hayden1126/dotclaude
Portable snapshot of my Claude Code setup: settings, hooks, statusline, custom agents, plugin manifest, and sync script.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ npx degit hayden1126/dotclaude/agents ./rig-dotclaude/agents $ npx degit hayden1126/dotclaude/skills ./rig-dotclaude/skills $ npx degit hayden1126/dotclaude/hooks ./rig-dotclaude/hooks
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit hayden1126/dotclaude/skills/coding-practices .claude/skills/coding-practices $ npx degit hayden1126/dotclaude/skills/deck-production .claude/skills/deck-production $ npx degit hayden1126/dotclaude/skills/delegation .claude/skills/delegation $ npx degit hayden1126/dotclaude/skills/ebook-extract .claude/skills/ebook-extract $ npx degit hayden1126/dotclaude/skills/frontend-ui-discipline .claude/skills/frontend-ui-discipline $ npx degit hayden1126/dotclaude/skills/handoff .claude/skills/handoff $ npx degit hayden1126/dotclaude/skills/research-discipline .claude/skills/research-discipline $ npx degit hayden1126/dotclaude/skills/research-sourcing .claude/skills/research-sourcing $ npx degit hayden1126/dotclaude/skills/staged-reader-review .claude/skills/staged-reader-review $ npx degit hayden1126/dotclaude/skills/ui-alignment .claude/skills/ui-alignment $ npx degit hayden1126/dotclaude/skills/vetting-sources .claude/skills/vetting-sources $ npx degit hayden1126/dotclaude/skills/writing-voice .claude/skills/writing-voice
$ curl -fsSL --create-dirs -o .claude/agents/Explore.md https://raw.githubusercontent.com/hayden1126/dotclaude/main/agents/Explore.md $ curl -fsSL --create-dirs -o .claude/agents/researcher.md https://raw.githubusercontent.com/hayden1126/dotclaude/main/agents/researcher.md $ curl -fsSL --create-dirs -o .claude/agents/reviewer.md https://raw.githubusercontent.com/hayden1126/dotclaude/main/agents/reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/writer.md https://raw.githubusercontent.com/hayden1126/dotclaude/main/agents/writer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(git push --force*)",
"Bash(git push -f*)",
"Bash(git push * --force*)",
"Bash(git push * -f*)",
"Bash(git -C * push --force*)",
"Bash(git -C * push -f*)",
"Bash(git -C * push * --force*)",
"Bash(git -C * push * -f*)",
"Bash(git reset --hard*)",
"Bash(git reset * --hard*)",
"Bash(git -C * reset --hard*)",
"Bash(git -C * reset * --hard*)",
"Bash(git reset --merge*)",
"Bash(git reset * --merge*)",
"Bash(git -C * reset --merge*)",
"Bash(git -C * reset * --merge*)",
"Bash(git clean -*f*)",
"Bash(git -C * clean -*f*)",
"Bash(bash -c *git push*--force*)",
"Bash(bash -c *git reset*--hard*)"
],
"ask": [
"Bash(git push)",
"Bash(git push origin)",
"Bash(git push -*)",
"Bash(git push origin -*)",
"Bash(git push *main*)",
"Bash(git push *HEAD*)",
"Bash(git push *@*)",
"Bash(git push *--all*)",
"Bash(git push *--mirror*)",
"Bash(git push *+*)",
"Bash(git -C * push)",
"Bash(git -C * push *)",
"Bash(gh pr merge*)",
"Bash(gh api *merge*)",
"Bash(git *--output*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "i=$(cat); case \"$i\" in *'\"agent_id\"'*) printf '%s' \"$i\" | timeout 8 bash \"$HOME/.claude/hooks/subagent-policy.sh\" || { echo \"subagent-policy missing, failed or timed out: this delegated call is blocked\" >&2; exit 2; } ;; esac"
