/auto-format.sh
PostToolUseEdit|Write~/.claude/hooks/lint-fix.sh
PostToolUseEdit|Write~/.claude/hooks/typecheck.sh
UserPromptSubmit*~/.claude/hooks/security-validator.sh
Stop*~/.claude/hooks/ralph-loop.sh
Stop*~/.claude/hooks/team-notification.sh

Plugins (1)

typescript-lsp@claude-plugins-official

Permissions

deny (30)
Bash(rm -rf /)
Bash(rm -rf /*)
Bash(rm -rf ~)
Bash(git push --force origin main)
Bash(git push --force origin master)
Bash(git push -f origin main)
Bash(git push -f origin master)
Bash(sudo:*)
Bash(pnpm publish)
Bash(npm publish)
Bash(bun publish)
Bash(terraform:destroy)
Bash(kubectl:delete:*)
Bash(DROP TABLE:*)
Bash(DELETE FROM:*)
Bash(TRUNCATE:*)
Read(./.env)
Read(./.env.*)
Read(./.env.local)
Read(./.env.production)
Read(./secrets/**)
Read(~/.aws/**)
Read(~/.ssh/**)
Read(./.git/config)
Edit(./.env)
Edit(./.env.*)
Edit(./secrets/**)
Write(./.env)
Write(./.env.*)
Write(./secrets/**)
ask (0)
—
allow (22)
Bash(git:*)
Bash(pnpm:*)
Bash(npm:*)
Bash(npx:*)
Bash(node:*)
Bash(mkdir:*)
Bash(ls:*)
Bash(docker:*)
Bash(bun:*)
Bash(biome:*)
Bash(vitest:*)
Bash(tsc:*)
Bash(terraform:validate)
Bash(terraform:plan)
Bash(kubectl:describe:*)
Bash(kubectl:get:*)
Bash(kubectl:logs:*)
Write
Edit
Read
Glob
Grep

Similar rigs

copied ✓