~ / rigs / clever-cc-plugins / cc-config

clever-cc-plugins/cc-config

Two Claude Code skills for setting up and maintaining a best-practice Claude Code configuration, distributed as a Claude Code plugin.

↗ GitHub ★ 1 MIT updated 5d ago personal setup Claude Code Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.2k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit clever-cc-plugins/cc-config/.claude ./rig-cc-config  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit clever-cc-plugins/cc-config/plugins/cc-config/skills/auditing-config .claude/skills/auditing-config
$ npx degit clever-cc-plugins/cc-config/plugins/cc-config/skills/bootstrapping-config .claude/skills/bootstrapping-config

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.local)",
      "Read(./.env.*.local)",
      "Read(./.env.development)",
      "Read(./.env.production)",
      "Read(./.env.staging)",
      "Read(./.env.test)",
      "Read(./secrets/**)",
      "Bash(rm -rf:*)",
      "Bash(curl:*)",
      "Bash(wget:*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Read|Edit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "bash .claude/guard-secret-files.sh"
          }
        ]
      }
    ]
  }
}

Skills (2)

Hooks (2)

eventmatcherruns
PreToolUseRead|Edit|Writebash .claude/guard-secret-files.sh
PostToolUseEdit|Writebash .claude/format-markdown.sh

Permissions

deny (11)
Read(./.env)
Read(./.env.local)
Read(./.env.*.local)
Read(./.env.development)
Read(./.env.production)
Read(./.env.staging)
Read(./.env.test)
Read(./secrets/**)
Bash(rm -rf:*)
Bash(curl:*)
Bash(wget:*)
ask (0)
—
allow (2)
Bash(git *)
Bash(chmod +x *)

Similar rigs

copied ✓