Yuutokata/claude-code-setup
🔄 One Claude Code setup for my desktop and MacBook, synced through git, with guardrails that keep secrets out.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ npx degit Yuutokata/claude-code-setup/agents ./rig-claude-code-setup/agents $ npx degit Yuutokata/claude-code-setup/commands ./rig-claude-code-setup/commands
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/architect.md $ curl -fsSL --create-dirs -o .claude/agents/build-error-resolver.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/build-error-resolver.md $ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/code-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/doc-updater.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/doc-updater.md $ curl -fsSL --create-dirs -o .claude/agents/e2e-runner.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/e2e-runner.md $ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/planner.md $ curl -fsSL --create-dirs -o .claude/agents/refactor-cleaner.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/refactor-cleaner.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/tdd-guide.md https://raw.githubusercontent.com/Yuutokata/claude-code-setup/main/agents/tdd-guide.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(**/.env)",
"Read(**/.env.local)",
"Read(**/.env.dev)",
"Read(**/.env.development)",
"Read(**/.env.development.local)",
"Read(**/.env.test)",
"Read(**/.env.test.local)",
"Read(**/.env.staging)",
"Read(**/.env.prod)",
"Read(**/.env.production)",
"Read(**/.env.production.local)",
"Read(**/.env.*.local)",
"Read(**/secrets/**)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/*.p12)",
"Read(**/*.pfx)",
"Read(**/id_rsa*)",
"Read(**/id_ed25519*)",
"Read(**/.git-credentials)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Read(~/.azure/**)",
"Read(~/.kube/**)",
"Read(~/.gnupg/**)",
"Read(~/.config/gcloud/**)",
"Read(~/AppData/Roaming/gcloud/**)",
"Read(~/.config/gh/**)",
"Read(~/AppData/Roaming/GitHub CLI/**)",
"Read(~/.phase/**)",
"Read(~/.docker/config.json)",
"Read(~/.npmrc)",
"Read(~/.pypirc)",
"Read(~/.netrc)",
"Read(~/.claude/.credentials.json)",
"Bash(cat *.env*)",
"Bash(head *.env*)",
"Bash(tail *.env*)",
"Bash(less *.env*)",
"Bash(more *.env*)",
"Bash(bat *.env*)",
"Bash(cat ~/.ssh/*)",
"Bash(cat ~/.aws/*)",
"PowerShell(Get-Content *.env*)",
"PowerShell(Get-Content ~/.ssh/*)",
"PowerShell(Get-Content ~/.aws/*)",
"Bash(git push --force*)",
"PowerShell(git push --force*)",
"Bash(git push -f*)",
"PowerShell(git push -f*)",
"Bash(git push * --force*)",
"PowerShell(git push * --force*)",
"Bash(git push * -f)",
"PowerShell(git push * -f)",
"Bash(git push * -f *)",
"PowerShell(git push * -f *)",
"Bash(git clean -fdx*)",
"PowerShell(git clean -fdx*)",
"Bash(git clean -xdf*)",
"PowerShell(git clean -xdf*)",
"Bash(rm -rf /)",
"Bash(rm -rf /*)",
"Bash(rm -rf ~)",
"Bash(rm -rf ~/*)",
"Bash(rm -rf .)",
"Bash(rm -rf ..)",
"Bash(rm -rf $HOME*)",
"Bash(rm -fr /)",
"Bash(rm -fr /*)",
"Bash(rm -fr ~)",
"Bash(rm -fr ~/*)",
"Bash(rm * --no-preserve-root*)",
"Bash(mkfs*)",
"Bash(dd if=*)",
"Bash(chmod -R 777 *)",
"Bash(curl * | sh*)",
"Bash(curl * | bash*)",
"Bash(wget * | sh*)",
"Bash(wget * | bash*)",
"Bash(sh)"
],
"ask": [
"Bash(git push *)",
"PowerShell(git push *)",
