herdrdev/herdr
the runtime your coding agents live on
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ npx degit herdrdev/herdr/skills ./rig-herdr/skills MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit herdrdev/herdr/.agents/skills/herdr-pre-release-audit .claude/skills/herdr-pre-release-audit $ npx degit herdrdev/herdr/.agents/skills/herdr-throwaway-repro .claude/skills/herdr-throwaway-repro $ npx degit herdrdev/herdr/.agents/skills/triage .claude/skills/triage $ npx degit herdrdev/herdr/skills/herdr .claude/skills/herdr
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,413 rigs:
{
"permissions": {
"deny": [
"Read(~/.ssh/**)",
"Read(**/.env)",
"Bash(rm -rf *)",
"Read(./.env)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(**/*.pem)",
"Bash(rm -rf /*)",
"Read(~/.aws/**)",
"Bash(rm -rf:*)",
"Read(.env)",
"Bash(git push --force*)",
"Read(**/*.key)",
"Read(./.env.*)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(gh pr merge *)",
"Bash(chown *)",
"Bash(docker *)"
]
}
} Skills (4)
Similar rigs
technicalpickles/dotfiles
My shareable dotfiles
Pragmatist 4.3k tok ·
bitbonsai/mcpvault
A lightweight Model Context Protocol (MCP) server for safe Obsidian vault access
Pragmatist 2.6k tok ·
kradalby/dotfiles
monorepo for everything in my tech life.
Minimalist 2.1k tok ·
nettlesh/dotfiles
The pinnacle of dotfile engineering
Minimalist 1.1k tok ·