~ / rigs / Sting25 / ai-coding-rules-scaffold

Sting25/ai-coding-rules-scaffold

Two-layer enforcement (pre-commit hook + CI mirror) for small teams using AI agents. Catches debug leaks, file growth, secrets, and forbidden patterns before they merge, and scaffold-doctor tells you when a guardrail is installed but not ac

↗ GitHub ★ 4 MIT updated 1mo ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit Sting25/ai-coding-rules-scaffold/.claude ./rig-ai-coding-rules-scaffold  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(**/id_rsa)",
      "Read(**/id_ed25519)",
      "Read(**/id_ecdsa)",
      "Read(**/id_dsa)",
      "Read(**/credentials)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(~/.config/gcloud/**)",
      "Read(~/.kube/config)",
      "Read(~/.netrc)",
      "Read(~/.npmrc)",
      "Bash(rm -rf /:*)",
      "Bash(rm -rf ~:*)",
      "Bash(rm -rf /*:*)",
      "Bash(sudo rm:*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Write|Edit|MultiEdit|Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.githooks/lib/agent-precheck"
          }
        ]
      }
    ]
  }
}

Hooks (1)

eventmatcherruns
PreToolUseWrite|Edit|MultiEdit|Bash$CLAUDE_PROJECT_DIR/.githooks/lib/agent-precheck

Permissions

deny (19)
Read(**/.env)
Read(**/.env.*)
Read(**/*.pem)
Read(**/*.key)
Read(**/id_rsa)
Read(**/id_ed25519)
Read(**/id_ecdsa)
Read(**/id_dsa)
Read(**/credentials)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(~/.kube/config)
Read(~/.netrc)
Read(~/.npmrc)
Bash(rm -rf /:*)
Bash(rm -rf ~:*)
Bash(rm -rf /*:*)
Bash(sudo rm:*)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