"Bash(git reset --hard *)",
"PowerShell(git reset --hard *)",
"Bash(git clean *)",
"PowerShell(git clean *)",
"Bash(git branch -D *)",
"PowerShell(git branch -D *)",
"Bash(git rebase *)",
"PowerShell(git rebase *)",
"Bash(git restore *)",
"PowerShell(git restore *)",
"Bash(git checkout -- *)",
"PowerShell(git checkout -- *)",
"Bash(git checkout .)",
"PowerShell(git checkout .)",
"Bash(npm install *)",
"PowerShell(npm install *)",
"Bash(npm i *)",
"PowerShell(npm i *)",
"Bash(pnpm add *)",
"PowerShell(pnpm add *)",
"Bash(pnpm install *)",
"PowerShell(pnpm install *)",
"Bash(yarn add *)",
"PowerShell(yarn add *)",
"Bash(pip install *)",
"PowerShell(pip install *)",
"Bash(pip3 install *)",
"PowerShell(pip3 install *)",
"Bash(python -m pip install *)",
"PowerShell(python -m pip install *)",
"Bash(uv add *)",
"PowerShell(uv add *)",
"Bash(uv pip install *)",
"PowerShell(uv pip install *)",
"Bash(docker compose up *)",
"PowerShell(docker compose up *)",
"Bash(docker compose down *)",
"PowerShell(docker compose down *)",
"Bash(docker compose exec *)",
"PowerShell(docker compose exec *)",
"Bash(docker compose run *)",
"PowerShell(docker compose run *)",
"Bash(docker restart *)",
"PowerShell(docker restart *)",
"Bash(docker stop *)",
"PowerShell(docker stop *)",
"Bash(docker kill *)",
"PowerShell(docker kill *)",
"Bash(docker rm *)",
"PowerShell(docker rm *)",
"Bash(docker run *)",
"PowerShell(docker run *)",
"Bash(docker exec *)",
"PowerShell(docker exec *)",
"Bash(docker volume *)",
"PowerShell(docker volume *)",
"Bash(docker system prune *)",
"PowerShell(docker system prune *)",
"Bash(mongosh *)",
"PowerShell(mongosh *)",
"Bash(mongo *)",
"PowerShell(mongo *)",
"Bash(mongodump *)",
"PowerShell(mongodump *)",
"Bash(mongorestore *)",
"PowerShell(mongorestore *)",
"Bash(mongoexport *)",
"PowerShell(mongoexport *)",
"Bash(mongoimport *)",
"PowerShell(mongoimport *)",
"Bash(gh pr create *)",
"PowerShell(gh pr create *)",
"Bash(gh pr merge *)",
"PowerShell(gh pr merge *)",
"Bash(gh pr close *)",
"PowerShell(gh pr close *)",
"Bash(gh pr edit *)",
"PowerShell(gh pr edit *)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash|PowerShell",
"hooks": [
{
"type": "command",
"command": "node \"$HOME/.claude/scripts/hooks/bash-guard.js\""
}
]
}
]
}
} Subagents (9)
| architect model: opus | Software architecture specialist for system design, trade-off analysis and technical decisions. Use for larger features, cross-service changes or architectural decisions. |
| build-error-resolver model: sonnet | Fixes build, compile and type errors with minimal changes. Use when a build, a Gradle run, a Docker build or a type check fails. No architectural changes. |
| code-reviewer model: sonnet | Code review specialist for quality, security and maintainability in Python, Kotlin, Docker and React changes. Use after larger code changes, before merging. |
| doc-updater model: haiku | Use to bring README, docs/, API docs and env var tables back in sync with code after changes, and to generate docs/CODEMAPS only when the user asks for codemaps. |
| e2e-runner model: sonnet | Use for writing, running and debugging Playwright end-to-end tests of the React frontend's browser flows, plus API smoke tests against a running FastAPI or Ktor service. |
