ebkn/dotfiles
ebkn's dotfiles
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit ebkn/dotfiles/root/.claude ./rig-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit ebkn/dotfiles/root/.agents/skills/check-production-readiness .claude/skills/check-production-readiness $ npx degit ebkn/dotfiles/root/.agents/skills/commit .claude/skills/commit $ npx degit ebkn/dotfiles/root/.agents/skills/create-pr .claude/skills/create-pr $ npx degit ebkn/dotfiles/root/.agents/skills/deep-dive .claude/skills/deep-dive $ npx degit ebkn/dotfiles/root/.agents/skills/init-project .claude/skills/init-project $ npx degit ebkn/dotfiles/root/.agents/skills/lint-docs .claude/skills/lint-docs $ npx degit ebkn/dotfiles/root/.agents/skills/retrospective .claude/skills/retrospective $ npx degit ebkn/dotfiles/root/.agents/skills/review-design .claude/skills/review-design $ npx degit ebkn/dotfiles/root/.agents/skills/review-support .claude/skills/review-support $ npx degit ebkn/dotfiles/root/.agents/skills/review-test .claude/skills/review-test $ npx degit ebkn/dotfiles/root/.agents/skills/update-pr .claude/skills/update-pr
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf /)",
"Bash(rm -rf ~)",
"Bash(rm -rf /*)",
"Bash(rm -rf --no-preserve-root /)",
"Bash(rm -rf --no-preserve-root /*)",
"Bash(rm /etc*)",
"Bash(rm * /etc*)",
"Bash(rm /usr*)",
"Bash(rm * /usr*)",
"Bash(rm /var*)",
"Bash(rm * /var*)",
"Bash(rm /opt*)",
"Bash(rm * /opt*)",
"Bash(rm /bin*)",
"Bash(rm * /bin*)",
"Bash(rm /sbin*)",
"Bash(rm * /sbin*)",
"Bash(rm /lib*)",
"Bash(rm * /lib*)",
"Bash(rm /lib64*)",
"Bash(rm * /lib64*)",
"Bash(rm /boot*)",
"Bash(rm * /boot*)",
"Bash(rm /proc*)",
"Bash(rm * /proc*)",
"Bash(rm /sys*)",
"Bash(rm * /sys*)",
"Bash(rm /dev*)",
"Bash(rm * /dev*)",
"Bash(rm ~/.ssh/id_*)",
"Bash(rm * ~/.ssh/id_*)",
"Bash(rm ~/.ssh/*_rsa)",
"Bash(rm * ~/.ssh/*_rsa)",
"Bash(rm ~/.ssh/*_ecdsa)",
"Bash(rm * ~/.ssh/*_ecdsa)",
"Bash(rm ~/.ssh/*_ed25519)",
"Bash(rm * ~/.ssh/*_ed25519)",
"Bash(sudo)",
"Bash(sudo *)",
"Bash(su)",
"Bash(su *)",
"Bash(doas)",
"Bash(doas *)",
"Bash(sudo rm *)",
"Bash(sudo dd *)",
"Bash(sudo mkfs *)",
"Bash(sudo fdisk *)",
"Bash(sudo mount *)",
"Bash(sudo umount *)",
"Bash(dd *)",
"Bash(mkfs *)",
"Bash(fdisk *)",
"Bash(> /dev/*)",
"Bash(>> /dev/*)",
"Bash(chmod 777 /*)",
"Bash(chown root *)",
"Bash(sudo chmod 777 *)",
"Bash(sudo chown *)",
"Bash(sudo -i *)",
"Bash(sudo su *)",
"Bash(rm -rf .git)",
"Bash(git push --force*)",
"Bash(git push -f*)",
"Bash(git push * --force*)",
"Bash(git push * -f *)",
"Bash(git push * -f)",
"Bash(git -C * push --force*)",
"Bash(git -C * push -f*)",
"Bash(git -C * push * --force*)",
"Bash(git -C * push * -f *)",
"Bash(git -C * push * -f)",
"Bash(git clean -fd *)",
"Bash(git reset --hard *)",
"Bash(git -C * reset --hard *)",
"Bash(git clean -fdx *)",
"Bash(git -C * clean -fdx *)",
"Bash(git checkout -- *)",
"Bash(git -C * checkout -- *)",
"Bash(git restore --worktree *)",
"Bash(git -C * restore --worktree *)"
],
"ask": [
"Bash(wget *)",
"Bash(telnet *)",
"Bash(nc *)",
"Bash(netcat *)",
"Bash(git checkout *)",
"Bash(git switch *)",
"Bash(git branch -d *)",
"Bash(git branch -D *)",
"Bash(git branch *-d *)",
"Bash(git branch *-D *)",
"Bash(git -C * branch -d *)",
"Bash(git -C * branch -D *)",
"Bash(git -C * branch *-d *)",
"Bash(git -C * branch *-D *)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "~/.claude/hooks/approve-multiline-commands.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/strip-redundant-cd.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/curl-guard.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/rm-guard.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/git-guard.sh"
}
]
},
{
"matcher": "AskUserQuestion",
"hooks": [
{
"type": "command",
"command": "~/.claude/hooks/agent-state.sh ask"
}
]
}
]
}
} Skills (11)
check-production-readinesscommitcreate-prdeep-diveinit-projectlint-docsretrospectivereview-designreview-supportreview-testupdate-pr
