~ / rigs / Yuutokata / claude-code-setup

Yuutokata/claude-code-setup

🔄 One Claude Code setup for my desktop and MacBook, synced through git, with guardrails that keep secrets out.

↗ GitHub ★ 0 MIT updated 2d ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.1k tokens
Featherweight · median rig: 2.2k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit Yuutokata/claude-code-setup/agents ./rig-claude-code-setup/agents
$ npx degit Yuutokata/claude-code-setup/commands ./rig-claude-code-setup/commands

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/architect.md
$ curl -fsSL --create-dirs -o .claude/agents/build-error-resolver.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/build-error-resolver.md
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/doc-updater.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/doc-updater.md
$ curl -fsSL --create-dirs -o .claude/agents/e2e-runner.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/e2e-runner.md
$ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/planner.md
$ curl -fsSL --create-dirs -o .claude/agents/refactor-cleaner.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/refactor-cleaner.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/security-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/tdd-guide.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/tdd-guide.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.local)",
      "Read(**/.env.dev)",
      "Read(**/.env.development)",
      "Read(**/.env.development.local)",
      "Read(**/.env.test)",
      "Read(**/.env.test.local)",
      "Read(**/.env.staging)",
      "Read(**/.env.prod)",
      "Read(**/.env.production)",
      "Read(**/.env.production.local)",
      "Read(**/.env.*.local)",
      "Read(**/secrets/**)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/*.pfx)",
      "Read(**/id_rsa*)",
      "Read(**/id_ed25519*)",
      "Read(**/.git-credentials)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(~/.azure/**)",
      "Read(~/.kube/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.config/gcloud/**)",
      "Read(~/AppData/Roaming/gcloud/**)",
      "Read(~/.config/gh/**)",
      "Read(~/AppData/Roaming/GitHub CLI/**)",
      "Read(~/.phase/**)",
      "Read(~/.docker/config.json)",
      "Read(~/.npmrc)",
      "Read(~/.pypirc)",
      "Read(~/.netrc)",
      "Read(~/.claude/.credentials.json)",
      "Bash(cat *.env*)",
      "Bash(head *.env*)",
      "Bash(tail *.env*)",
      "Bash(less *.env*)",
      "Bash(more *.env*)",
      "Bash(bat *.env*)",
      "Bash(cat ~/.ssh/*)",
      "Bash(cat ~/.aws/*)",
      "PowerShell(Get-Content *.env*)",
      "PowerShell(Get-Content ~/.ssh/*)",
      "PowerShell(Get-Content ~/.aws/*)",
      "Bash(git push --force*)",
      "PowerShell(git push --force*)",
      "Bash(git push -f*)",
      "PowerShell(git push -f*)",
      "Bash(git push * --force*)",
      "PowerShell(git push * --force*)",
      "Bash(git push * -f)",
      "PowerShell(git push * -f)",
      "Bash(git push * -f *)",
      "PowerShell(git push * -f *)",
      "Bash(git clean -fdx*)",
      "PowerShell(git clean -fdx*)",
      "Bash(git clean -xdf*)",
      "PowerShell(git clean -xdf*)",
      "Bash(rm -rf /)",
      "Bash(rm -rf /*)",
      "Bash(rm -rf ~)",
      "Bash(rm -rf ~/*)",
      "Bash(rm -rf .)",
      "Bash(rm -rf ..)",
      "Bash(rm -rf $HOME*)",
      "Bash(rm -fr /)",
      "Bash(rm -fr /*)",
      "Bash(rm -fr ~)",
      "Bash(rm -fr ~/*)",
      "Bash(rm * --no-preserve-root*)",
      "Bash(mkfs*)",
      "Bash(dd if=*)",
      "Bash(chmod -R 777 *)",
      "Bash(curl * | sh*)",
      "Bash(curl * | bash*)",
      "Bash(wget * | sh*)",
      "Bash(wget * | bash*)",
      "Bash(sh)"
    ],
    "ask": [
      "Bash(git push *)",
      "PowerShell(git push *)",
      "Bash(git reset --hard *)",
      "PowerShell(git reset --hard *)",
      "Bash(git clean *)",
      "PowerShell(git clean *)",
      "Bash(git branch -D *)",
      "PowerShell(git branch -D *)",
      "Bash(git rebase *)",
      "PowerShell(git rebase *)",
      "Bash(git restore *)",
      "PowerShell(git restore *)",
      "Bash(git checkout -- *)",
      "PowerShell(git checkout -- *)",
      "Bash(git checkout .)",
      "PowerShell(git checkout .)",
      "Bash(npm install *)",
      "PowerShell(npm install *)",
      "Bash(npm i *)",
      "PowerShell(npm i *)",
      "Bash(pnpm add *)",
      "PowerShell(pnpm add *)",
      "Bash(pnpm install *)",
      "PowerShell(pnpm install *)",
      "Bash(yarn add *)",
      "PowerShell(yarn add *)",
      "Bash(pip install *)",
      "PowerShell(pip install *)",
      "Bash(pip3 install *)",
      "PowerShell(pip3 install *)",
      "Bash(python -m pip install *)",
      "PowerShell(python -m pip install *)",
      "Bash(uv add *)",
      "PowerShell(uv add *)",
      "Bash(uv pip install *)",
      "PowerShell(uv pip install *)",
      "Bash(docker compose up *)",
      "PowerShell(docker compose up *)",
      "Bash(docker compose down *)",
      "PowerShell(docker compose down *)",
      "Bash(docker compose exec *)",
      "PowerShell(docker compose exec *)",
      "Bash(docker compose run *)",
      "PowerShell(docker compose run *)",
      "Bash(docker restart *)",
      "PowerShell(docker restart *)",
      "Bash(docker stop *)",
      "PowerShell(docker stop *)",
      "Bash(docker kill *)",
      "PowerShell(docker kill *)",
      "Bash(docker rm *)",
      "PowerShell(docker rm *)",
      "Bash(docker run *)",
      "PowerShell(docker run *)",
      "Bash(docker exec *)",
      "PowerShell(docker exec *)",
      "Bash(docker volume *)",
      "PowerShell(docker volume *)",
      "Bash(docker system prune *)",
      "PowerShell(docker system prune *)",
      "Bash(mongosh *)",
      "PowerShell(mongosh *)",
      "Bash(mongo *)",
      "PowerShell(mongo *)",
      "Bash(mongodump *)",
      "PowerShell(mongodump *)",
      "Bash(mongorestore *)",
      "PowerShell(mongorestore *)",
      "Bash(mongoexport *)",
      "PowerShell(mongoexport *)",
      "Bash(mongoimport *)",
      "PowerShell(mongoimport *)",
      "Bash(gh pr create *)",
      "PowerShell(gh pr create *)",
      "Bash(gh pr merge *)",
      "PowerShell(gh pr merge *)",
      "Bash(gh pr close *)",
      "PowerShell(gh pr close *)",
      "Bash(gh pr edit *)",
      "PowerShell(gh pr edit *)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|PowerShell",
        "hooks": [
          {
            "type": "command",
            "command": "node \"$HOME/.claude/scripts/hooks/bash-guard.js\""
          }
        ]
      }
    ]
  }
}

