coil398/dotfiles
my best dotfiles.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code $ claude mcp add context7 -- npx -y @upstash/context7-mcp $ npx degit coil398/dotfiles/.claude ./rig-dotfiles # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add context7 -- npx -y @upstash/context7-mcp $ npx degit coil398/dotfiles/.agents/skills/agent-cli .claude/skills/agent-cli $ npx degit coil398/dotfiles/.agents/skills/agent-skill-migrate .claude/skills/agent-skill-migrate $ npx degit coil398/dotfiles/.agents/skills/ai-design-system .claude/skills/ai-design-system $ npx degit coil398/dotfiles/.agents/skills/ai-diary .claude/skills/ai-diary $ npx degit coil398/dotfiles/.agents/skills/ai-ltm .claude/skills/ai-ltm $ npx degit coil398/dotfiles/.agents/skills/brainstorm .claude/skills/brainstorm $ npx degit coil398/dotfiles/.agents/skills/chat .claude/skills/chat $ npx degit coil398/dotfiles/.agents/skills/check-updates .claude/skills/check-updates $ npx degit coil398/dotfiles/.agents/skills/code-review-guidance .claude/skills/code-review-guidance $ npx degit coil398/dotfiles/.agents/skills/codex .claude/skills/codex $ npx degit coil398/dotfiles/.agents/skills/debug .claude/skills/debug $ npx degit coil398/dotfiles/.agents/skills/deepplan .claude/skills/deepplan $ npx degit coil398/dotfiles/.agents/skills/deepseek-ops .claude/skills/deepseek-ops $ npx degit coil398/dotfiles/.agents/skills/deepthink .claude/skills/deepthink $ npx degit coil398/dotfiles/.agents/skills/design-review .claude/skills/design-review $ npx degit coil398/dotfiles/.agents/skills/diagram-design .claude/skills/diagram-design $ npx degit coil398/dotfiles/.agents/skills/directed-task-execution .claude/skills/directed-task-execution $ npx degit coil398/dotfiles/.agents/skills/dotfiles-autosync .claude/skills/dotfiles-autosync $ npx degit coil398/dotfiles/.agents/skills/epic .claude/skills/epic $ npx degit coil398/dotfiles/.agents/skills/field-notes .claude/skills/field-notes $ npx degit coil398/dotfiles/.agents/skills/git-sync .claude/skills/git-sync $ npx degit coil398/dotfiles/.agents/skills/instruction-refactor .claude/skills/instruction-refactor $ npx degit coil398/dotfiles/.agents/skills/ir .claude/skills/ir $ npx degit coil398/dotfiles/.agents/skills/jev .claude/skills/jev $ npx degit coil398/dotfiles/.agents/skills/overlay-audit .claude/skills/overlay-audit $ npx degit coil398/dotfiles/.agents/skills/pipeline-diagnose .claude/skills/pipeline-diagnose $ npx degit coil398/dotfiles/.agents/skills/pipeline-improve .claude/skills/pipeline-improve $ npx degit coil398/dotfiles/.agents/skills/pipeline .claude/skills/pipeline $ npx degit coil398/dotfiles/.agents/skills/pir2 .claude/skills/pir2 $ npx degit coil398/dotfiles/.agents/skills/prompt-budget .claude/skills/prompt-budget $ npx degit coil398/dotfiles/.agents/skills/python-toolchain .claude/skills/python-toolchain $ npx degit coil398/dotfiles/.agents/skills/refactor-advisor .claude/skills/refactor-advisor $ npx degit coil398/dotfiles/.agents/skills/research .claude/skills/research $ npx degit coil398/dotfiles/.agents/skills/retro .claude/skills/retro $ npx degit coil398/dotfiles/.agents/skills/review-pr .claude/skills/review-pr $ npx degit coil398/dotfiles/.agents/skills/reviewer .claude/skills/reviewer $ npx degit coil398/dotfiles/.agents/skills/sentinel-review .claude/skills/sentinel-review $ npx degit coil398/dotfiles/.agents/skills/tester .claude/skills/tester $ npx degit coil398/dotfiles/.agents/skills/walkthrough .claude/skills/walkthrough $ npx degit coil398/dotfiles/.agents/skills/writing-plan .claude/skills/writing-plan
