~ / rigs / domengabrovsek / agent-config

domengabrovsek/agent-config

Shared agent configuration for Claude Code, Codex, and Pi. One AGENTS.md instruction source, 35 portable skills, 16 expert personas, and host adapters that wire each runtime to the same rules, hooks, and permission boundaries.

↗ GitHub ★ 17 no license updated 7d ago personal setup Claude CodeCodex
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~25.5k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add drawio -- npx -y @drawio/mcp
$ claude mcp add --transport http notion https://mcp.notion.com/mcp
$ claude mcp add --transport http slack https://mcp.slack.com/mcp
$ claude mcp add playwright -- npx -y @playwright/mcp@latest
$ npx degit domengabrovsek/agent-config/agents ./rig-agent-config/agents
$ npx degit domengabrovsek/agent-config/skills ./rig-agent-config/skills
$ npx degit domengabrovsek/agent-config/hooks ./rig-agent-config/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add drawio -- npx -y @drawio/mcp
$ claude mcp add --transport http notion https://mcp.notion.com/mcp
$ claude mcp add --transport http slack https://mcp.slack.com/mcp
$ claude mcp add playwright -- npx -y @playwright/mcp@latest
$ npx degit domengabrovsek/agent-config/skills/ci .claude/skills/ci
$ npx degit domengabrovsek/agent-config/skills/constraints .claude/skills/constraints
$ npx degit domengabrovsek/agent-config/skills/debug .claude/skills/debug
$ npx degit domengabrovsek/agent-config/skills/deliver .claude/skills/deliver
$ npx degit domengabrovsek/agent-config/skills/diagram .claude/skills/diagram
$ npx degit domengabrovsek/agent-config/skills/document .claude/skills/document
$ npx degit domengabrovsek/agent-config/skills/drive-fleet .claude/skills/drive-fleet
$ npx degit domengabrovsek/agent-config/skills/fix-issue .claude/skills/fix-issue
$ npx degit domengabrovsek/agent-config/skills/grill-with-docs .claude/skills/grill-with-docs
$ npx degit domengabrovsek/agent-config/skills/handoff .claude/skills/handoff
$ npx degit domengabrovsek/agent-config/skills/improve-codebase-architecture .claude/skills/improve-codebase-architecture
$ npx degit domengabrovsek/agent-config/skills/jira .claude/skills/jira
$ npx degit domengabrovsek/agent-config/skills/mr .claude/skills/mr
$ npx degit domengabrovsek/agent-config/skills/observability .claude/skills/observability
$ npx degit domengabrovsek/agent-config/skills/plan .claude/skills/plan
$ npx degit domengabrovsek/agent-config/skills/pr-comments .claude/skills/pr-comments
$ npx degit domengabrovsek/agent-config/skills/prototype .claude/skills/prototype
$ npx degit domengabrovsek/agent-config/skills/prune .claude/skills/prune
$ npx degit domengabrovsek/agent-config/skills/research .claude/skills/research
$ npx degit domengabrovsek/agent-config/skills/resolve-conflicts .claude/skills/resolve-conflicts
$ npx degit domengabrovsek/agent-config/skills/review-pr .claude/skills/review-pr
$ npx degit domengabrovsek/agent-config/skills/rulebook .claude/skills/rulebook
$ npx degit domengabrovsek/agent-config/skills/sentry-issue .claude/skills/sentry-issue
$ npx degit domengabrovsek/agent-config/skills/ship .claude/skills/ship
$ npx degit domengabrovsek/agent-config/skills/spec .claude/skills/spec
$ npx degit domengabrovsek/agent-config/skills/summarize .claude/skills/summarize
$ npx degit domengabrovsek/agent-config/skills/to-issues .claude/skills/to-issues
$ npx degit domengabrovsek/agent-config/skills/verify-done .claude/skills/verify-done
$ npx degit domengabrovsek/agent-config/skills/wait-what .claude/skills/wait-what
$ npx degit domengabrovsek/agent-config/skills/wayfinder .claude/skills/wayfinder
$ npx degit domengabrovsek/agent-config/skills/wizard .claude/skills/wizard
$ npx degit domengabrovsek/agent-config/skills/worktree-merge .claude/skills/worktree-merge
$ npx degit domengabrovsek/agent-config/skills/worktree .claude/skills/worktree
$ npx degit domengabrovsek/agent-config/skills/worktrees .claude/skills/worktrees
$ npx degit domengabrovsek/agent-config/skills/write-a-skill .claude/skills/write-a-skill
$ npx degit domengabrovsek/agent-config/skills/write-plain .claude/skills/write-plain
$ curl -fsSL --create-dirs -o .claude/agents/argocd-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/argocd-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/aws-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/aws-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/backend-staff-engineer.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/backend-staff-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/cybersecurity-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/cybersecurity-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/devops-engineer.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/devops-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/doc-reader.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/doc-reader.md