| planner model: opus | Planning specialist that turns larger features, refactors or architectural changes into phased implementation plans. Use before coding; it waits for user confirmation before any code is written. |
| refactor-cleaner model: sonnet | Dead code and duplicate cleanup specialist for Python, Kotlin, TypeScript and Docker projects. Use when asked to remove unused code or dependencies, or for cleanup of larger refactors. |
| security-reviewer model: sonnet | Use after writing code that handles input, auth, secrets or infra, and for Docker/Compose/Traefik/Dokploy/MongoDB/Phase security checks. Finds secrets, injection, authz gaps, and misconfigurations. |
| tdd-guide model: sonnet | Test-first specialist. Use for new logic, bug fixes and refactorings where a test is worthwhile. Writes a failing test first, then the minimal implementation. |
Hooks (5)
| event | matcher | runs |
|---|---|---|
| SessionStart | startup|resume | bash "$HOME/.claude/scripts/hooks/sync.sh" |
| SessionEnd | * | bash "$HOME/.claude/scripts/hooks/push.sh" |
| Notification | permission_prompt|idle_prompt|elicitation_dialog | node "$HOME/.claude/scripts/hooks/notify.js" |
| PreToolUse | Bash|PowerShell | node "$HOME/.claude/scripts/hooks/bash-guard.js" |
| PostToolUse | Edit|Write | node "$HOME/.claude/scripts/hooks/format-on-edit.js" |
Slash commands (11)
/build-fix/checkpoint/e2e/eval/learn/orchestrate/plan/refactor-clean/test-coverage/update-docs/verify
Plugins (2)
superpowers@superpowers-marketplacekotlin-lsp@claude-plugins-official
Permissions
deny (103)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.dev)
Read(**/.env.development)
Read(**/.env.development.local)
Read(**/.env.test)
Read(**/.env.test.local)
Read(**/.env.staging)
Read(**/.env.prod)
Read(**/.env.production)
Read(**/.env.production.local)
Read(**/.env.*.local)
Read(**/secrets/**)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/id_rsa*)
Read(**/id_ed25519*)
Read(**/.git-credentials)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.kube/**)
Read(~/.gnupg/**)
Read(~/.config/gcloud/**)
Read(~/AppData/Roaming/gcloud/**)
Read(~/.config/gh/**)
Read(~/AppData/Roaming/GitHub CLI/**)
Read(~/.phase/**)
Read(~/.docker/config.json)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.netrc)
Read(~/.claude/.credentials.json)
Bash(cat *.env*)
Bash(head *.env*)
Bash(tail *.env*)
Bash(less *.env*)
Bash(more *.env*)
Bash(bat *.env*)
Bash(cat ~/.ssh/*)
Bash(cat ~/.aws/*)
PowerShell(Get-Content *.env*)
PowerShell(Get-Content ~/.ssh/*)
PowerShell(Get-Content ~/.aws/*)
Bash(git push --force*)
PowerShell(git push --force*)
Bash(git push -f*)
PowerShell(git push -f*)
Bash(git push * --force*)
PowerShell(git push * --force*)
Bash(git push * -f)
PowerShell(git push * -f)
Bash(git push * -f *)
PowerShell(git push * -f *)
Bash(git clean -fdx*)
PowerShell(git clean -fdx*)
Bash(git clean -xdf*)
PowerShell(git clean -xdf*)
ask (118)
Bash(git push *)
PowerShell(git push *)
Bash(git reset --hard *)
PowerShell(git reset --hard *)
Bash(git clean *)
PowerShell(git clean *)
Bash(git branch -D *)
PowerShell(git branch -D *)
Bash(git rebase *)
PowerShell(git rebase *)
Bash(git restore *)
PowerShell(git restore *)
Bash(git checkout -- *)
PowerShell(git checkout -- *)
Bash(git checkout .)
PowerShell(git checkout .)
