jtrv/dotfiles
A repository for all my configurations
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
$ git clone --depth 1 https://github.com/jtrv/dotfiles MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit jtrv/dotfiles/.config/agents/skills/agy .claude/skills/agy $ npx degit jtrv/dotfiles/.config/agents/skills/cholo .claude/skills/cholo $ npx degit jtrv/dotfiles/.config/agents/skills/dotfiles .claude/skills/dotfiles $ npx degit jtrv/dotfiles/.config/agents/skills/find-skills .claude/skills/find-skills $ npx degit jtrv/dotfiles/.config/agents/skills/flutter-verify-loop .claude/skills/flutter-verify-loop $ npx degit jtrv/dotfiles/.config/agents/skills/flutter .claude/skills/flutter $ npx degit jtrv/dotfiles/.config/agents/skills/geiger .claude/skills/geiger $ npx degit jtrv/dotfiles/.config/agents/skills/go .claude/skills/go $ npx degit jtrv/dotfiles/.config/agents/skills/grill-me .claude/skills/grill-me $ npx degit jtrv/dotfiles/.config/agents/skills/grilling .claude/skills/grilling $ npx degit jtrv/dotfiles/.config/agents/skills/grind .claude/skills/grind $ npx degit jtrv/dotfiles/.config/agents/skills/handoff .claude/skills/handoff $ npx degit jtrv/dotfiles/.config/agents/skills/html-report .claude/skills/html-report $ npx degit jtrv/dotfiles/.config/agents/skills/kotlin .claude/skills/kotlin $ npx degit jtrv/dotfiles/.config/agents/skills/nix .claude/skills/nix $ npx degit jtrv/dotfiles/.config/agents/skills/plan-refute .claude/skills/plan-refute $ npx degit jtrv/dotfiles/.config/agents/skills/python .claude/skills/python $ npx degit jtrv/dotfiles/.config/agents/skills/rust .claude/skills/rust $ npx degit jtrv/dotfiles/.config/agents/skills/tutor .claude/skills/tutor $ npx degit jtrv/dotfiles/.config/agents/skills/typescript .claude/skills/typescript $ npx degit jtrv/dotfiles/.config/agents/skills/unslop .claude/skills/unslop
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(**/.env)",
"Read(**/.env.local)",
"Read(**/.env.*.local)",
"Read(**/.env.production)",
"Read(**/.env.development)",
"Read(**/.env.staging)",
"Read(**/.env.test)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/*.p12)",
"Read(**/*.pfx)",
"Read(**/*.jks)",
"Read(**/*.keystore)",
"Read(**/*.ppk)",
"Read(**/*.asc)",
"Read(**/*.gpg)",
"Read(**/*.p8)",
"Read(**/*.kdbx)",
"Read(**/*.ovpn)",
"Read(**/id_rsa)",
"Read(**/id_dsa)",
"Read(**/id_ecdsa)",
"Read(**/id_ed25519)",
"Read(**/.ssh/**)",
"Read(**/.aws/**)",
"Read(**/.gnupg/**)",
"Read(**/.kube/**)",
"Read(**/.docker/**)",
"Read(**/.azure/**)",
"Read(**/.config/gcloud/**)",
"Read(**/.local/share/keyrings/**)",
"Read(**/.password-store/**)",
"Read(**/.netrc)",
"Read(**/.npmrc)",
"Read(**/.pypirc)",
"Read(**/.git-credentials)",
"Read(**/.htpasswd)",
"Read(**/.pgpass)",
"Read(**/.my.cnf)",
"Read(**/.authinfo)",
"Read(**/.authinfo.gpg)",
"Read(**/credentials)",
"Read(**/credentials.json)",
"Read(**/credentials.yaml)",
"Read(**/credentials.yml)",
"Read(**/credentials.toml)",
"Read(**/credentials.ini)",
"Read(**/credentials.csv)",
"Read(**/.credentials.json)",
"Read(**/.credentials.yaml)",
"Read(**/.credentials.yml)",
"Read(**/secret.json)",
"Read(**/secret.yaml)",
"Read(**/secret.yml)",
"Read(**/secrets.json)",
"Read(**/secrets.yaml)",
