~ / rigs / jtrv / dotfiles

jtrv/dotfiles

A repository for all my configurations

↗ GitHub ★ 22 no license updated 15d ago personal setup Claude CodeCodexGemini CLI
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~5.1k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

$ git clone --depth 1 https://github.com/jtrv/dotfiles

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit jtrv/dotfiles/.config/agents/skills/agy .claude/skills/agy
$ npx degit jtrv/dotfiles/.config/agents/skills/cholo .claude/skills/cholo
$ npx degit jtrv/dotfiles/.config/agents/skills/dotfiles .claude/skills/dotfiles
$ npx degit jtrv/dotfiles/.config/agents/skills/find-skills .claude/skills/find-skills
$ npx degit jtrv/dotfiles/.config/agents/skills/flutter-verify-loop .claude/skills/flutter-verify-loop
$ npx degit jtrv/dotfiles/.config/agents/skills/flutter .claude/skills/flutter
$ npx degit jtrv/dotfiles/.config/agents/skills/geiger .claude/skills/geiger
$ npx degit jtrv/dotfiles/.config/agents/skills/go .claude/skills/go
$ npx degit jtrv/dotfiles/.config/agents/skills/grill-me .claude/skills/grill-me
$ npx degit jtrv/dotfiles/.config/agents/skills/grilling .claude/skills/grilling
$ npx degit jtrv/dotfiles/.config/agents/skills/grind .claude/skills/grind
$ npx degit jtrv/dotfiles/.config/agents/skills/handoff .claude/skills/handoff
$ npx degit jtrv/dotfiles/.config/agents/skills/html-report .claude/skills/html-report
$ npx degit jtrv/dotfiles/.config/agents/skills/kotlin .claude/skills/kotlin
$ npx degit jtrv/dotfiles/.config/agents/skills/nix .claude/skills/nix
$ npx degit jtrv/dotfiles/.config/agents/skills/plan-refute .claude/skills/plan-refute
$ npx degit jtrv/dotfiles/.config/agents/skills/python .claude/skills/python
$ npx degit jtrv/dotfiles/.config/agents/skills/rust .claude/skills/rust
$ npx degit jtrv/dotfiles/.config/agents/skills/tutor .claude/skills/tutor
$ npx degit jtrv/dotfiles/.config/agents/skills/typescript .claude/skills/typescript
$ npx degit jtrv/dotfiles/.config/agents/skills/unslop .claude/skills/unslop

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.local)",
      "Read(**/.env.*.local)",
      "Read(**/.env.production)",
      "Read(**/.env.development)",
      "Read(**/.env.staging)",
      "Read(**/.env.test)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/*.pfx)",
      "Read(**/*.jks)",
      "Read(**/*.keystore)",
      "Read(**/*.ppk)",
      "Read(**/*.asc)",
      "Read(**/*.gpg)",
      "Read(**/*.p8)",
      "Read(**/*.kdbx)",
      "Read(**/*.ovpn)",
      "Read(**/id_rsa)",
      "Read(**/id_dsa)",
      "Read(**/id_ecdsa)",
      "Read(**/id_ed25519)",
      "Read(**/.ssh/**)",
      "Read(**/.aws/**)",
      "Read(**/.gnupg/**)",
      "Read(**/.kube/**)",
      "Read(**/.docker/**)",
      "Read(**/.azure/**)",
      "Read(**/.config/gcloud/**)",
      "Read(**/.local/share/keyrings/**)",
      "Read(**/.password-store/**)",
      "Read(**/.netrc)",
      "Read(**/.npmrc)",
      "Read(**/.pypirc)",
      "Read(**/.git-credentials)",
      "Read(**/.htpasswd)",
      "Read(**/.pgpass)",
      "Read(**/.my.cnf)",
      "Read(**/.authinfo)",
      "Read(**/.authinfo.gpg)",
      "Read(**/credentials)",
      "Read(**/credentials.json)",
      "Read(**/credentials.yaml)",
      "Read(**/credentials.yml)",
      "Read(**/credentials.toml)",
      "Read(**/credentials.ini)",
      "Read(**/credentials.csv)",
      "Read(**/.credentials.json)",
      "Read(**/.credentials.yaml)",
      "Read(**/.credentials.yml)",
      "Read(**/secret.json)",
      "Read(**/secret.yaml)",
      "Read(**/secret.yml)",
      "Read(**/secrets.json)",
      "Read(**/secrets.yaml)",
      "Read(**/secrets.yml)",
      "Read(**/secrets.toml)",
      "Read(**/secrets.ini)",
      "Read(**/secrets.txt)",
      "Read(**/secrets.enc)",
      "Read(**/secrets.env)",
      "Read(**/terraform.tfvars)",
      "Read(**/*service-account*.json)",
      "Read(**/*service_account*.json)",
      "Read(**/*serviceaccount*.json)",
      "Read(**/*client_secret*)",
      "Read(**/*serviceAccountKey*)",
      "Read(**/*firebase-adminsdk*)",
      "Read(**/auth.json)",
      "Read(**/.auth.json)",
      "Read(**/gh/hosts.yml)",
      "Read(**/gh/hosts.yaml)",
      "Read(**/rclone.conf)",
      "Read(**/age/keys.txt)",
      "Read(**/mise.local.toml)"
    ],
    "ask": [
      "Bash(rm -rf *)",
      "Bash(rm -fr *)",
      "Bash(git push *--force*)",
      "Bash(git push -f*)",
      "Bash(git push * -f)",
      "Bash(git push * -f *)",
      "Bash(git reset --hard*)",
      "Bash(git clean -f*)",
      "Bash(config push *--force*)",
      "Bash(config push -f*)",
      "Bash(config push * -f)",
      "Bash(config push * -f *)",
      "Bash(config reset --hard*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "*",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"~/.config/agents/hooks/block-secrets.sh\""
          },
          {
            "type": "command",
            "command": "bash \"~/.config/claude/hooks/nosleep.sh\" acquire"
          }
        ]
      }
    ]
  }
}