},
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/tmux-state.sh\" busy"
}
]
},
{
"matcher": "Agent|Task",
"hooks": [
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/agent-spawn-guard.sh\" || exit 2"
}
]
},
{
"matcher": "SubagentHandback",
"hooks": [
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/report-check.sh\""
}
]
},
{
"matcher": "Write",
"hooks": [
{
"type": "command",
"command": "bash \"$HOME/.claude/hooks/overwrite-guard.sh\""
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "i=$(cat); case \"$i\" in *'\"dangerouslyDisableSandbox\":true'*|*'\"dangerouslyDisableSandbox\": true'*) printf '%s' \"$i\" | bash \"$HOME/.claude/hooks/delete-guard.sh\" ;; esac"
}
]
}
]
},
"sandbox": {
"enabled": true
}
} Skills (12)
coding-practicesdeck-productiondelegationebook-extractfrontend-ui-disciplinehandoffresearch-disciplineresearch-sourcingstaged-reader-reviewui-alignmentvetting-sourceswriting-voice
Subagents (4)
| Explore model: sonnet | Read-only agent for finding and reading code, docs and web pages. Locates files by pattern, greps for symbols, reads whole files when the question needs it, and reports what it found with path:line ci |
| researcher model: sonnet | Read-only research that needs a shell - git history (log, show, blame, diff), public GitHub (gh-public, curl GET, a shallow clone into temp), text tools like jq and sed -n. Changes nothing, and a poli |
| reviewer model: inherit | Read-only code and document reviewer. Reads a diff, files or a design and returns verified findings - bugs, regressions, contract violations, missing cases - each with path:line, severity and evidence |
| writer model: inherit | Makes changes - code, docs, config - in an isolated git worktree on its own branch, runs the verification the brief names, and commits there. Never pushes. Spawn it with isolation "worktree" on the Ag |
Hooks (25)
| event | matcher | runs |
|---|---|---|
| PreToolUse | * | i=$(cat); case "$i" in *'"agent_id"'*) printf '%s' "$i" | timeout 8 bash "$HOME/.claude/hooks/subagent-policy.sh" || { echo "subagent-policy missing, failed or timed out: this delegated call is blocked" >&2; exit 2; } ;; esac |
| PreToolUse | Agent|Task | bash "$HOME/.claude/hooks/agent-spawn-guard.sh" || exit 2 |
| PreToolUse | SubagentHandback | bash "$HOME/.claude/hooks/report-check.sh" |
| PreToolUse | Write | bash "$HOME/.claude/hooks/overwrite-guard.sh" |
| PreToolUse | Bash | i=$(cat); case "$i" in *'"dangerouslyDisableSandbox":true'*|*'"dangerouslyDisableSandbox": true'*) printf '%s' "$i" | bash "$HOME/.claude/hooks/delete-guard.sh" ;; esac |
| PreToolUse | * | bash "$HOME/.claude/hooks/tmux-state.sh" busy |
| PostToolUse | * | i=$(cat); case "$i" in *'"agent_id"'*) printf '%s' "$i" | bash "$HOME/.claude/hooks/delegation-ledger.sh" ;; esac |
| PostToolUse | * | bash "$HOME/.claude/hooks/tmux-state.sh" busy |
| SessionStart | startup|resume | bash "$HOME/.claude/hooks/delegation-due.sh" |
| SessionStart | startup|resume|clear|compact | bash "$HOME/.claude/hooks/session-registry.sh" |
| SessionStart | * | bash "$HOME/.claude/hooks/memory-git.sh" |
