joshukraine/dotfiles
:round_pushpin: My dotfiles for macOS using Neovim, Zsh, and Ghostty + Tmux
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit joshukraine/dotfiles/.claude ./rig-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit joshukraine/dotfiles/claude/.claude/skills/autopilot-batch .claude/skills/autopilot-batch $ npx degit joshukraine/dotfiles/claude/.claude/skills/autopilot-triage .claude/skills/autopilot-triage $ npx degit joshukraine/dotfiles/claude/.claude/skills/autopilot .claude/skills/autopilot $ npx degit joshukraine/dotfiles/claude/.claude/skills/bootstrap-prd .claude/skills/bootstrap-prd $ npx degit joshukraine/dotfiles/claude/.claude/skills/checkpoint .claude/skills/checkpoint $ npx degit joshukraine/dotfiles/claude/.claude/skills/create-pr .claude/skills/create-pr $ npx degit joshukraine/dotfiles/claude/.claude/skills/debrief .claude/skills/debrief $ npx degit joshukraine/dotfiles/claude/.claude/skills/drift-check .claude/skills/drift-check $ npx degit joshukraine/dotfiles/claude/.claude/skills/dustoff .claude/skills/dustoff $ npx degit joshukraine/dotfiles/claude/.claude/skills/md2pdf .claude/skills/md2pdf $ npx degit joshukraine/dotfiles/claude/.claude/skills/merge-pr .claude/skills/merge-pr $ npx degit joshukraine/dotfiles/claude/.claude/skills/model-triage .claude/skills/model-triage $ npx degit joshukraine/dotfiles/claude/.claude/skills/plan-phase .claude/skills/plan-phase $ npx degit joshukraine/dotfiles/claude/.claude/skills/prd-view .claude/skills/prd-view $ npx degit joshukraine/dotfiles/claude/.claude/skills/qa-handoff .claude/skills/qa-handoff $ npx degit joshukraine/dotfiles/claude/.claude/skills/qa-triage-batch .claude/skills/qa-triage-batch $ npx degit joshukraine/dotfiles/claude/.claude/skills/qa-triage .claude/skills/qa-triage $ npx degit joshukraine/dotfiles/claude/.claude/skills/readme-refresh .claude/skills/readme-refresh $ npx degit joshukraine/dotfiles/claude/.claude/skills/resolve-issue .claude/skills/resolve-issue $ npx degit joshukraine/dotfiles/claude/.claude/skills/ruby-gc .claude/skills/ruby-gc $ npx degit joshukraine/dotfiles/claude/.claude/skills/sidecar .claude/skills/sidecar $ npx degit joshukraine/dotfiles/claude/.claude/skills/todoist-cli .claude/skills/todoist-cli $ npx degit joshukraine/dotfiles/claude/.claude/skills/update-deps .claude/skills/update-deps $ npx degit joshukraine/dotfiles/claude/.claude/skills/walkthrough .claude/skills/walkthrough
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(curl *|bash*)",
"Bash(dd:*)",
"Bash(git clean -fd:*)",
"Bash(git clean -fx:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git reset --hard:*)",
"Bash(mkfs:*)",
"Bash(rm -fr:*)",
"Bash(rm -rf:*)",
"Bash(sudo:*)",
"Bash(wget *|bash*)",
"Edit(~/.bashrc)",
"Edit(~/.ssh/**)",
"Edit(~/.zshrc)",
"Read(~/.aws/**)",
"Read(~/.docker/config.json)",
"Read(~/.git-credentials)",
"Read(~/.ssh/**)",
"Read(~/Library/Keychains/**)",
"Bash(curl *|bash*)",
"Bash(dd:*)",
"Bash(git clean -fd:*)",
"Bash(git clean -fx:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git reset --hard:*)",
"Bash(mkfs:*)",
"Bash(rm -fr:*)",
"Bash(rm -rf:*)",
"Bash(sudo:*)",
"Bash(wget *|bash*)",
"Edit(~/.bashrc)",
"Edit(~/.ssh/**)",
"Edit(~/.zshrc)",
"Read(~/.aws/**)",
"Read(~/.docker/config.json)",
"Read(~/.git-credentials)",
"Read(~/.ssh/**)",
"Read(~/Library/Keychains/**)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qE 'rm[[:space:]]+-[^[:space:]]*r[^[:space:]]*f'; then echo 'BLOCKED: Use trash instead of rm -rf' >&2; exit 2; fi; if echo \"$CMD\" | grep -qE 'git push.*(--force([[:space:]]|$)|[[:s"
