babushkai/claude-code-config
Production-ready Claude Code configuration defaults. Hooks, Skills, Rules, Permissions, MCP — one-command setup.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit babushkai/claude-code-config/.claude ./rig-claude-code-config # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit babushkai/claude-code-config/.claude/skills/deploy .claude/skills/deploy $ npx degit babushkai/claude-code-config/.claude/skills/explain-code .claude/skills/explain-code $ npx degit babushkai/claude-code-config/.claude/skills/fix-issue .claude/skills/fix-issue $ npx degit babushkai/claude-code-config/.claude/skills/review-pr .claude/skills/review-pr $ npx degit babushkai/claude-code-config/.claude/skills/status .claude/skills/status
$ curl -fsSL --create-dirs -o .claude/agents/AGENT.md https://raw.githubusercontent.com/babushkai/claude-code-config/main/.claude/agents/security-reviewer/AGENT.md Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(git push --force *)",
"Bash(git push --force-with-lease *)",
"Bash(git reset --hard *)",
"Bash(git clean -fd *)",
"Bash(git clean -f *)",
"Bash(rm -rf *)",
"Bash(rm -r *)",
"Bash(rmdir *)",
"Bash(curl *)",
"Bash(wget *)",
"Bash(ssh *)",
"Bash(scp *)",
"Bash(sudo *)",
"Bash(chmod 777 *)",
"Bash(kill -9 *)",
"Bash(pkill *)",
"Read(.env*)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/*secret*)",
"Read(**/*credential*)",
"Read(**/.ssh/*)",
"Edit(.env*)",
"Edit(**/*.pem)",
"Edit(**/*.key)",
"Edit(/.github/workflows/**)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-commands.sh"
}
]
},
{
"matcher": "Edit|Write",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-protected-files.sh"
}
]
}
]
}
} Skills (5)
Subagents (1)
| security-reviewer model: sonnet | Review code changes for security vulnerabilities, secret leaks, and OWASP Top 10 issues |
Hooks (6)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-dangerous-commands.sh |
| PreToolUse | Edit|Write | "$CLAUDE_PROJECT_DIR"/.claude/hooks/block-protected-files.sh |
| PostToolUse | Edit|Write | "$CLAUDE_PROJECT_DIR"/.claude/hooks/lint-on-save.sh |
| PostToolUse | Edit|Write | "$CLAUDE_PROJECT_DIR"/.claude/hooks/format-on-save.sh |
| Stop | * | "$CLAUDE_PROJECT_DIR"/.claude/hooks/notify-completion.sh |
| SessionStart | startup|resume | "$CLAUDE_PROJECT_DIR"/.claude/hooks/log-session.sh |
Permissions
deny (26)
Bash(git push --force *)
Bash(git push --force-with-lease *)
Bash(git reset --hard *)
Bash(git clean -fd *)
Bash(git clean -f *)
Bash(rm -rf *)
Bash(rm -r *)
Bash(rmdir *)
Bash(curl *)
Bash(wget *)
Bash(ssh *)
Bash(scp *)
Bash(sudo *)
Bash(chmod 777 *)
Bash(kill -9 *)
Bash(pkill *)
Read(.env*)
Read(**/*.pem)
Read(**/*.key)
Read(**/*secret*)
Read(**/*credential*)
Read(**/.ssh/*)
Edit(.env*)
Edit(**/*.pem)
Edit(**/*.key)
Edit(/.github/workflows/**)
ask (0)
—
allow (28)
Read
Glob
Grep
Bash(pnpm *)
Bash(npm run *)
Bash(npx *)
Bash(git status)
Bash(git diff *)
Bash(git log *)
Bash(git branch *)
Bash(git checkout *)
Bash(git switch *)
Bash(git add *)
Bash(git commit *)
Bash(git stash *)
Bash(git show *)
Bash(git blame *)
Bash(gh pr *)
Bash(gh issue *)
Bash(gh run *)
Bash(* --version)
Bash(* --help)
Bash(which *)
Bash(echo *)
Bash(cat package.json)
Bash(wc *)
Bash(date *)
Bash(ls *)
Similar rigs
peterkimpro/claude-code-powerpack
Drop-in Claude Code config for efficient AI-assisted development. Includes CLAUDE.md template, permission allowlist, agents, skills, and memory system.
Pragmatist 4.4k tok ·
AI-BrandFactory/claude-code-starter-pack
Working templates for Claude Code primitives: slash commands, skills, hooks, subagents, MCP configs, Agent SDK starters. Current to Opus 4.7, April 2026.
Fort Knox 584 tok ·
crampeddamselfly/claude-dotfiles
—
YOLO Cowboy 1.5k tok ·
Seme4eg/dotfiles
My $HOME
Pragmatist 681 tok ·