~ / rigs / ifitsmanu / claude-template

ifitsmanu/claude-template

The best Claude Code setup template. 14 commands, 5 agents, 6 MCP servers, auto-formatting hooks. Based on Boris Cherny's workflow.

↗ GitHub ★ 2 MIT updated 9mo ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~17.2k tokens
Context hog · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add sequential-thinking -- npx -y @modelcontextprotocol/server-sequential-thinking
$ claude mcp add context7 -- npx -y @upstash/context7-mcp@latest
$ claude mcp add playwright -- npx -y @playwright/mcp@latest
$ claude mcp add memory -- npx -y @modelcontextprotocol/server-memory
$ claude mcp add exa -e EXA_<redacted> -- npx -y exa-mcp-server
$ claude mcp add jina -e JINA_<redacted> -- npx -y jina-mcp
$ npx degit ifitsmanu/claude-template/.claude ./rig-claude-template  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add sequential-thinking -- npx -y @modelcontextprotocol/server-sequential-thinking
$ claude mcp add context7 -- npx -y @upstash/context7-mcp@latest
$ claude mcp add playwright -- npx -y @playwright/mcp@latest
$ claude mcp add memory -- npx -y @modelcontextprotocol/server-memory
$ claude mcp add exa -e EXA_<redacted> -- npx -y exa-mcp-server
$ claude mcp add jina -e JINA_<redacted> -- npx -y jina-mcp

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(.env)",
      "Read(.env.*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/secrets.json)",
      "Read(**/secrets.yaml)",
      "Read(**/secret.json)",
      "Read(**/credentials.json)",
      "Read(**/*.pem)",
      "Read(**/*_rsa)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/*.pfx)",
      "Read(**/id_rsa)",
      "Read(**/id_ed25519)",
      "Bash(rm -rf /)",
      "Bash(rm -rf /*)",
      "Bash(rm -rf ~)",
      "Bash(rm -rf ~/*)",
      "Bash(git push --force)",
      "Bash(git push --force:*)",
      "Bash(git push -f)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard origin/*)",
      "Bash(sudo rm:*)",
      "Bash(sudo chmod:*)",
      "Bash(sudo chown:*)",
      "Bash(chmod 777:*)",
      "Bash(chmod -R 777:*)",
      "Bash(curl * | sh)",
      "Bash(curl * | bash)",
      "Bash(wget * | sh)",
      "Bash(wget * | bash)",
      "Bash(mkfs:*)",
      "Bash(dd if=/dev/zero:*)",
      "Bash(> /dev/sda)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash(npm run dev|pnpm dev|yarn dev|bun run dev|python manage.py runserver|uvicorn:*|flask run)",
        "hooks": [
          {
            "type": "command",
            "command": ".claude/hooks/check-tmux.sh"
          }
        ]
      }
    ]
  }
}

MCP servers (6)

serversourceest. tokens
Sequential Thinking · "sequential-thinking" npm 900
Context7 npm 1.2k
Playwright MCP · "playwright" npm 7.5k
Memory (knowledge graph) · "memory" npm 2.6k
Exa
env: EXA_API_KEY
npm 1.5k
jina-mcp · "jina"
env: JINA_API_KEY
npm 2.5k

Hooks (6)

eventmatcherruns
PreToolUseBash(npm run dev|pnpm dev|yarn dev|bun run dev|python manage.py runserver|uvicorn:*|flask run).claude/hooks/check-tmux.sh
PostToolUseEdit|Write.claude/hooks/post-save.sh
PostToolUseEdit(**/*.ts|**/*.tsx|**/*.js|**/*.jsx).claude/hooks/check-console-log.sh $FILE
PreCompact*.claude/hooks/save-state.sh
SessionStart*.claude/hooks/load-state.sh
Stop*.claude/hooks/save-state.sh

Slash commands (12)

/COMMANDS/deep/analyze/deep/debug/deep/plan/deep/refactor/parallel/implement/parallel/research/quick/commit/quick/fix/quick/ship/workflow/memory/workflow/sprint

Permissions

deny (36)
Read(.env)
Read(.env.*)
Read(**/.env)
Read(**/.env.*)
Read(**/secrets.json)
Read(**/secrets.yaml)
Read(**/secret.json)
Read(**/credentials.json)
Read(**/*.pem)
Read(**/*_rsa)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/id_rsa)
Read(**/id_ed25519)
Bash(rm -rf /)
Bash(rm -rf /*)
Bash(rm -rf ~)
Bash(rm -rf ~/*)
Bash(git push --force)
Bash(git push --force:*)
Bash(git push -f)
Bash(git push -f:*)
Bash(git reset --hard origin/*)
Bash(sudo rm:*)
Bash(sudo chmod:*)
Bash(sudo chown:*)
Bash(chmod 777:*)
Bash(chmod -R 777:*)
Bash(curl * | sh)
Bash(curl * | bash)
Bash(wget * | sh)
Bash(wget * | bash)
Bash(mkfs:*)
Bash(dd if=/dev/zero:*)
Bash(> /dev/sda)
ask (0)
—
allow (47)
Read
Glob
Grep
Task
WebFetch
WebSearch
TodoWrite
EnterPlanMode
ExitPlanMode
Skill
mcp__sequential-thinking__*
mcp__context7__*
mcp__memory__*
Bash(git status)
Bash(git status:*)
Bash(git diff)
Bash(git diff:*)
Bash(git log:*)
Bash(git branch)
Bash(git branch:*)
Bash(git show:*)
Bash(git rev-parse:*)
Bash(git remote:*)
Bash(ls)
Bash(ls:*)
Bash(cat:*)
Bash(head:*)
Bash(tail:*)
Bash(find:*)
Bash(wc:*)
Bash(echo:*)
Bash(pwd)
Bash(which:*)
Bash(env)
Bash(tree:*)
Bash(file:*)
Bash(stat:*)
Bash(du:*)
Bash(df:*)
Bash(grep:*)
Bash(awk:*)
Bash(sed:*)
Bash(sort:*)
Bash(uniq:*)
Bash(cut:*)
Bash(jq:*)
Bash(yq:*)

Similar rigs

copied ✓