Subagents (9)

architect
model: opus
Software architecture specialist for system design, trade-off analysis and technical decisions. Use for larger features, cross-service changes or architectural decisions.
build-error-resolver
model: sonnet
Fixes build, compile and type errors with minimal changes. Use when a build, a Gradle run, a Docker build or a type check fails. No architectural changes.
code-reviewer
model: sonnet
Code review specialist for quality, security and maintainability in Python, Kotlin, Docker and React changes. Use after larger code changes, before merging.
doc-updater
model: haiku
Use to bring README, docs/, API docs and env var tables back in sync with code after changes, and to generate docs/CODEMAPS only when the user asks for codemaps.
e2e-runner
model: sonnet
Use for writing, running and debugging Playwright end-to-end tests of the React frontend's browser flows, plus API smoke tests against a running FastAPI or Ktor service.
planner
model: opus
Planning specialist that turns larger features, refactors or architectural changes into phased implementation plans. Use before coding; it waits for user confirmation before any code is written.
refactor-cleaner
model: sonnet
Dead code and duplicate cleanup specialist for Python, Kotlin, TypeScript and Docker projects. Use when asked to remove unused code or dependencies, or for cleanup of larger refactors.
security-reviewer
model: sonnet
Use after writing code that handles input, auth, secrets or infra, and for Docker/Compose/Traefik/Dokploy/MongoDB/Phase security checks. Finds secrets, injection, authz gaps, and misconfigurations.
tdd-guide
model: sonnet
Test-first specialist. Use for new logic, bug fixes and refactorings where a test is worthwhile. Writes a failing test first, then the minimal implementation.

Hooks (5)

eventmatcherruns
SessionStartstartup|resumebash "$HOME/.claude/scripts/hooks/sync.sh"
SessionEnd*bash "$HOME/.claude/scripts/hooks/push.sh"
Notificationpermission_prompt|idle_prompt|elicitation_dialognode "$HOME/.claude/scripts/hooks/notify.js"
PreToolUseBash|PowerShellnode "$HOME/.claude/scripts/hooks/bash-guard.js"
PostToolUseEdit|Writenode "$HOME/.claude/scripts/hooks/format-on-edit.js"

Slash commands (11)

/build-fix/checkpoint/e2e/eval/learn/orchestrate/plan/refactor-clean/test-coverage/update-docs/verify