Bash(npm install *)
PowerShell(npm install *)
Bash(npm i *)
PowerShell(npm i *)
Bash(pnpm add *)
PowerShell(pnpm add *)
Bash(pnpm install *)
PowerShell(pnpm install *)
Bash(yarn add *)
PowerShell(yarn add *)
Bash(pip install *)
PowerShell(pip install *)
Bash(pip3 install *)
PowerShell(pip3 install *)
Bash(python -m pip install *)
PowerShell(python -m pip install *)
Bash(uv add *)
PowerShell(uv add *)
Bash(uv pip install *)
PowerShell(uv pip install *)
Bash(docker compose up *)
PowerShell(docker compose up *)
Bash(docker compose down *)
PowerShell(docker compose down *)
Bash(docker compose exec *)
PowerShell(docker compose exec *)
Bash(docker compose run *)
PowerShell(docker compose run *)
Bash(docker restart *)
PowerShell(docker restart *)
Bash(docker stop *)
PowerShell(docker stop *)
Bash(docker kill *)
PowerShell(docker kill *)
Bash(docker rm *)
PowerShell(docker rm *)
Bash(docker run *)
PowerShell(docker run *)
Bash(docker exec *)
PowerShell(docker exec *)
Bash(docker volume *)
PowerShell(docker volume *)
Bash(docker system prune *)
PowerShell(docker system prune *)
allow (120)
Bash(git status*)
PowerShell(git status*)
Bash(git diff*)
PowerShell(git diff*)
Bash(git log*)
PowerShell(git log*)
Bash(git show*)
PowerShell(git show*)
Bash(git branch)
PowerShell(git branch)
Bash(git branch --list*)
PowerShell(git branch --list*)
Bash(git fetch*)
PowerShell(git fetch*)
Bash(git add *)
PowerShell(git add *)
Bash(git commit *)
PowerShell(git commit *)
Bash(git switch *)
PowerShell(git switch *)
Bash(git stash *)
PowerShell(git stash *)
Bash(git checkout *)
Bash(gh repo view *)
Bash(gh issue list *)
Bash(gh issue view *)
Bash(gh pr list *)
Bash(gh pr view *)
Bash(gh pr diff *)
Bash(gh pr checks *)
Bash(gh run list *)
Bash(gh run view *)
Bash(gh api *)
Bash(pytest*)
PowerShell(pytest*)
Bash(python -m pytest*)
PowerShell(python -m pytest*)
Bash(uv run pytest*)
PowerShell(uv run pytest*)
Bash(ruff *)
PowerShell(ruff *)
Bash(uv run ruff *)
PowerShell(uv run ruff *)
Bash(python -m ruff *)
PowerShell(python -m ruff *)
Bash(mypy *)
PowerShell(mypy *)
Bash(uv run mypy *)
PowerShell(uv run mypy *)
Bash(python -m mypy *)
PowerShell(python -m mypy *)
Bash(./gradlew test*)
PowerShell(./gradlew test*)
Bash(./gradlew build*)
PowerShell(./gradlew build*)
Bash(./gradlew check*)
PowerShell(./gradlew check*)
Bash(./gradlew compile*)
PowerShell(./gradlew compile*)
Bash(./gradlew assemble*)
Similar rigs
cfrs2005/claude-init
Claude Code 中文开发套件 - 为中国开发者定制的零门槛 AI 编程环境。一键安装完整中文化体验,集成 MCP 服务器、智能上下文管理、安全扫描,支持免翻墙访问。让 AI 编程更简单。
Orchestrator 1.5k tok ·
mh2-lee/everything-claude-code
Complete Claude Code configuration collection - agents, skills, hooks, commands, rules, MCPs. Battle-tested configs from an Anthropic hackathon winner.
Orchestrator 1.2k tok ·
hirokami3/everything-claude-code
Claude Code configs collection - agents, skills, hooks, commands, rules, and MCP configurations
Orchestrator 1.2k tok ·
mrpilot01/everything-claude-code
Complete Claude Code configuration collection - agents, skills, hooks, commands, rules, MCPs. Battle-tested configs from an Anthropic hackathon winner.
Orchestrator 1.2k tok ·