ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
$ git clone --depth 1 https://github.com/Surgo/dotfiles MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(~/Repos/obsidian-vault/Diary/**)",
"Read(//**/.env*)",
"Edit(//**/.env*)",
"Read(//**/credentials*)",
"Edit(//**/credentials*)",
"Read(//**/*.pem)",
"Edit(//**/*.pem)",
"Read(//**/.ssh/**)",
"Edit(//**/.ssh/**)",
"Read(//**/.aws/**)",
"Edit(//**/.aws/**)",
"Bash(git commit *)",
"Bash(git push *)",
"Bash(git merge *)",
"Bash(git rebase *)",
"Bash(git reset *)",
"Bash(git revert *)",
"Bash(gh pr create *)",
"Bash(gh pr comment *)",
"Bash(gh pr review *)",
"Bash(gh pr merge *)",
"Bash(gh issue create *)",
"Bash(gh issue comment *)",
"Bash(gh issue close *)",
"Bash(gh release *)",
"Bash(rm -rf *)",
"Bash(sudo *)",
"mcp__*__apply_*",
"mcp__*__copy_*",
"mcp__*__create_*",
"mcp__*__delete_*",
"mcp__*__label_*",
"mcp__*__mark_*",
"mcp__*__respond_*",
"mcp__*__share_*",
"mcp__*__trash_*",
"mcp__*__unlabel_*",
"mcp__*__unmark_*",
"mcp__*__untrash_*",
"mcp__*__update_*",
"mcp__*__slack_add_*",
"mcp__*__slack_create_*",
"mcp__*__slack_schedule_*",
"mcp__*__slack_send_*",
"mcp__*__slack_update_*"
],
"ask": [
"Bash(rm *)",
"Bash(git branch *)",
"Bash(git tag *)",
"Bash(git stash *)"
]
}
} Plugins (5)
rust-analyzer-lsp@claude-plugins-officialpyright-lsp@claude-plugins-officialtypescript-lsp@claude-plugins-officialclaude-md-management@claude-plugins-officialclaude-security@claude-plugins-official
Permissions
deny (45)
Read(~/Repos/obsidian-vault/Diary/**)
Read(//**/.env*)
Edit(//**/.env*)
Read(//**/credentials*)
Edit(//**/credentials*)
Read(//**/*.pem)
Edit(//**/*.pem)
Read(//**/.ssh/**)
Edit(//**/.ssh/**)
Read(//**/.aws/**)
Edit(//**/.aws/**)
Bash(git commit *)
Bash(git push *)
Bash(git merge *)
Bash(git rebase *)
Bash(git reset *)
Bash(git revert *)
Bash(gh pr create *)
Bash(gh pr comment *)
Bash(gh pr review *)
Bash(gh pr merge *)
Bash(gh issue create *)
Bash(gh issue comment *)
Bash(gh issue close *)
Bash(gh release *)
Bash(rm -rf *)
Bash(sudo *)
mcp__*__apply_*
mcp__*__copy_*
mcp__*__create_*
mcp__*__delete_*
mcp__*__label_*
mcp__*__mark_*
mcp__*__respond_*
mcp__*__share_*
mcp__*__trash_*
mcp__*__unlabel_*
mcp__*__unmark_*
mcp__*__untrash_*
mcp__*__update_*
mcp__*__slack_add_*
mcp__*__slack_create_*
mcp__*__slack_schedule_*
mcp__*__slack_send_*
mcp__*__slack_update_*
ask (4)
Bash(rm *)
Bash(git branch *)
Bash(git tag *)
Bash(git stash *)
allow (10)
Bash(git status*)
Bash(git log*)
Bash(git diff*)
Bash(git show*)
Bash(git grep*)
Bash(gh pr view*)
Bash(gh pr diff*)
Bash(gh issue view*)
Bash(rg *)
Bash(ls *)
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·