Skills (21)

Hooks (16)

eventmatcherruns
Notification*bash "~/.config/claude/hooks/nosleep.sh" release
Notification*bash "~/.config/claude/hooks/herdr-codex-state.sh" clear
PreToolUse*bash "~/.config/agents/hooks/block-secrets.sh"
PreToolUse*bash "~/.config/claude/hooks/nosleep.sh" acquire
SessionEnd*bash "~/.config/claude/hooks/nosleep.sh" release
SessionEnd*bash "~/.config/claude/hooks/herdr-codex-state.sh" clear
SessionStart*"~/.config/claude/hooks/context-mode-cache-heal.mjs"
SessionStart*"~/.config/claude/hooks/capture-window.sh"
SessionStartcompactecho 'Context was just compacted. Summaries drift: re-read any state.md/ledger and the relevant ~/.config/agents/contexts/ file before continuing; treat compaction-summary claims about decisions and constraints as unverified until checked a
SessionStart^(startup|resume|clear|compact|fork)$bash '~/.config/claude/hooks/herdr-agent-state.sh' session
SessionStart*bash "~/.config/agents/hooks/cholo-context.sh"
Stop*bash "~/.config/claude/hooks/nosleep.sh" release
Stop*bash "~/.config/claude/hooks/herdr-codex-state.sh" stop
UserPromptSubmit*bash "~/.config/claude/hooks/nosleep.sh" acquire
PreCompact*echo 'Preserve verbatim in the summary: current objective; decisions with status (accepted/provisional/superseded); failed attempts and why; constraints and rules currently in effect; the exact next action. If a state.md or ledger file exis
SubagentStart*bash "~/.config/agents/hooks/cholo-context.sh"

Plugins (12)

codex@openai-codexcontext-mode@context-modecontext7@claude-plugins-officialralph-loop@claude-plugins-officialremember@claude-plugins-officialrust-analyzer-lsp@claude-plugins-officialsecurity-guidance@claude-plugins-officialskill-creator@claude-plugins-officialtypescript-lsp@claude-plugins-officialclangd-lsp@claude-plugins-officialcloudflare@cloudflaretypesafe@typesafe-ai

Permissions

deny (76)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.*.local)
Read(**/.env.production)
Read(**/.env.development)
Read(**/.env.staging)
Read(**/.env.test)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.jks)
Read(**/*.keystore)
Read(**/*.ppk)
Read(**/*.asc)
Read(**/*.gpg)
Read(**/*.p8)
Read(**/*.kdbx)
Read(**/*.ovpn)
Read(**/id_rsa)
Read(**/id_dsa)
Read(**/id_ecdsa)
Read(**/id_ed25519)
Read(**/.ssh/**)
Read(**/.aws/**)
Read(**/.gnupg/**)
Read(**/.kube/**)
Read(**/.docker/**)
Read(**/.azure/**)
Read(**/.config/gcloud/**)
Read(**/.local/share/keyrings/**)
Read(**/.password-store/**)
Read(**/.netrc)
Read(**/.npmrc)
Read(**/.pypirc)
Read(**/.git-credentials)
Read(**/.htpasswd)
Read(**/.pgpass)
Read(**/.my.cnf)
Read(**/.authinfo)
Read(**/.authinfo.gpg)
Read(**/credentials)
Read(**/credentials.json)
Read(**/credentials.yaml)
Read(**/credentials.yml)
Read(**/credentials.toml)
Read(**/credentials.ini)
Read(**/credentials.csv)
Read(**/.credentials.json)
Read(**/.credentials.yaml)
Read(**/.credentials.yml)
Read(**/secret.json)
Read(**/secret.yaml)
Read(**/secret.yml)
Read(**/secrets.json)
Read(**/secrets.yaml)
Read(**/secrets.yml)
Read(**/secrets.toml)
Read(**/secrets.ini)
Read(**/secrets.txt)
ask (13)
Bash(rm -rf *)
Bash(rm -fr *)
Bash(git push *--force*)
Bash(git push -f*)
Bash(git push * -f)
Bash(git push * -f *)
Bash(git reset --hard*)
Bash(git clean -f*)
Bash(config push *--force*)
Bash(config push -f*)
Bash(config push * -f)
Bash(config push * -f *)
Bash(config reset --hard*)
allow (0)
—

Similar rigs

copied ✓