ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ npx degit Yota-K/dotfiles/.claude ./rig-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit Yota-K/dotfiles/.claude/skills/ask .claude/skills/ask $ npx degit Yota-K/dotfiles/.claude/skills/commit-and-pr .claude/skills/commit-and-pr $ npx degit Yota-K/dotfiles/.claude/skills/commit-and-push .claude/skills/commit-and-push $ npx degit Yota-K/dotfiles/.claude/skills/update-pr-summary .claude/skills/update-pr-summary
$ curl -fsSL --create-dirs -o .claude/agents/refactor-cleaner.md https://raw.githubusercontent.com/Yota-K/dotfiles/main/.claude/agents/refactor-cleaner.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/Yota-K/dotfiles/main/.claude/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/verify-app.md https://raw.githubusercontent.com/Yota-K/dotfiles/main/.claude/agents/verify-app.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(**/.env)",
"Edit(**/.env.production)",
"Bash(rm -rf /)",
"Bash(rm -rf ~)",
"Bash(rm -rf /*)",
"Bash(sudo rm:*)",
"Bash(sudo dd:*)",
"Bash(sudo mkfs:*)",
"Bash(sudo fdisk:*)",
"Bash(sudo mount:*)",
"Bash(sudo umount:*)",
"Bash(dd:*)",
"Bash(mkfs:*)",
"Bash(fdisk:*)",
"Bash(> /dev/*)",
"Bash(>> /dev/*)",
"Bash(chmod 777 /*)",
"Bash(chown root:*)",
"Bash(sudo chmod 777:*)",
"Bash(sudo chown:*)",
"Bash(sudo -i:*)",
"Bash(sudo su:*)",
"Bash(rm -rf .git)",
"Bash(git push --force-with-lease origin main)",
"Bash(git push -f origin main)",
"Bash(docker system prune -af)",
"Bash(npm publish:*)",
"Bash(deno publish:*)",
"mcp__supabase__apply_migration",
"Edit(/etc/**)",
"Edit(/usr/**)",
"Edit(/var/**)",
"Edit(/opt/**)",
"Edit(/bin/**)",
"Edit(/sbin/**)",
"Edit(/lib/**)",
"Edit(/lib64/**)",
"Edit(/boot/**)",
"Edit(/proc/**)",
"Edit(/sys/**)",
"Edit(/dev/**)",
"Edit(~/.ssh/id_*)",
"Edit(~/.ssh/*_rsa)",
"Edit(~/.ssh/*_ecdsa)",
"Edit(~/.ssh/*_ed25519)",
"Edit(/etc/passwd)",
"Edit(/etc/shadow)",
"Edit(/etc/sudoers)"
]
}
} Skills (4)
Subagents (3)
| refactor-cleaner model: opus | デッドコードのクリーンアップと統合を専門とするエージェント。未使用コード、重複コード、不要なエクスポートの削除を**積極的に**行う。knip / depcheck / ts-prune などの分析ツールを実行し、安全に削除する。 |
| security-reviewer model: opus | セキュリティ脆弱性の検出と修正の専門家。ユーザー入力、認証、APIエンドポイント、機密データを扱うコード記述後に積極的に使用。シークレット、SSRF、インジェクション、安全でない暗号化、OWASP Top 10脆弱性をフラグ付け。 |
| verify-app model: opus | push前の変更の包括的な検証 - テスト、型チェック、Lint、手動チェック |
Hooks (2)
| event | matcher | runs |
|---|---|---|
| Notification | * | if [ "$(uname)" = "Darwin" ]; then osascript -e 'display notification "Claude Code needs your attention" with title "Claude Code"'; fi |
| SessionEnd | * | input=$(cat); cwd=$(printf '%s' "$input" | jq -r '.cwd // empty'); [ -n "$cwd" ] || exit 0; gitdir=$(git -C "$cwd" rev-parse --absolute-git-dir 2>/dev/null) || exit 0; case "$gitdir" in */.git/worktrees/*) ;; *) exit 0 ;; esac; if [ -n "$(g |
Plugins (2)
gopls-lsp@claude-plugins-officialsecurity-guidance@claude-plugins-official
Permissions
deny (48)
Read(**/.env)
Edit(**/.env.production)
Bash(rm -rf /)
Bash(rm -rf ~)
Bash(rm -rf /*)
Bash(sudo rm:*)
Bash(sudo dd:*)
Bash(sudo mkfs:*)
Bash(sudo fdisk:*)
Bash(sudo mount:*)
Bash(sudo umount:*)
Bash(dd:*)
Bash(mkfs:*)
Bash(fdisk:*)
Bash(> /dev/*)
Bash(>> /dev/*)
Bash(chmod 777 /*)
Bash(chown root:*)
Bash(sudo chmod 777:*)
Bash(sudo chown:*)
Bash(sudo -i:*)
Bash(sudo su:*)
Bash(rm -rf .git)
Bash(git push --force-with-lease origin main)
Bash(git push -f origin main)
Bash(docker system prune -af)
Bash(npm publish:*)
Bash(deno publish:*)
mcp__supabase__apply_migration
Edit(/etc/**)
Edit(/usr/**)
Edit(/var/**)
Edit(/opt/**)
Edit(/bin/**)
Edit(/sbin/**)
Edit(/lib/**)
Edit(/lib64/**)
Edit(/boot/**)
Edit(/proc/**)
Edit(/sys/**)
Edit(/dev/**)
Edit(~/.ssh/id_*)
Edit(~/.ssh/*_rsa)
Edit(~/.ssh/*_ecdsa)
Edit(~/.ssh/*_ed25519)
Edit(/etc/passwd)
Edit(/etc/shadow)
Edit(/etc/sudoers)
ask (0)
—
allow (13)
WebFetch(domain:github.com)
WebFetch(domain:docs.anthropic.com)
WebFetch(domain:zenn.dev)
WebSearch
Bash(gh pr view:*)
Bash(gh run view:*)
Bash(gh pr list:*)
Bash(gh issue view:*)
Bash(ls:*)
Bash(cat:*)
Bash(git fetch:*)
Bash(git push:*)
Bash(pnpm install:*)
Similar rigs
vuhuucuong/dotfiles
My Neovim config and relevant stuff
Pragmatist 3.9k tok ·
Seme4eg/dotfiles
My $HOME
Pragmatist 681 tok ·
kjuq/dotfiles
My ultimate dotfiles
Minimalist 309 tok ·
Yuutokata/claude-code-setup
🔄 One Claude Code setup for my desktop and MacBook, synced through git, with guardrails that keep secrets out.
Fort Knox 1.1k tok ·