| SessionEnd | * | bash "$HOME/.claude/hooks/session-registry.sh" |
| SubagentStart | * | bash "$HOME/.claude/hooks/delegation-ledger.sh" |
| SubagentStop | * | bash "$HOME/.claude/hooks/delegation-ledger.sh" |
| SubagentStop | * | bash "$HOME/.claude/hooks/report-check.sh" |
| UserPromptSubmit | * | bash "$HOME/.claude/hooks/handoff-reminder.sh" |
| UserPromptSubmit | * | bash "$HOME/.claude/hooks/session-title.sh" |
| UserPromptSubmit | * | bash "$HOME/.claude/hooks/tmux-state.sh" busy |
| Stop | * | bash "$HOME/.claude/hooks/stop-ring.sh" |
| Stop | * | bash "$HOME/.claude/hooks/session-summary.sh" |
| Stop | * | bash "$HOME/.claude/hooks/watch-guard.sh" |
| Stop | * | bash "$HOME/.claude/hooks/memory-git.sh" |
| Stop | * | bash "$HOME/.claude/hooks/tmux-state.sh" idle |
| Notification | permission_prompt | bash "$HOME/.claude/hooks/notify.sh" |
| Notification | permission_prompt|elicitation_dialog | bash "$HOME/.claude/hooks/tmux-state.sh" wait |
Plugins (8)
superpowers@claude-plugins-officialcode-review@claude-plugins-officialcommit-commands@claude-plugins-officialclaude-md-management@claude-plugins-officialhookify@claude-plugins-officialcontext7@claude-plugins-officialchrome-devtools-mcp@claude-plugins-officialcodex@openai-codex
Permissions
deny (20)
Bash(git push --force*)
Bash(git push -f*)
Bash(git push * --force*)
Bash(git push * -f*)
Bash(git -C * push --force*)
Bash(git -C * push -f*)
Bash(git -C * push * --force*)
Bash(git -C * push * -f*)
Bash(git reset --hard*)
Bash(git reset * --hard*)
Bash(git -C * reset --hard*)
Bash(git -C * reset * --hard*)
Bash(git reset --merge*)
Bash(git reset * --merge*)
Bash(git -C * reset --merge*)
Bash(git -C * reset * --merge*)
Bash(git clean -*f*)
Bash(git -C * clean -*f*)
Bash(bash -c *git push*--force*)
Bash(bash -c *git reset*--hard*)
ask (15)
Bash(git push)
Bash(git push origin)
Bash(git push -*)
Bash(git push origin -*)
Bash(git push *main*)
Bash(git push *HEAD*)
Bash(git push *@*)
Bash(git push *--all*)
Bash(git push *--mirror*)
Bash(git push *+*)
Bash(git -C * push)
Bash(git -C * push *)
Bash(gh pr merge*)
Bash(gh api *merge*)
Bash(git *--output*)
allow (27)
Bash(delegation-ledger wait *)
Bash(git push origin *)
Bash(gh pr create *)
Bash(gh pr checks *)
Bash(gh pr view *)
Bash(gh pr list*)
Bash(gh pr status*)
Bash(gh pr diff *)
Bash(gh run list*)
Bash(gh run view *)
Bash(gh run watch *)
Bash(git status)
Bash(git status *)
Bash(git log)
Bash(git log *)
Bash(git diff)
Bash(git diff *)
Bash(git show)
Bash(git show *)
Bash(git rev-parse *)
Bash(head)
Bash(head *)
Bash(tail)
Bash(tail *)
Bash(wc)
Bash(wc *)
Bash(grep *)
Similar rigs
btclib-org/claude-process
The btclib-org Claude Code process: the /btclib-iss and /btclib-pr commands, the file they share, and the writer and reviewer agents
Pragmatist 987 tok ·
jaqubowsky/fleet
Runs Claude Code and pi agents in parallel on your Mac, one Docker sandbox per issue. A host agent hands out the work, watches every sandbox and brings back tested, reviewed pull requests.
Minimalist 341 tok ·
OMOCHInoHOSHI/dotfiles-claude
.claude
Pragmatist 293 tok ·
joaolozano-lendario/athena-os
A Claude Code Native System for Intelligent Workflow Architecture - Slash Commands for Smarter AI Workflows
Orchestrator 3.7k tok ·