~ / rigs / daviguides / entryway

daviguides/entryway

Claude Code starter kit — settings, hooks, status line, and notifications

↗ GitHub ★ 0 MIT updated 3mo ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~812 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

$ git clone --depth 1 https://github.com/daviguides/entryway

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf:*)",
      "Bash(git push --force:*)",
      "Bash(git reset --hard:*)",
      "Bash(git clean -fd:*)",
      "Bash(sudo:*)",
      "Bash(chmod 777:*)",
      "Bash(chown:*)",
      "Read(//**/.env)",
      "Read(//**/secrets/**)",
      "Bash(nc:*)"
    ],
    "ask": [
      "Bash(gh repo create:*)",
      "Bash(gh repo delete:*)",
      "Bash(gh release create:*)",
      "Bash(rm:*)",
      "Bash(curl:*)",
      "Bash(wget:*)"
    ]
  }
}

Hooks (4)

eventmatcherruns
SessionStart*$HOME/.local/share/entryway/scripts/session-start-loader.sh
Stop*claude_notifier
Notification*claude_notifier
UserPromptSubmit*slash_command

Permissions

deny (10)
Bash(rm -rf:*)
Bash(git push --force:*)
Bash(git reset --hard:*)
Bash(git clean -fd:*)
Bash(sudo:*)
Bash(chmod 777:*)
Bash(chown:*)
Read(//**/.env)
Read(//**/secrets/**)
Bash(nc:*)
ask (6)
Bash(gh repo create:*)
Bash(gh repo delete:*)
Bash(gh release create:*)
Bash(rm:*)
Bash(curl:*)
Bash(wget:*)
allow (49)
Bash(chmod:*)
Bash(echo:*)
Bash(cat:*)
Bash(test:*)
Bash(find:*)
Bash(tree:*)
Bash(mv:*)
Bash(mkdir:*)
Bash(timeout:*)
Bash(awk:*)
Bash(xargs:*)
Bash(basename:*)
Bash(sort:*)
Bash(for:*)
Bash(while:*)
Bash(do:*)
Bash(if:*)
Bash(then:*)
Bash(else:*)
Bash(fi:*)
Bash(done:*)
Bash(uv:*)
Bash(uv run pytest:*)
Bash(uv add:*)
Bash(python3:*)
Bash(python:*)
Bash(git init)
Bash(git config:*)
Bash(git add:*)
Bash(git rm:*)
Bash(git checkout:*)
Bash(git diff:*)
Bash(git -C:*)
Bash(git commit:*)
Bash(git push)
Bash(gh --version)
Bash(gh pr:*)
Bash(gh repo:*)
Bash(gh api:*)
Bash(git mv:*)
Bash(git branch:*)
Bash(git log:*)
Bash(make:*)
WebSearch
SlashCommand(/:*)
SlashCommand(/*:*)
Bash(git merge:*)
Bash(git rebase:*)
Bash(gh pr merge:*)

Similar rigs

copied ✓