}
]
}
]
}
} Skills (24)
autopilot-batchautopilot-triageautopilotbootstrap-prdcheckpointcreate-prdebriefdrift-checkdustoffmd2pdfmerge-prmodel-triageplan-phaseprd-viewqa-handoffqa-triage-batchqa-triagereadme-refreshresolve-issueruby-gcsidecartodoist-cliupdate-depswalkthrough
Hooks (4)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qE 'rm[[:space:]]+-[^[:space:]]*r[^[:space:]]*f'; then echo 'BLOCKED: Use trash instead of rm -rf' >&2; exit 2; fi; if echo "$CMD" | grep -qE 'git push.*(--force([[:space:]]|$)|[[:s |
| PostToolUse | Bash | jq -r '"[" + (now | todate) + "] " + .tool_input.command' >> ~/.claude/bash-commands.log |
| Notification | * | osascript -e 'display notification "Claude needs your attention" with title "Claude Code"' |
| Notification | * | afplay /System/Library/Sounds/Glass.aiff |
Plugins (5)
lua-lsp@claude-plugins-officialtypescript-lsp@claude-plugins-officialstarship-claude@starship-clauderuby-lsp@claude-plugins-officialpyright-lsp@claude-plugins-official
Permissions
deny (40)
Bash(curl *|bash*)
Bash(dd:*)
Bash(git clean -fd:*)
Bash(git clean -fx:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(mkfs:*)
Bash(rm -fr:*)
Bash(rm -rf:*)
Bash(sudo:*)
Bash(wget *|bash*)
Edit(~/.bashrc)
Edit(~/.ssh/**)
Edit(~/.zshrc)
Read(~/.aws/**)
Read(~/.docker/config.json)
Read(~/.git-credentials)
Read(~/.ssh/**)
Read(~/Library/Keychains/**)
Bash(curl *|bash*)
Bash(dd:*)
Bash(git clean -fd:*)
Bash(git clean -fx:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
Bash(mkfs:*)
Bash(rm -fr:*)
Bash(rm -rf:*)
Bash(sudo:*)
Bash(wget *|bash*)
Edit(~/.bashrc)
Edit(~/.ssh/**)
Edit(~/.zshrc)
Read(~/.aws/**)
Read(~/.docker/config.json)
Read(~/.git-credentials)
Read(~/.ssh/**)
Read(~/Library/Keychains/**)
ask (0)
—
allow (120)
Bash(./scripts/lint-shell:*)
Bash(./scripts/run-tests:*)
Bash(awk:*)
Bash(basename:*)
Bash(bats:*)
Bash(brew info:*)
Bash(brew list:*)
Bash(brew search:*)
Bash(brew uninstall:*)
Bash(cat:*)
Bash(chmod:*)
Bash(command -v:*)
Bash(cp:*)
Bash(cut:*)
Bash(date:*)
Bash(diff:*)
Bash(dirname:*)
Bash(echo:*)
Bash(env:*)
Bash(file:*)
Bash(find:*)
Bash(gh api:*)
Bash(gh issue:*)
Bash(gh label:*)
Bash(gh pr:*)
Bash(gh run:*)
Bash(gh search:*)
Bash(git add:*)
Bash(git branch:*)
Bash(git check-ignore:*)
Bash(git checkout:*)
Bash(git commit:*)
Bash(git config:*)
Bash(git diff:*)
Bash(git fetch:*)
Bash(git log:*)
Bash(git merge:*)
Bash(git pull:*)
Bash(git push --force-with-lease:*)
Bash(git push:*)
Bash(git rebase:*)
Bash(git remote:*)
Bash(git rev-parse:*)
Bash(git show:*)
Bash(git stash:*)
Bash(git status:*)
Bash(git switch:*)
Bash(git tag:*)
Bash(grep:*)
Bash(head:*)
Bash(ls:*)
Bash(lua:*)
Bash(markdownlint-cli2:*)
Bash(mkdir:*)
Bash(mv:*)
Bash(pre-commit run:*)
Bash(printenv:*)
Bash(pwd:*)
Bash(rm:*)
Bash(sed:*)
Similar rigs
Jkudjo/oh-my-cursor
Workflow layer for Cursor — structured skills, MCP state, and tmux parallel agents
Skill Collector 684 tok ·
2found/2build
Product engineering workflows: plan, implement, review, test, QA and release. A 2found product.
Skill Collector 7.7k tok ·
SatymSingh01/claude-code-pack
Drop-in config pack for Claude Code: CLAUDE.md best practices, safety hooks, auto-checkpoint, session logging, and slash commands. One install script.
Minimalist 344 tok ·
ReflexioAI/claude-smart
Turns corrections into Preferences, Project-specific skills, and Shared skills for Claude Code, Codex, and OpenCode.
Minimalist 327 tok ·