~ / rigs / joshukraine / dotfiles

joshukraine/dotfiles

:round_pushpin: My dotfiles for macOS using Neovim, Zsh, and Ghostty + Tmux

↗ GitHub ★ 429 MIT updated 3d ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~4.8k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit joshukraine/dotfiles/.claude ./rig-dotfiles  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit joshukraine/dotfiles/claude/.claude/skills/autopilot-batch .claude/skills/autopilot-batch
$ npx degit joshukraine/dotfiles/claude/.claude/skills/autopilot-triage .claude/skills/autopilot-triage
$ npx degit joshukraine/dotfiles/claude/.claude/skills/autopilot .claude/skills/autopilot
$ npx degit joshukraine/dotfiles/claude/.claude/skills/bootstrap-prd .claude/skills/bootstrap-prd
$ npx degit joshukraine/dotfiles/claude/.claude/skills/checkpoint .claude/skills/checkpoint
$ npx degit joshukraine/dotfiles/claude/.claude/skills/create-pr .claude/skills/create-pr
$ npx degit joshukraine/dotfiles/claude/.claude/skills/debrief .claude/skills/debrief
$ npx degit joshukraine/dotfiles/claude/.claude/skills/drift-check .claude/skills/drift-check
$ npx degit joshukraine/dotfiles/claude/.claude/skills/dustoff .claude/skills/dustoff
$ npx degit joshukraine/dotfiles/claude/.claude/skills/md2pdf .claude/skills/md2pdf
$ npx degit joshukraine/dotfiles/claude/.claude/skills/merge-pr .claude/skills/merge-pr
$ npx degit joshukraine/dotfiles/claude/.claude/skills/model-triage .claude/skills/model-triage
$ npx degit joshukraine/dotfiles/claude/.claude/skills/plan-phase .claude/skills/plan-phase
$ npx degit joshukraine/dotfiles/claude/.claude/skills/prd-view .claude/skills/prd-view
$ npx degit joshukraine/dotfiles/claude/.claude/skills/qa-handoff .claude/skills/qa-handoff
$ npx degit joshukraine/dotfiles/claude/.claude/skills/qa-triage-batch .claude/skills/qa-triage-batch
$ npx degit joshukraine/dotfiles/claude/.claude/skills/qa-triage .claude/skills/qa-triage
$ npx degit joshukraine/dotfiles/claude/.claude/skills/readme-refresh .claude/skills/readme-refresh
$ npx degit joshukraine/dotfiles/claude/.claude/skills/resolve-issue .claude/skills/resolve-issue
$ npx degit joshukraine/dotfiles/claude/.claude/skills/ruby-gc .claude/skills/ruby-gc
$ npx degit joshukraine/dotfiles/claude/.claude/skills/sidecar .claude/skills/sidecar
$ npx degit joshukraine/dotfiles/claude/.claude/skills/todoist-cli .claude/skills/todoist-cli
$ npx degit joshukraine/dotfiles/claude/.claude/skills/update-deps .claude/skills/update-deps
$ npx degit joshukraine/dotfiles/claude/.claude/skills/walkthrough .claude/skills/walkthrough

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(curl *|bash*)",
      "Bash(dd:*)",
      "Bash(git clean -fd:*)",
      "Bash(git clean -fx:*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(mkfs:*)",
      "Bash(rm -fr:*)",
      "Bash(rm -rf:*)",
      "Bash(sudo:*)",
      "Bash(wget *|bash*)",
      "Edit(~/.bashrc)",
      "Edit(~/.ssh/**)",
      "Edit(~/.zshrc)",
      "Read(~/.aws/**)",
      "Read(~/.docker/config.json)",
      "Read(~/.git-credentials)",
      "Read(~/.ssh/**)",
      "Read(~/Library/Keychains/**)",
      "Bash(curl *|bash*)",
      "Bash(dd:*)",
      "Bash(git clean -fd:*)",
      "Bash(git clean -fx:*)",
      "Bash(git push --force:*)",
      "Bash(git push -f:*)",
      "Bash(git reset --hard:*)",
      "Bash(mkfs:*)",
      "Bash(rm -fr:*)",
      "Bash(rm -rf:*)",
      "Bash(sudo:*)",
      "Bash(wget *|bash*)",
      "Edit(~/.bashrc)",
      "Edit(~/.ssh/**)",
      "Edit(~/.zshrc)",
      "Read(~/.aws/**)",
      "Read(~/.docker/config.json)",
      "Read(~/.git-credentials)",
      "Read(~/.ssh/**)",
      "Read(~/Library/Keychains/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qE 'rm[[:space:]]+-[^[:space:]]*r[^[:space:]]*f'; then echo 'BLOCKED: Use trash instead of rm -rf' >&2; exit 2; fi; if echo \"$CMD\" | grep -qE 'git push.*(--force([[:space:]]|$)|[[:s"
          }
        ]
      }
    ]
  }
}