Plugins (2)

superpowers@superpowers-marketplacekotlin-lsp@claude-plugins-official

Permissions

deny (103)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.dev)
Read(**/.env.development)
Read(**/.env.development.local)
Read(**/.env.test)
Read(**/.env.test.local)
Read(**/.env.staging)
Read(**/.env.prod)
Read(**/.env.production)
Read(**/.env.production.local)
Read(**/.env.*.local)
Read(**/secrets/**)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/id_rsa*)
Read(**/id_ed25519*)
Read(**/.git-credentials)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.kube/**)
Read(~/.gnupg/**)
Read(~/.config/gcloud/**)
Read(~/AppData/Roaming/gcloud/**)
Read(~/.config/gh/**)
Read(~/AppData/Roaming/GitHub CLI/**)
Read(~/.phase/**)
Read(~/.docker/config.json)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.netrc)
Read(~/.claude/.credentials.json)
Bash(cat *.env*)
Bash(head *.env*)
Bash(tail *.env*)
Bash(less *.env*)
Bash(more *.env*)
Bash(bat *.env*)
Bash(cat ~/.ssh/*)
Bash(cat ~/.aws/*)
PowerShell(Get-Content *.env*)
PowerShell(Get-Content ~/.ssh/*)
PowerShell(Get-Content ~/.aws/*)
Bash(git push --force*)
PowerShell(git push --force*)
Bash(git push -f*)
PowerShell(git push -f*)
Bash(git push * --force*)
PowerShell(git push * --force*)
Bash(git push * -f)
PowerShell(git push * -f)
Bash(git push * -f *)
PowerShell(git push * -f *)
Bash(git clean -fdx*)
PowerShell(git clean -fdx*)
Bash(git clean -xdf*)
PowerShell(git clean -xdf*)
ask (118)
Bash(git push *)
PowerShell(git push *)
Bash(git reset --hard *)
PowerShell(git reset --hard *)
Bash(git clean *)
PowerShell(git clean *)
Bash(git branch -D *)
PowerShell(git branch -D *)
Bash(git rebase *)
PowerShell(git rebase *)
Bash(git restore *)
PowerShell(git restore *)
Bash(git checkout -- *)
PowerShell(git checkout -- *)
Bash(git checkout .)
PowerShell(git checkout .)
Bash(npm install *)
PowerShell(npm install *)
Bash(npm i *)
PowerShell(npm i *)
Bash(pnpm add *)
PowerShell(pnpm add *)
Bash(pnpm install *)
PowerShell(pnpm install *)
Bash(yarn add *)
PowerShell(yarn add *)
Bash(pip install *)
PowerShell(pip install *)
Bash(pip3 install *)
PowerShell(pip3 install *)
Bash(python -m pip install *)
PowerShell(python -m pip install *)
Bash(uv add *)
PowerShell(uv add *)
Bash(uv pip install *)
PowerShell(uv pip install *)
Bash(docker compose up *)
PowerShell(docker compose up *)
Bash(docker compose down *)
PowerShell(docker compose down *)
Bash(docker compose exec *)
PowerShell(docker compose exec *)
Bash(docker compose run *)
PowerShell(docker compose run *)
Bash(docker restart *)
PowerShell(docker restart *)
Bash(docker stop *)
PowerShell(docker stop *)
Bash(docker kill *)
PowerShell(docker kill *)
Bash(docker rm *)
PowerShell(docker rm *)
Bash(docker run *)
PowerShell(docker run *)
Bash(docker exec *)
PowerShell(docker exec *)
Bash(docker volume *)
PowerShell(docker volume *)
Bash(docker system prune *)
PowerShell(docker system prune *)
allow (120)
Bash(git status*)
PowerShell(git status*)
Bash(git diff*)
PowerShell(git diff*)
Bash(git log*)
PowerShell(git log*)
Bash(git show*)
PowerShell(git show*)
Bash(git branch)
PowerShell(git branch)
Bash(git branch --list*)
PowerShell(git branch --list*)
Bash(git fetch*)
PowerShell(git fetch*)
Bash(git add *)
PowerShell(git add *)
Bash(git commit *)
PowerShell(git commit *)
Bash(git switch *)
PowerShell(git switch *)
Bash(git stash *)
PowerShell(git stash *)
Bash(git checkout *)
Bash(gh repo view *)
Bash(gh issue list *)
Bash(gh issue view *)
Bash(gh pr list *)
Bash(gh pr view *)
Bash(gh pr diff *)
Bash(gh pr checks *)
Bash(gh run list *)
Bash(gh run view *)
Bash(gh api *)
Bash(pytest*)
PowerShell(pytest*)
Bash(python -m pytest*)
PowerShell(python -m pytest*)
Bash(uv run pytest*)
PowerShell(uv run pytest*)
Bash(ruff *)
PowerShell(ruff *)
Bash(uv run ruff *)
PowerShell(uv run ruff *)
Bash(python -m ruff *)
PowerShell(python -m ruff *)
Bash(mypy *)
PowerShell(mypy *)
Bash(uv run mypy *)
PowerShell(uv run mypy *)
Bash(python -m mypy *)
PowerShell(python -m mypy *)
Bash(./gradlew test*)
PowerShell(./gradlew test*)
Bash(./gradlew build*)
PowerShell(./gradlew build*)
Bash(./gradlew check*)
PowerShell(./gradlew check*)
Bash(./gradlew compile*)
PowerShell(./gradlew compile*)
Bash(./gradlew assemble*)

Similar rigs

copied ✓