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf *)",
"Bash(git push --force *)",
"Bash(git reset --hard *)",
"Bash(sudo *)",
"Bash(su *)",
"Read(**/node_modules/**)",
"Read(**/.next/**)",
"Read(**/.nuxt/**)",
"Read(**/dist/**)",
"Read(**/build/**)",
"Read(**/__pycache__/**)",
"Read(**/.venv/**)",
"Read(**/target/**)",
"Read(**/coverage/**)",
"Read(**/.turbo/**)",
"Read(**/.cache/**)",
"Read(**/package-lock.json)",
"Read(**/yarn.lock)",
"Read(**/pnpm-lock.yaml)",
"Bash(find * -delete*)",
"Bash(find * -exec*)",
"Bash(find * -ok*)",
"Bash(find * -fprint*)",
"Read(**/.zsh_secret)",
"Read(~/.zsh_secret)",
"Read(**/.env)",
"Read(**/.env.local)",
"Read(**/.env.*.local)",
"Read(**/.env.development)",
"Read(**/.env.production)",
"Read(**/.env.staging)",
"Read(**/.env.test)",
"Bash(find -delete*)",
"Bash(find * -fls*)",
"Bash(fd * -x*)",
"Bash(fd * -X*)",
"Bash(fd * --exec*)",
"Bash(rg * --pre*)",
"Bash(rg --pre*)",
"Bash(sort * -o*)",
"Bash(sort * --output*)",
"Bash(tree * -o*)",
"Bash(git branch -D*)",
"Bash(git branch * -D*)",
"Bash(git branch -d*)",
"Bash(git branch * -d*)",
"Bash(git diff * --output*)",
"Bash(*zsh_secret*)",
"Bash(*.env)",
"Bash(*.env *)",
"Bash(*.env.local*)",
"Bash(*.env.development*)",
"Bash(*.env.production*)",
"Bash(*.env.staging*)",
"Bash(*.env.test*)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Read(~/.config/gh/**)",
"Read(~/.gnupg/**)",
"Read(**/*.pem)",
"Bash(*.ssh/*)",
"Bash(*.aws/*)",
"Bash(*.config/gh/*)",
"Bash(*.gnupg/*)",
"Bash(*.pem*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "bash ~/.claude/hooks/foreign-project-name-guard.sh"
},
{
"type": "command",
"command": "bash ~/.claude/hooks/foreign-project-name-guard.sh"
},
{
"type": "command",
"command": "bash ~/.claude/hooks/foreign-project-name-guard.sh"
}
]
},
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "bash ~/.claude/lib/jev-hook.sh"
}
]
}
]
}
} MCP servers (2)
| server | source | est. tokens |
|---|---|---|
| Context7 | npm | 1.2k |
| hisyo | local / custom | 2.5k |
Skills (42)
agent-cliagent-skill-migrateai-design-systemai-diaryai-ltmbrainstormchatcheck-updatescode-review-guidancecodexdebugdeepplandeepseek-opsdeepthinkdesign-reviewdiagram-designdirected-task-executiondotfiles-autosyncepicfield-notesgit-syncinstruction-refactorirjevoverlay-auditpipeline-diagnosepipeline-improvepipelinepir2prompt-budgetpython-toolchainrefactor-advisorresearchretroreview-prreviewersentinel-reviewtesterwalkthroughwriting-planwsl-windowsgeminify
Hooks (15)
| event | matcher | runs |
|---|---|---|
| SessionStart | * | bash ~/.claude/lib/dotfiles-session-sync.sh |
| PreToolUse | Bash | bash ~/.claude/hooks/foreign-project-name-guard.sh |
| PreToolUse | Bash | bash ~/.claude/hooks/foreign-project-name-guard.sh |
| PreToolUse | Bash | bash ~/.claude/hooks/foreign-project-name-guard.sh |
| PreToolUse | * | bash ~/.claude/lib/jev-hook.sh |
| PostToolUse | Edit|Write|MultiEdit | bash ~/.claude/lib/sync-opencode-hook.sh |
| PostToolUse | Edit|Write|MultiEdit | bash ~/.claude/lib/sync-codex-hook.sh |
| PostToolUse | Edit|Write|MultiEdit | bash ~/.claude/lib/sync-devin-hook.sh |
| PostToolUse | Edit|Write|MultiEdit | bash ~/.claude/lib/shellcheck-hook.sh |