$ curl -fsSL --create-dirs -o .claude/agents/frontend-staff-engineer.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/frontend-staff-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/gcp-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/gcp-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/gdpr-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/gdpr-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/gtm-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/gtm-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/networking-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/networking-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/postgresql-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/postgresql-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/pr-reviewer.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/pr-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/product-manager.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/product-manager.md
$ curl -fsSL --create-dirs -o .claude/agents/qa-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/qa-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/spec-verifier.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/spec-verifier.md
$ curl -fsSL --create-dirs -o .claude/agents/staff-engineer.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/staff-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/ux-expert.md https://raw.githubusercontent.com/domengabrovsek/agent-config/main/agents/ux-expert.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.local)",
      "Read(**/.env.*.local)",
      "Read(**/.env.development)",
      "Read(**/.env.production)",
      "Read(**/.env.staging)",
      "Read(**/.env.test)",
      "Read(**/.env.dev)",
      "Read(**/.env.prod)",
      "Read(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.aws/**)",
      "Read(~/.config/gcloud/**)",
      "Read(~/.config/gh/hosts.yml)",
      "Read(~/.gradle/gradle.properties)",
      "Read(~/.pypirc)",
      "Read(~/.terraform.d/**)",
      "Read(~/.vault-token)",
      "Read(~/.kube/**)",
      "Read(~/.docker/config.json)",
      "Read(~/.npmrc)",
      "Read(~/.netrc)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/*.pfx)",
      "Read(**/*.jks)",
      "Read(**/*-key.json)",
      "Read(**/service-account*.json)",
      "Read(**/credentials.json)",
      "Read(**/.vault-token)",
      "Read(**/.htpasswd)",
      "Read(~/.git-credentials)",
      "Read(~/.gitconfig)",
      "Read(**/.terraform.tfstate*)",
      "Read(~/.terraformrc)",
      "Read(~/.config/terraform/**)",
      "Read(~/.yarnrc.yml)",
      "Read(~/.yarnrc)",
      "Read(~/.pnpmrc)",
      "Read(~/.config/npm/**)",
      "Read(~/.zsh_history)",
      "Read(~/.bash_history)",
      "Read(~/.config/Code/User/globalStorage/**)",
      "Read(**/*.kubeconfig)",
      "Read(~/.config/gke-gcloud-auth-plugin/**)",
      "Read(~/.azure/**)",
      "Edit(**/.env)",
      "Edit(**/.env.local)",
      "Edit(**/.env.*.local)",
      "Edit(**/.env.development)",
      "Edit(**/.env.production)",
      "Edit(**/.env.staging)",
      "Edit(**/.env.test)",
      "Edit(**/.env.dev)",
      "Edit(**/.env.prod)",
      "Edit(~/.ssh/**)",
      "Edit(~/.gnupg/**)",
      "Edit(~/.aws/**)",
      "Edit(~/.npmrc)",
      "Edit(~/.netrc)",
      "Edit(~/.docker/config.json)",
      "Edit(~/.gitconfig)",
      "Edit(~/.kube/**)",
      "Edit(~/.config/gcloud/**)",
      "Edit(~/.azure/**)",
      "Edit(**/*.pem)",
      "Edit(**/*.key)",
      "Edit(**/*-key.json)",
      "Edit(**/*.p12)",
      "Edit(**/*.pfx)",
      "Edit(**/*.jks)",
      "Edit(**/service-account*.json)",
      "Edit(**/credentials.json)",
      "Edit(**/*.kubeconfig)",
      "Edit(**/.htpasswd)",
      "Edit(**/.vault-token)",
      "Edit(**/.terraform.tfstate*)",
      "Edit(~/.git-credentials)",
      "Edit(~/.vault-token)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|Write|Edit|mcp__.*",
        "hooks": [
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/deny-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/deny-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-git-state-refresh.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-git-state-refresh.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-git-state-refresh.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-git-state-refresh.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-git-state-refresh.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-git-state-refresh.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-pr-test-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-pr-test-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-pr-test-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-pr-test-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-pr-evidence-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-pr-evidence-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-push-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-push-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-push-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-push-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-commit-branch-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-commit-branch-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-commit-branch-gate.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-commit-branch-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          }
        ]
      },
      {
        "matcher": "Write|Edit",
        "hooks": [
          {
            "type": "command",
            "command": "HOOK=\"$CLAUDE_PROJECT_DIR/hooks/pre-edit-test-lock.sh\"; [ -x \"$HOOK\" ] || HOOK=\"$HOME/.claude/hooks/pre-edit-test-lock.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          }
        ]
      }
    ]
  }
}