Skills (24)

Hooks (4)

eventmatcherruns
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qE 'rm[[:space:]]+-[^[:space:]]*r[^[:space:]]*f'; then echo 'BLOCKED: Use trash instead of rm -rf' >&2; exit 2; fi; if echo "$CMD" | grep -qE 'git push.*(--force([[:space:]]|$)|[[:s
PostToolUseBashjq -r '"[" + (now | todate) + "] " + .tool_input.command' >> ~/.claude/bash-commands.log
Notification*osascript -e 'display notification "Claude needs your attention" with title "Claude Code"'
Notification*afplay /System/Library/Sounds/Glass.aiff

Plugins (5)

lua-lsp@claude-plugins-officialtypescript-lsp@claude-plugins-officialstarship-claude@starship-clauderuby-lsp@claude-plugins-officialpyright-lsp@claude-plugins-official

Permissions

deny (40)
Bash(curl *|bash*)
Bash(dd:*)
Bash(git clean -fd:*)
Bash(git clean -fx:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(mkfs:*)
Bash(rm -fr:*)
Bash(rm -rf:*)
Bash(sudo:*)
Bash(wget *|bash*)
Edit(~/.bashrc)
Edit(~/.ssh/**)
Edit(~/.zshrc)
Read(~/.aws/**)
Read(~/.docker/config.json)
Read(~/.git-credentials)
Read(~/.ssh/**)
Read(~/Library/Keychains/**)
Bash(curl *|bash*)
Bash(dd:*)
Bash(git clean -fd:*)
Bash(git clean -fx:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(mkfs:*)
Bash(rm -fr:*)
Bash(rm -rf:*)
Bash(sudo:*)
Bash(wget *|bash*)
Edit(~/.bashrc)
Edit(~/.ssh/**)
Edit(~/.zshrc)
Read(~/.aws/**)
Read(~/.docker/config.json)
Read(~/.git-credentials)
Read(~/.ssh/**)
Read(~/Library/Keychains/**)
ask (0)
—
allow (120)
Bash(./scripts/lint-shell:*)
Bash(./scripts/run-tests:*)
Bash(awk:*)
Bash(basename:*)
Bash(bats:*)
Bash(brew info:*)
Bash(brew list:*)
Bash(brew search:*)
Bash(brew uninstall:*)
Bash(cat:*)
Bash(chmod:*)
Bash(command -v:*)
Bash(cp:*)
Bash(cut:*)
Bash(date:*)
Bash(diff:*)
Bash(dirname:*)
Bash(echo:*)
Bash(env:*)
Bash(file:*)
Bash(find:*)
Bash(gh api:*)
Bash(gh issue:*)
Bash(gh label:*)
Bash(gh pr:*)
Bash(gh run:*)
Bash(gh search:*)
Bash(git add:*)
Bash(git branch:*)
Bash(git check-ignore:*)
Bash(git checkout:*)
Bash(git commit:*)
Bash(git config:*)
Bash(git diff:*)
Bash(git fetch:*)
Bash(git log:*)
Bash(git merge:*)
Bash(git pull:*)
Bash(git push --force-with-lease:*)
Bash(git push:*)
Bash(git rebase:*)
Bash(git remote:*)
Bash(git rev-parse:*)
Bash(git show:*)
Bash(git stash:*)
Bash(git status:*)
Bash(git switch:*)
Bash(git tag:*)
Bash(grep:*)
Bash(head:*)
Bash(ls:*)
Bash(lua:*)
Bash(markdownlint-cli2:*)
Bash(mkdir:*)
Bash(mv:*)
Bash(pre-commit run:*)
Bash(printenv:*)
Bash(pwd:*)
Bash(rm:*)
Bash(sed:*)

Similar rigs

copied ✓