~ / rigs / ebkn / dotfiles

ebkn/dotfiles

ebkn's dotfiles

share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~10.7k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit ebkn/dotfiles/root/.claude ./rig-dotfiles  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit ebkn/dotfiles/root/.agents/skills/check-production-readiness .claude/skills/check-production-readiness
$ npx degit ebkn/dotfiles/root/.agents/skills/commit .claude/skills/commit
$ npx degit ebkn/dotfiles/root/.agents/skills/create-pr .claude/skills/create-pr
$ npx degit ebkn/dotfiles/root/.agents/skills/deep-dive .claude/skills/deep-dive
$ npx degit ebkn/dotfiles/root/.agents/skills/init-project .claude/skills/init-project
$ npx degit ebkn/dotfiles/root/.agents/skills/lint-docs .claude/skills/lint-docs
$ npx degit ebkn/dotfiles/root/.agents/skills/retrospective .claude/skills/retrospective
$ npx degit ebkn/dotfiles/root/.agents/skills/review-design .claude/skills/review-design
$ npx degit ebkn/dotfiles/root/.agents/skills/review-support .claude/skills/review-support
$ npx degit ebkn/dotfiles/root/.agents/skills/review-test .claude/skills/review-test
$ npx degit ebkn/dotfiles/root/.agents/skills/update-pr .claude/skills/update-pr

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf /)",
      "Bash(rm -rf ~)",
      "Bash(rm -rf /*)",
      "Bash(rm -rf --no-preserve-root /)",
      "Bash(rm -rf --no-preserve-root /*)",
      "Bash(rm /etc*)",
      "Bash(rm * /etc*)",
      "Bash(rm /usr*)",
      "Bash(rm * /usr*)",
      "Bash(rm /var*)",
      "Bash(rm * /var*)",
      "Bash(rm /opt*)",
      "Bash(rm * /opt*)",
      "Bash(rm /bin*)",
      "Bash(rm * /bin*)",
      "Bash(rm /sbin*)",
      "Bash(rm * /sbin*)",
      "Bash(rm /lib*)",
      "Bash(rm * /lib*)",
      "Bash(rm /lib64*)",
      "Bash(rm * /lib64*)",
      "Bash(rm /boot*)",
      "Bash(rm * /boot*)",
      "Bash(rm /proc*)",
      "Bash(rm * /proc*)",
      "Bash(rm /sys*)",
      "Bash(rm * /sys*)",
      "Bash(rm /dev*)",
      "Bash(rm * /dev*)",
      "Bash(rm ~/.ssh/id_*)",
      "Bash(rm * ~/.ssh/id_*)",
      "Bash(rm ~/.ssh/*_rsa)",
      "Bash(rm * ~/.ssh/*_rsa)",
      "Bash(rm ~/.ssh/*_ecdsa)",
      "Bash(rm * ~/.ssh/*_ecdsa)",
      "Bash(rm ~/.ssh/*_ed25519)",
      "Bash(rm * ~/.ssh/*_ed25519)",
      "Bash(sudo)",
      "Bash(sudo *)",
      "Bash(su)",
      "Bash(su *)",
      "Bash(doas)",
      "Bash(doas *)",
      "Bash(sudo rm *)",
      "Bash(sudo dd *)",
      "Bash(sudo mkfs *)",
      "Bash(sudo fdisk *)",
      "Bash(sudo mount *)",
      "Bash(sudo umount *)",
      "Bash(dd *)",
      "Bash(mkfs *)",
      "Bash(fdisk *)",
      "Bash(> /dev/*)",
      "Bash(>> /dev/*)",
      "Bash(chmod 777 /*)",
      "Bash(chown root *)",
      "Bash(sudo chmod 777 *)",
      "Bash(sudo chown *)",
      "Bash(sudo -i *)",
      "Bash(sudo su *)",
      "Bash(rm -rf .git)",
      "Bash(git push --force*)",
      "Bash(git push -f*)",
      "Bash(git push * --force*)",
      "Bash(git push * -f *)",
      "Bash(git push * -f)",
      "Bash(git -C * push --force*)",
      "Bash(git -C * push -f*)",
      "Bash(git -C * push * --force*)",
      "Bash(git -C * push * -f *)",
      "Bash(git -C * push * -f)",
      "Bash(git clean -fd *)",
      "Bash(git reset --hard *)",
      "Bash(git -C * reset --hard *)",
      "Bash(git clean -fdx *)",
      "Bash(git -C * clean -fdx *)",
      "Bash(git checkout -- *)",
      "Bash(git -C * checkout -- *)",
      "Bash(git restore --worktree *)",
      "Bash(git -C * restore --worktree *)"
    ],
    "ask": [
      "Bash(wget *)",
      "Bash(telnet *)",
      "Bash(nc *)",
      "Bash(netcat *)",
      "Bash(git checkout *)",
      "Bash(git switch *)",
      "Bash(git branch -d *)",
      "Bash(git branch -D *)",
      "Bash(git branch *-d *)",
      "Bash(git branch *-D *)",
      "Bash(git -C * branch -d *)",
      "Bash(git -C * branch -D *)",
      "Bash(git -C * branch *-d *)",
      "Bash(git -C * branch *-D *)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/approve-multiline-commands.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/strip-redundant-cd.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/curl-guard.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/rm-guard.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/git-guard.sh"
          }
        ]
      },
      {
        "matcher": "AskUserQuestion",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/agent-state.sh ask"
          }
        ]
      }
    ]
  }
}