MCP servers (4)

serversourceest. tokens
@drawio/mcp · "drawio" npm 2.5k
Notion remote · remote 6.0k
Slack remote · remote 3.5k
Playwright MCP · "playwright" npm 7.5k

Skills (36)

Subagents (18)

ArgoCD ExpertDesigns and reviews ArgoCD Applications, ApplicationSets, AppProjects, sync policies, and Argo Rollouts progressive delivery. Use when the task involves ArgoCD manifests, sync behavior, GitOps repo la
AWS ExpertDesigns and reviews AWS architecture, IAM, networking, and cloud cost. Use when the task involves AWS services, Terraform targeting AWS, a Well-Architected review, or AWS cost optimization. Not for GC
Backend Staff EngineerDesigns and reviews Node.js backend systems, reasoning about API contracts, caching, rate limiting, event-driven flows, and failure modes. Use for server logic, API design, queue consumers, resilience
Cybersecurity ExpertThreat-models code and architecture changes across trust boundaries, authn/authz flows, secrets handling, and injection surfaces, returning severity-ranked findings with concrete attack scenarios. Use
DevOps EngineerBuilds and reviews infrastructure-as-code, CI/CD pipelines, containers, and Kubernetes deployments. Use when the task involves Terraform structure, Dockerfiles, GitHub Actions workflows, Kubernetes ma
Doc ReaderAnswers questions about one document from its text alone, with no shell and no web, so the document cannot steer it into actions. Use for the reader test in /document review. Returns a verdict per que
Frontend Staff EngineerImplements and reviews React/TypeScript frontend work covering component architecture, state management, rendering strategy, and web performance. Use when a change touches React components, CSS, clien
GCP ExpertDesigns and reviews Google Cloud architecture, IAM, networking, and cloud cost. Use when the task involves GCP services, Terraform targeting GCP, gcloud operations, or GCP cost optimization. Not for A
GDPR ExpertAssesses data-handling changes for EU data subjects, judging lawful basis, DPIA triggers, PII flows, consent quality, retention, and data subject rights implementability, and returning severity-ranked
GTM ExpertDesigns and audits Google Tag Manager setups, covering server-side tagging on Cloud Run, Consent Mode v2, GA4, data layer schemas, and conversion APIs. Use for tag migrations, data layer design, conse
Networking ExpertDiagnoses and designs DNS, TLS, load balancing, CDN caching, and protocol-level behavior (TCP, HTTP, gRPC, WebSocket). Use when the task involves DNS records, certificates, LB or proxy configuration,
PostgreSQL ExpertDesigns and optimizes PostgreSQL schemas, queries, indexes, and migrations, reasoning from EXPLAIN plans and pg_stat data. Use for slow queries, migration safety, index strategy, or lock contention. P
PR ReviewerReviews a pull request or working diff for correctness, security, and maintainability, returning severity-ranked findings with file:line references and a verdict. Use when asked to review a PR, code-r
Product ManagerReviews feature plans, specs, and user stories for problem framing, scope boundaries, and measurable success criteria. Use when planning a feature, writing user stories, prioritizing work, or defining
QA ExpertDesigns test strategy and writes tests at the right level, from unit to E2E, including diagnosing flaky suites. Use when a task involves test strategy, test architecture, coverage gaps, flaky tests, o
Spec VerifierChecks an implementation against its spec by running each acceptance criterion's check at HEAD and recording the result in the evidence ledger. Use before opening a PR for a branch with a spec, after
Staff EngineerShapes system architecture, reasoning about module boundaries, dependency direction, domain modeling, and long-term maintainability trade-offs. Use for system design, DDD, cross-module refactors, or a
UX ExpertReviews usability, accessibility, and interaction design of UI changes, returning severity-ranked findings. Use when a change touches user-facing UI, WCAG compliance, or interaction flows. Advisory an

