jaymcgavren/dotfiles
My linux/unix/osx config files for the shell and various applications.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit jaymcgavren/dotfiles/dot_claude ./rig-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(gh pr comment *)",
"Bash(gh issue comment *)",
"Bash(git add -A*)",
"Bash(git add --all*)",
"Bash(git add .)"
],
"ask": [
"Bash(git push *)",
"Bash(rails runner *)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "~/.claude/hooks/bundle-exec-rewrite.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/git-c-rewrite.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/block-github-comment-create.sh"
}
]
}
]
}
} Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | ~/.claude/hooks/bundle-exec-rewrite.sh |
| PreToolUse | Bash | ~/.claude/hooks/git-c-rewrite.sh |
| PreToolUse | Bash | ~/.claude/hooks/block-github-comment-create.sh |
Plugins (3)
chrome-devtools-mcp@chrome-devtools-pluginsruby-lsp@claude-plugins-officialsuperpowers@claude-plugins-official
Permissions
deny (5)
Bash(gh pr comment *)
Bash(gh issue comment *)
Bash(git add -A*)
Bash(git add --all*)
Bash(git add .)
ask (2)
Bash(git push *)
Bash(rails runner *)
allow (23)
Bash(awk *)
Bash(bundle exec rspec *)
Bash(bundle exec rubocop *)
Bash(chezmoi diff *)
Bash(find *)
Bash(gh api *)
Bash(gh pr *)
Bash(git add *)
Bash(git commit *)
Bash(git log *)
Bash(git status:*)
Bash(grep *)
Bash(jq *)
Bash(ls *)
Bash(mise ls *)
Bash(rg *)
Bash(short api *)
Bash(short story *)
Bash(wc *)
mcp__shortcut__epics-get-by-id
mcp__shortcut__stories-get-by-id
mcp__shortcut__users-get-current
Read(~/.claude/**)
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·