Sting25/ai-coding-rules-scaffold
Two-layer enforcement (pre-commit hook + CI mirror) for small teams using AI agents. Catches debug leaks, file growth, secrets, and forbidden patterns before they merge, and scaffold-doctor tells you when a guardrail is installed but not ac
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit Sting25/ai-coding-rules-scaffold/.claude ./rig-ai-coding-rules-scaffold # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(**/.env)",
"Read(**/.env.*)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/id_rsa)",
"Read(**/id_ed25519)",
"Read(**/id_ecdsa)",
"Read(**/id_dsa)",
"Read(**/credentials)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Read(~/.config/gcloud/**)",
"Read(~/.kube/config)",
"Read(~/.netrc)",
"Read(~/.npmrc)",
"Bash(rm -rf /:*)",
"Bash(rm -rf ~:*)",
"Bash(rm -rf /*:*)",
"Bash(sudo rm:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Write|Edit|MultiEdit|Bash",
"hooks": [
{
"type": "command",
"command": "$CLAUDE_PROJECT_DIR/.githooks/lib/agent-precheck"
}
]
}
]
}
} Hooks (1)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Write|Edit|MultiEdit|Bash | $CLAUDE_PROJECT_DIR/.githooks/lib/agent-precheck |
Permissions
deny (19)
Read(**/.env)
Read(**/.env.*)
Read(**/*.pem)
Read(**/*.key)
Read(**/id_rsa)
Read(**/id_ed25519)
Read(**/id_ecdsa)
Read(**/id_dsa)
Read(**/credentials)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(~/.kube/config)
Read(~/.netrc)
Read(~/.npmrc)
Bash(rm -rf /:*)
Bash(rm -rf ~:*)
Bash(rm -rf /*:*)
Bash(sudo rm:*)
ask (0)
—
allow (0)
—
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·