daviguides/entryway
Claude Code starter kit — settings, hooks, status line, and notifications
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
$ git clone --depth 1 https://github.com/daviguides/entryway MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf:*)",
"Bash(git push --force:*)",
"Bash(git reset --hard:*)",
"Bash(git clean -fd:*)",
"Bash(sudo:*)",
"Bash(chmod 777:*)",
"Bash(chown:*)",
"Read(//**/.env)",
"Read(//**/secrets/**)",
"Bash(nc:*)"
],
"ask": [
"Bash(gh repo create:*)",
"Bash(gh repo delete:*)",
"Bash(gh release create:*)",
"Bash(rm:*)",
"Bash(curl:*)",
"Bash(wget:*)"
]
}
} Hooks (4)
| event | matcher | runs |
|---|---|---|
| SessionStart | * | $HOME/.local/share/entryway/scripts/session-start-loader.sh |
| Stop | * | claude_notifier |
| Notification | * | claude_notifier |
| UserPromptSubmit | * | slash_command |
Permissions
deny (10)
Bash(rm -rf:*)
Bash(git push --force:*)
Bash(git reset --hard:*)
Bash(git clean -fd:*)
Bash(sudo:*)
Bash(chmod 777:*)
Bash(chown:*)
Read(//**/.env)
Read(//**/secrets/**)
Bash(nc:*)
ask (6)
Bash(gh repo create:*)
Bash(gh repo delete:*)
Bash(gh release create:*)
Bash(rm:*)
Bash(curl:*)
Bash(wget:*)
allow (49)
Bash(chmod:*)
Bash(echo:*)
Bash(cat:*)
Bash(test:*)
Bash(find:*)
Bash(tree:*)
Bash(mv:*)
Bash(mkdir:*)
Bash(timeout:*)
Bash(awk:*)
Bash(xargs:*)
Bash(basename:*)
Bash(sort:*)
Bash(for:*)
Bash(while:*)
Bash(do:*)
Bash(if:*)
Bash(then:*)
Bash(else:*)
Bash(fi:*)
Bash(done:*)
Bash(uv:*)
Bash(uv run pytest:*)
Bash(uv add:*)
Bash(python3:*)
Bash(python:*)
Bash(git init)
Bash(git config:*)
Bash(git add:*)
Bash(git rm:*)
Bash(git checkout:*)
Bash(git diff:*)
Bash(git -C:*)
Bash(git commit:*)
Bash(git push)
Bash(gh --version)
Bash(gh pr:*)
Bash(gh repo:*)
Bash(gh api:*)
Bash(git mv:*)
Bash(git branch:*)
Bash(git log:*)
Bash(make:*)
WebSearch
SlashCommand(/:*)
SlashCommand(/*:*)
Bash(git merge:*)
Bash(git rebase:*)
Bash(gh pr merge:*)
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·