Hooks (21)

eventmatcherruns
PreToolUseBash|Write|Edit|mcp__.*HOOK="$CLAUDE_PROJECT_DIR/hooks/deny-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/deny-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-git-state-refresh.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-git-state-refresh.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-git-state-refresh.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-git-state-refresh.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-git-state-refresh.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-git-state-refresh.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-pr-test-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-pr-test-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-pr-test-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-pr-test-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-pr-evidence-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-pr-evidence-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-push-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-push-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-push-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-push-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-commit-branch-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-commit-branch-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-commit-branch-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-commit-branch-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseWrite|EditHOOK="$CLAUDE_PROJECT_DIR/hooks/pre-edit-test-lock.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/pre-edit-test-lock.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PostToolUseWrite|EditHOOK="$CLAUDE_PROJECT_DIR/hooks/auto-format.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/auto-format.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PostToolUseWrite|EditHOOK="$CLAUDE_PROJECT_DIR/hooks/post-edit-typecheck.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/post-edit-typecheck.sh"; if [ -x "$HOOK" ]; then "$HOOK"; fi
PostToolUseWrite|EditHOOK="$CLAUDE_PROJECT_DIR/hooks/post-edit-lint.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/post-edit-lint.sh"; if [ -x "$HOOK" ]; then "$HOOK"; fi
PostToolUseWrite|EditHOOK="$CLAUDE_PROJECT_DIR/hooks/prose-gate.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/prose-gate.sh"; if [ -x "$HOOK" ]; then "$HOOK" file; fi
SessionEnd*HOOK="$CLAUDE_PROJECT_DIR/hooks/worktree-cleanup.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/worktree-cleanup.sh"; [ -x "$HOOK" ] && "$HOOK" || true
Notificationpermission_prompt|idle_promptosascript -e 'display notification "Claude Code needs your attention" with title "Claude Code"'
SessionStartcompactecho 'Reminder: follow the workflow (Research - Grill - Spec and plan - Implement - Summarize). Use /grill-with-docs for alignment. Minimal fix first for bugs. Run /verify-done before opening a PR. Current year: 2026.'
SessionStartstartupHOOK="$CLAUDE_PROJECT_DIR/hooks/symlink-check.sh"; [ -x "$HOOK" ] || HOOK="$HOME/.claude/hooks/symlink-check.sh"; [ -x "$HOOK" ] && "$HOOK" || true
SessionStart*HOOK="$HOME/.claude/hooks/herdr-agent-state.sh"; [ -x "$HOOK" ] && "$HOOK" session || true

Plugins (1)

frontend-design@claude-plugins-official

Permissions

deny (110)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.*.local)
Read(**/.env.development)
Read(**/.env.production)
Read(**/.env.staging)
Read(**/.env.test)
Read(**/.env.dev)
Read(**/.env.prod)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(~/.config/gh/hosts.yml)
Read(~/.gradle/gradle.properties)
Read(~/.pypirc)
Read(~/.terraform.d/**)
Read(~/.vault-token)
Read(~/.kube/**)
Read(~/.docker/config.json)
Read(~/.npmrc)
Read(~/.netrc)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.jks)
Read(**/*-key.json)
Read(**/service-account*.json)
Read(**/credentials.json)
Read(**/.vault-token)
Read(**/.htpasswd)
Read(~/.git-credentials)
Read(~/.gitconfig)
Read(**/.terraform.tfstate*)
Read(~/.terraformrc)
Read(~/.config/terraform/**)
Read(~/.yarnrc.yml)
Read(~/.yarnrc)
Read(~/.pnpmrc)
Read(~/.config/npm/**)
Read(~/.zsh_history)
Read(~/.bash_history)
Read(~/.config/Code/User/globalStorage/**)
Read(**/*.kubeconfig)
Read(~/.config/gke-gcloud-auth-plugin/**)
Read(~/.azure/**)
Edit(**/.env)
Edit(**/.env.local)
Edit(**/.env.*.local)
Edit(**/.env.development)
Edit(**/.env.production)
Edit(**/.env.staging)
Edit(**/.env.test)
Edit(**/.env.dev)
Edit(**/.env.prod)
Edit(~/.ssh/**)
Edit(~/.gnupg/**)
Edit(~/.aws/**)
Edit(~/.npmrc)
ask (0)
—
allow (4)
Read(**/.env.example)
Read(**/.env.sample)
Edit(**/.env.example)
Edit(**/.env.sample)

Similar rigs

copied ✓