Hooks (15)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | ~/.claude/hooks/approve-multiline-commands.sh |
| PreToolUse | Bash | ~/.claude/hooks/strip-redundant-cd.sh |
| PreToolUse | Bash | ~/.claude/hooks/curl-guard.sh |
| PreToolUse | Bash | ~/.claude/hooks/rm-guard.sh |
| PreToolUse | Bash | ~/.claude/hooks/git-guard.sh |
| PreToolUse | AskUserQuestion | ~/.claude/hooks/agent-state.sh ask |
| PostToolBatch | * | ~/.claude/hooks/agent-state.sh busy |
| UserPromptSubmit | * | ~/.claude/hooks/agent-state.sh busy |
| Notification | * | ~/.claude/hooks/agent-state.sh notify |
| Stop | * | ~/.claude/hooks/agent-state.sh done |
| SubagentStart | * | ~/.claude/hooks/agent-state.sh subagent-start |
| SubagentStop | * | ~/.claude/hooks/agent-state.sh subagent-stop |
| SessionStart | * | ~/.claude/hooks/agent-state.sh start |
| SessionEnd | * | ~/.claude/hooks/agent-state.sh clear |
| PermissionRequest | * | ~/.claude/hooks/agent-state.sh permission |
Plugins (6)
playwright@claude-plugins-officialslack@claude-plugins-officialsentry@claude-plugins-officialchrome-devtools-mcp@claude-plugins-officialskill-creator@claude-plugins-officialfrontend-design@claude-plugins-official
Permissions
deny (120)
Bash(rm -rf /)
Bash(rm -rf ~)
Bash(rm -rf /*)
Bash(rm -rf --no-preserve-root /)
Bash(rm -rf --no-preserve-root /*)
Bash(rm /etc*)
Bash(rm * /etc*)
Bash(rm /usr*)
Bash(rm * /usr*)
Bash(rm /var*)
Bash(rm * /var*)
Bash(rm /opt*)
Bash(rm * /opt*)
Bash(rm /bin*)
Bash(rm * /bin*)
Bash(rm /sbin*)
Bash(rm * /sbin*)
Bash(rm /lib*)
Bash(rm * /lib*)
Bash(rm /lib64*)
Bash(rm * /lib64*)
Bash(rm /boot*)
Bash(rm * /boot*)
Bash(rm /proc*)
Bash(rm * /proc*)
Bash(rm /sys*)
Bash(rm * /sys*)
Bash(rm /dev*)
Bash(rm * /dev*)
Bash(rm ~/.ssh/id_*)
Bash(rm * ~/.ssh/id_*)
Bash(rm ~/.ssh/*_rsa)
Bash(rm * ~/.ssh/*_rsa)
Bash(rm ~/.ssh/*_ecdsa)
Bash(rm * ~/.ssh/*_ecdsa)
Bash(rm ~/.ssh/*_ed25519)
Bash(rm * ~/.ssh/*_ed25519)
Bash(sudo)
Bash(sudo *)
Bash(su)
Bash(su *)
Bash(doas)
Bash(doas *)
Bash(sudo rm *)
Bash(sudo dd *)
Bash(sudo mkfs *)
Bash(sudo fdisk *)
Bash(sudo mount *)
Bash(sudo umount *)
Bash(dd *)
Bash(mkfs *)
Bash(fdisk *)
Bash(> /dev/*)
Bash(>> /dev/*)
Bash(chmod 777 /*)
Bash(chown root *)
Bash(sudo chmod 777 *)
Bash(sudo chown *)
Bash(sudo -i *)
Bash(sudo su *)
ask (14)
Bash(wget *)
Bash(telnet *)
Bash(nc *)
Bash(netcat *)
Bash(git checkout *)
Bash(git switch *)
Bash(git branch -d *)
Bash(git branch -D *)
Bash(git branch *-d *)
Bash(git branch *-D *)
Bash(git -C * branch -d *)
Bash(git -C * branch -D *)
Bash(git -C * branch *-d *)
Bash(git -C * branch *-D *)
allow (120)
Bash(actionlint *)
Bash(ast-grep *)
Bash(autossh -V)
Bash(awk *)
Bash(basename *)
Bash(cat *)
Bash(cut *)
Bash(date *)
Bash(df*)
Bash(diff *)
Bash(dig *)
Bash(dirname *)
Bash(done)
Bash(du*)
Bash(echo *)
Bash(false*)
Bash(file *)
Bash(find *)
Bash(fd *)
Bash(fd)
Bash(base64*)
Bash(for *)
Bash(grep *)
Bash(groups*)
Bash(head *)
Bash(host *)
Bash(id*)
Bash(jq *)
Bash(ls*)
Bash(log show*)
Bash(log stats*)
Bash(lsof*)
Bash(mkdir *)
Bash(nslookup *)
Bash(ping *)
Bash(printf *)
Bash(ps*)
Bash(pwd*)
Bash(read *)
Bash(readlink *)
Bash(realpath *)
Bash(rg *)
Bash(sed *)
Bash(shellcheck *)
Bash(sort *)
Bash(ssh -V)
Bash(stat *)
Bash(sw_vers)
Bash(tail *)
Bash(tailscale netcheck *)
Bash(tailscale ping *)
Bash(tailscale status *)
Bash(tee *)
Bash(terminal-notifier *)
Bash(test *)
Bash(tmux list-panes:*)
Bash(tmux list-sessions:*)
Bash(touch *)
Bash(tr *)
Bash(traceroute *)
Similar rigs
ReflexioAI/claude-smart
Turns corrections into Preferences, Project-specific skills, and Shared skills for Claude Code, Codex, and OpenCode.
Minimalist 327 tok ·
vichannnnn/ccstart
Quick setup for projects or repositories using Claude Code with built-in agents, ticket system, and planning tools.
Pragmatist 3.0k tok ·
uhooi/dotfiles
My dotfiles
Pragmatist 305 tok ·
liorm/dotfiles
General dotfiles I use
Pragmatist 471 tok ·