~ / rigs / bagdeli / KavoshStart

bagdeli/KavoshStart

Kavosh engineering standard: intake, rules, templates and reusable GitHub workflows for projects built by humans and AI agents (GitHub Free).

↗ GitHub ★ 1 no license updated today project Claude CodeCodexGemini CLICopilot
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~2.2k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit bagdeli/KavoshStart/.claude ./rig-kavoshstart  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(git push origin main:*)",
      "Bash(git push origin HEAD:main:*)",
      "Bash(git push -u origin main:*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git push --no-verify:*)",
      "Bash(git commit --no-verify:*)",
      "Bash(git config core.hooksPath:*)",
      "Bash(git branch -D:*)",
      "Bash(git push origin --delete:*)",
      "Bash(git tag -d:*)",
      "Bash(gh pr merge --admin:*)",
      "Bash(gh repo delete:*)",
      "Bash(gh release delete:*)",
      "Read(./**/secrets/**)",
      "Bash(git push origin main:*)",
      "Bash(git push origin HEAD:main:*)",
      "Bash(git push -u origin main:*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git push --no-verify:*)",
      "Bash(git commit --no-verify:*)",
      "Bash(git config core.hooksPath:*)",
      "Bash(git branch -D:*)",
      "Bash(git push origin --delete:*)",
      "Bash(git tag -d:*)",
      "Bash(gh pr merge --admin:*)",
      "Bash(gh repo delete:*)",
      "Bash(gh release delete:*)",
      "Read(./**/secrets/**)"
    ],
    "ask": [
      "Bash(gh pr merge:*)",
      "Bash(gh issue close:*)",
      "Bash(gh pr close:*)",
      "Bash(gh api -X DELETE:*)",
      "Read(./.env)",
      "Read(./.env.*)",
      "Bash(gh pr merge:*)",
      "Bash(gh issue close:*)",
      "Bash(gh pr close:*)",
      "Bash(gh api -X DELETE:*)",
      "Read(./.env)",
      "Read(./.env.*)"
    ]
  }
}

Permissions

deny (30)
Bash(git push origin main:*)
Bash(git push origin HEAD:main:*)
Bash(git push -u origin main:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git push --no-verify:*)
Bash(git commit --no-verify:*)
Bash(git config core.hooksPath:*)
Bash(git branch -D:*)
Bash(git push origin --delete:*)
Bash(git tag -d:*)
Bash(gh pr merge --admin:*)
Bash(gh repo delete:*)
Bash(gh release delete:*)
Read(./**/secrets/**)
Bash(git push origin main:*)
Bash(git push origin HEAD:main:*)
Bash(git push -u origin main:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git push --no-verify:*)
Bash(git commit --no-verify:*)
Bash(git config core.hooksPath:*)
Bash(git branch -D:*)
Bash(git push origin --delete:*)
Bash(git tag -d:*)
Bash(gh pr merge --admin:*)
Bash(gh repo delete:*)
Bash(gh release delete:*)
Read(./**/secrets/**)
ask (12)
Bash(gh pr merge:*)
Bash(gh issue close:*)
Bash(gh pr close:*)
Bash(gh api -X DELETE:*)
Read(./.env)
Read(./.env.*)
Bash(gh pr merge:*)
Bash(gh issue close:*)
Bash(gh pr close:*)
Bash(gh api -X DELETE:*)
Read(./.env)
Read(./.env.*)
allow (0)
—

Similar rigs

copied ✓