~ / rigs / Surgo / dotfiles

Surgo/dotfiles

🐾 Lazy dotfiles 🛰️

↗ GitHub ★ 5 no license updated 5d ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

$ git clone --depth 1 https://github.com/Surgo/dotfiles

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(~/Repos/obsidian-vault/Diary/**)",
      "Read(//**/.env*)",
      "Edit(//**/.env*)",
      "Read(//**/credentials*)",
      "Edit(//**/credentials*)",
      "Read(//**/*.pem)",
      "Edit(//**/*.pem)",
      "Read(//**/.ssh/**)",
      "Edit(//**/.ssh/**)",
      "Read(//**/.aws/**)",
      "Edit(//**/.aws/**)",
      "Bash(git commit *)",
      "Bash(git push *)",
      "Bash(git merge *)",
      "Bash(git rebase *)",
      "Bash(git reset *)",
      "Bash(git revert *)",
      "Bash(gh pr create *)",
      "Bash(gh pr comment *)",
      "Bash(gh pr review *)",
      "Bash(gh pr merge *)",
      "Bash(gh issue create *)",
      "Bash(gh issue comment *)",
      "Bash(gh issue close *)",
      "Bash(gh release *)",
      "Bash(rm -rf *)",
      "Bash(sudo *)",
      "mcp__*__apply_*",
      "mcp__*__copy_*",
      "mcp__*__create_*",
      "mcp__*__delete_*",
      "mcp__*__label_*",
      "mcp__*__mark_*",
      "mcp__*__respond_*",
      "mcp__*__share_*",
      "mcp__*__trash_*",
      "mcp__*__unlabel_*",
      "mcp__*__unmark_*",
      "mcp__*__untrash_*",
      "mcp__*__update_*",
      "mcp__*__slack_add_*",
      "mcp__*__slack_create_*",
      "mcp__*__slack_schedule_*",
      "mcp__*__slack_send_*",
      "mcp__*__slack_update_*"
    ],
    "ask": [
      "Bash(rm *)",
      "Bash(git branch *)",
      "Bash(git tag *)",
      "Bash(git stash *)"
    ]
  }
}

Plugins (5)

rust-analyzer-lsp@claude-plugins-officialpyright-lsp@claude-plugins-officialtypescript-lsp@claude-plugins-officialclaude-md-management@claude-plugins-officialclaude-security@claude-plugins-official

Permissions

deny (45)
Read(~/Repos/obsidian-vault/Diary/**)
Read(//**/.env*)
Edit(//**/.env*)
Read(//**/credentials*)
Edit(//**/credentials*)
Read(//**/*.pem)
Edit(//**/*.pem)
Read(//**/.ssh/**)
Edit(//**/.ssh/**)
Read(//**/.aws/**)
Edit(//**/.aws/**)
Bash(git commit *)
Bash(git push *)
Bash(git merge *)
Bash(git rebase *)
Bash(git reset *)
Bash(git revert *)
Bash(gh pr create *)
Bash(gh pr comment *)
Bash(gh pr review *)
Bash(gh pr merge *)
Bash(gh issue create *)
Bash(gh issue comment *)
Bash(gh issue close *)
Bash(gh release *)
Bash(rm -rf *)
Bash(sudo *)
mcp__*__apply_*
mcp__*__copy_*
mcp__*__create_*
mcp__*__delete_*
mcp__*__label_*
mcp__*__mark_*
mcp__*__respond_*
mcp__*__share_*
mcp__*__trash_*
mcp__*__unlabel_*
mcp__*__unmark_*
mcp__*__untrash_*
mcp__*__update_*
mcp__*__slack_add_*
mcp__*__slack_create_*
mcp__*__slack_schedule_*
mcp__*__slack_send_*
mcp__*__slack_update_*
ask (4)
Bash(rm *)
Bash(git branch *)
Bash(git tag *)
Bash(git stash *)
allow (10)
Bash(git status*)
Bash(git log*)
Bash(git diff*)
Bash(git show*)
Bash(git grep*)
Bash(gh pr view*)
Bash(gh pr diff*)
Bash(gh issue view*)
Bash(rg *)
Bash(ls *)

Similar rigs

copied ✓