Skills (11)

Hooks (15)

eventmatcherruns
PreToolUseBash~/.claude/hooks/approve-multiline-commands.sh
PreToolUseBash~/.claude/hooks/strip-redundant-cd.sh
PreToolUseBash~/.claude/hooks/curl-guard.sh
PreToolUseBash~/.claude/hooks/rm-guard.sh
PreToolUseBash~/.claude/hooks/git-guard.sh
PreToolUseAskUserQuestion~/.claude/hooks/agent-state.sh ask
PostToolBatch*~/.claude/hooks/agent-state.sh busy
UserPromptSubmit*~/.claude/hooks/agent-state.sh busy
Notification*~/.claude/hooks/agent-state.sh notify
Stop*~/.claude/hooks/agent-state.sh done
SubagentStart*~/.claude/hooks/agent-state.sh subagent-start
SubagentStop*~/.claude/hooks/agent-state.sh subagent-stop
SessionStart*~/.claude/hooks/agent-state.sh start
SessionEnd*~/.claude/hooks/agent-state.sh clear
PermissionRequest*~/.claude/hooks/agent-state.sh permission

Plugins (6)

playwright@claude-plugins-officialslack@claude-plugins-officialsentry@claude-plugins-officialchrome-devtools-mcp@claude-plugins-officialskill-creator@claude-plugins-officialfrontend-design@claude-plugins-official

Permissions

deny (120)
Bash(rm -rf /)
Bash(rm -rf ~)
Bash(rm -rf /*)
Bash(rm -rf --no-preserve-root /)
Bash(rm -rf --no-preserve-root /*)
Bash(rm /etc*)
Bash(rm * /etc*)
Bash(rm /usr*)
Bash(rm * /usr*)
Bash(rm /var*)
Bash(rm * /var*)
Bash(rm /opt*)
Bash(rm * /opt*)
Bash(rm /bin*)
Bash(rm * /bin*)
Bash(rm /sbin*)
Bash(rm * /sbin*)
Bash(rm /lib*)
Bash(rm * /lib*)
Bash(rm /lib64*)
Bash(rm * /lib64*)
Bash(rm /boot*)
Bash(rm * /boot*)
Bash(rm /proc*)
Bash(rm * /proc*)
Bash(rm /sys*)
Bash(rm * /sys*)
Bash(rm /dev*)
Bash(rm * /dev*)
Bash(rm ~/.ssh/id_*)
Bash(rm * ~/.ssh/id_*)
Bash(rm ~/.ssh/*_rsa)
Bash(rm * ~/.ssh/*_rsa)
Bash(rm ~/.ssh/*_ecdsa)
Bash(rm * ~/.ssh/*_ecdsa)
Bash(rm ~/.ssh/*_ed25519)
Bash(rm * ~/.ssh/*_ed25519)
Bash(sudo)
Bash(sudo *)
Bash(su)
Bash(su *)
Bash(doas)
Bash(doas *)
Bash(sudo rm *)
Bash(sudo dd *)
Bash(sudo mkfs *)
Bash(sudo fdisk *)
Bash(sudo mount *)
Bash(sudo umount *)
Bash(dd *)
Bash(mkfs *)
Bash(fdisk *)
Bash(> /dev/*)
Bash(>> /dev/*)
Bash(chmod 777 /*)
Bash(chown root *)
Bash(sudo chmod 777 *)
Bash(sudo chown *)
Bash(sudo -i *)
Bash(sudo su *)
ask (14)
Bash(wget *)
Bash(telnet *)
Bash(nc *)
Bash(netcat *)
Bash(git checkout *)
Bash(git switch *)
Bash(git branch -d *)
Bash(git branch -D *)
Bash(git branch *-d *)
Bash(git branch *-D *)
Bash(git -C * branch -d *)
Bash(git -C * branch -D *)
Bash(git -C * branch *-d *)
Bash(git -C * branch *-D *)
allow (120)
Bash(actionlint *)
Bash(ast-grep *)
Bash(autossh -V)
Bash(awk *)
Bash(basename *)
Bash(cat *)
Bash(cut *)
Bash(date *)
Bash(df*)
Bash(diff *)
Bash(dig *)
Bash(dirname *)
Bash(done)
Bash(du*)
Bash(echo *)
Bash(false*)
Bash(file *)
Bash(find *)
Bash(fd *)
Bash(fd)
Bash(base64*)
Bash(for *)
Bash(grep *)
Bash(groups*)
Bash(head *)
Bash(host *)
Bash(id*)
Bash(jq *)
Bash(ls*)
Bash(log show*)
Bash(log stats*)
Bash(lsof*)
Bash(mkdir *)
Bash(nslookup *)
Bash(ping *)
Bash(printf *)
Bash(ps*)
Bash(pwd*)
Bash(read *)
Bash(readlink *)
Bash(realpath *)
Bash(rg *)
Bash(sed *)
Bash(shellcheck *)
Bash(sort *)
Bash(ssh -V)
Bash(stat *)
Bash(sw_vers)
Bash(tail *)
Bash(tailscale netcheck *)
Bash(tailscale ping *)
Bash(tailscale status *)
Bash(tee *)
Bash(terminal-notifier *)
Bash(test *)
Bash(tmux list-panes:*)
Bash(tmux list-sessions:*)
Bash(touch *)
Bash(tr *)
Bash(traceroute *)

Similar rigs

copied ✓