| PostToolUse | * | bash ~/.claude/lib/jev-hook.sh |
| Stop | * | bash ~/.claude/lib/parse-failure-continue-hook.sh |
| Stop | * | bash ~/.claude/lib/jev-hook.sh |
| UserPromptSubmit | * | bash ~/.claude/lib/jev-hook.sh |
| SubagentStop | * | bash ~/.claude/lib/jev-hook.sh |
| PostToolUseFailure | * | bash ~/.claude/lib/jev-hook.sh |
Plugins (7)
gopls-lsp@claude-plugins-officialskill-creator@claude-plugins-officialpyright-lsp@claude-plugins-officialtypescript-lsp@claude-plugins-officialclaude-md-management@claude-plugins-officialsecurity-guidance@claude-plugins-officialfigma@claude-plugins-official
Cursor rules (2)
shared-agents · alwaysskill-procedure · always
Permissions
deny (65)
Bash(rm -rf *)
Bash(git push --force *)
Bash(git reset --hard *)
Bash(sudo *)
Bash(su *)
Read(**/node_modules/**)
Read(**/.next/**)
Read(**/.nuxt/**)
Read(**/dist/**)
Read(**/build/**)
Read(**/__pycache__/**)
Read(**/.venv/**)
Read(**/target/**)
Read(**/coverage/**)
Read(**/.turbo/**)
Read(**/.cache/**)
Read(**/package-lock.json)
Read(**/yarn.lock)
Read(**/pnpm-lock.yaml)
Bash(find * -delete*)
Bash(find * -exec*)
Bash(find * -ok*)
Bash(find * -fprint*)
Read(**/.zsh_secret)
Read(~/.zsh_secret)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.*.local)
Read(**/.env.development)
Read(**/.env.production)
Read(**/.env.staging)
Read(**/.env.test)
Bash(find -delete*)
Bash(find * -fls*)
Bash(fd * -x*)
Bash(fd * -X*)
Bash(fd * --exec*)
Bash(rg * --pre*)
Bash(rg --pre*)
Bash(sort * -o*)
Bash(sort * --output*)
Bash(tree * -o*)
Bash(git branch -D*)
Bash(git branch * -D*)
Bash(git branch -d*)
Bash(git branch * -d*)
Bash(git diff * --output*)
Bash(*zsh_secret*)
Bash(*.env)
Bash(*.env *)
Bash(*.env.local*)
Bash(*.env.development*)
Bash(*.env.production*)
Bash(*.env.staging*)
Bash(*.env.test*)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gh/**)
Read(~/.gnupg/**)
Read(**/*.pem)
ask (0)
—
allow (66)
Read
Grep
Glob
Bash(git status *)
Bash(git log *)
Bash(git diff *)
Bash(git show *)
Bash(git branch *)
Bash(git stash list *)
Bash(gh issue list *)
Bash(gh issue view *)
Bash(gh pr list *)
Bash(gh pr view *)
Bash(gh run list *)
Bash(gh run view *)
Bash(ls *)
Bash(ls:*)
Bash(head *)
Bash(tail *)
Bash(cat *)
Bash(diff *)
Bash(wc *)
Bash(sort *)
Bash(find *)
Bash(find:*)
Bash(grep *)
Bash(grep:*)
Bash(rg *)
Bash(rg:*)
Bash(fd *)
Bash(fd:*)
Bash(tree *)
Bash(tree:*)
Bash(file *)
Bash(stat *)
Bash(pwd)
Bash(which *)
Bash(command -v *)
Bash(type *)
Bash(echo *)
Bash(printf *)
Bash(mkdir *)
Bash(mkdir -p:*)
Bash(touch *)
Bash(ps *)
Bash(df *)
Bash(du *)
Bash(date *)
Bash(uname *)
Bash(id)
Bash(whoami)
Bash(npm show *)
WebSearch
WebFetch
mcp__context7__resolve-library-id
Edit(~/.claude/projects/*/memory/**)
Edit(~/.ai-pir-runs/**)
Read(~/.ai-pir-runs/**)
Bash(ls ~/.ai-pir-runs/**)
Edit(docs/plans/**)
Similar rigs
bubacoder/dave-tools
Automation tools for AI-assisted software development — from spec to merged PR, plus reusable slash commands, skills, and agent configs for Claude Code and OpenCode.
Skill Collector 4.3k tok ·
zeuikli/claude-code-workspace
—
Orchestrator 3.3k tok ·
iamvirul/claude-setup
One-command Claude Code optimization - Staff engineer persona, rules, hooks, skills, agents
Minimalist 2.4k tok ·
nejcfurh/nejcfurh-claude
Personal global Claude Code configuration — rules, skills, agents, hooks, and settings that apply to every project.
Fort Knox 5.3k tok ·