"Read(**/secrets.yml)",
"Read(**/secrets.toml)",
"Read(**/secrets.ini)",
"Read(**/secrets.txt)",
"Read(**/secrets.enc)",
"Read(**/secrets.env)",
"Read(**/terraform.tfvars)",
"Read(**/*service-account*.json)",
"Read(**/*service_account*.json)",
"Read(**/*serviceaccount*.json)",
"Read(**/*client_secret*)",
"Read(**/*serviceAccountKey*)",
"Read(**/*firebase-adminsdk*)",
"Read(**/auth.json)",
"Read(**/.auth.json)",
"Read(**/gh/hosts.yml)",
"Read(**/gh/hosts.yaml)",
"Read(**/rclone.conf)",
"Read(**/age/keys.txt)",
"Read(**/mise.local.toml)"
],
"ask": [
"Bash(rm -rf *)",
"Bash(rm -fr *)",
"Bash(git push *--force*)",
"Bash(git push -f*)",
"Bash(git push * -f)",
"Bash(git push * -f *)",
"Bash(git reset --hard*)",
"Bash(git clean -f*)",
"Bash(config push *--force*)",
"Bash(config push -f*)",
"Bash(config push * -f)",
"Bash(config push * -f *)",
"Bash(config reset --hard*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "bash \"~/.config/agents/hooks/block-secrets.sh\""
},
{
"type": "command",
"command": "bash \"~/.config/claude/hooks/nosleep.sh\" acquire"
}
]
}
]
}
} Skills (21)
agycholodotfilesfind-skillsflutter-verify-loopfluttergeigergogrill-megrillinggrindhandoffhtml-reportkotlinnixplan-refutepythonrusttutortypescriptunslop
Hooks (16)
| event | matcher | runs |
|---|---|---|
| Notification | * | bash "~/.config/claude/hooks/nosleep.sh" release |
| Notification | * | bash "~/.config/claude/hooks/herdr-codex-state.sh" clear |
| PreToolUse | * | bash "~/.config/agents/hooks/block-secrets.sh" |
| PreToolUse | * | bash "~/.config/claude/hooks/nosleep.sh" acquire |
| SessionEnd | * | bash "~/.config/claude/hooks/nosleep.sh" release |
| SessionEnd | * | bash "~/.config/claude/hooks/herdr-codex-state.sh" clear |
| SessionStart | * | "~/.config/claude/hooks/context-mode-cache-heal.mjs" |
| SessionStart | * | "~/.config/claude/hooks/capture-window.sh" |
| SessionStart | compact | echo 'Context was just compacted. Summaries drift: re-read any state.md/ledger and the relevant ~/.config/agents/contexts/ file before continuing; treat compaction-summary claims about decisions and constraints as unverified until checked a |
| SessionStart | ^(startup|resume|clear|compact|fork)$ | bash '~/.config/claude/hooks/herdr-agent-state.sh' session |
| SessionStart | * | bash "~/.config/agents/hooks/cholo-context.sh" |
| Stop | * | bash "~/.config/claude/hooks/nosleep.sh" release |
| Stop | * | bash "~/.config/claude/hooks/herdr-codex-state.sh" stop |
| UserPromptSubmit | * | bash "~/.config/claude/hooks/nosleep.sh" acquire |
| PreCompact | * | echo 'Preserve verbatim in the summary: current objective; decisions with status (accepted/provisional/superseded); failed attempts and why; constraints and rules currently in effect; the exact next action. If a state.md or ledger file exis |
| SubagentStart | * | bash "~/.config/agents/hooks/cholo-context.sh" |
Plugins (12)
codex@openai-codexcontext-mode@context-modecontext7@claude-plugins-officialralph-loop@claude-plugins-officialremember@claude-plugins-officialrust-analyzer-lsp@claude-plugins-officialsecurity-guidance@claude-plugins-officialskill-creator@claude-plugins-officialtypescript-lsp@claude-plugins-officialclangd-lsp@claude-plugins-officialcloudflare@cloudflaretypesafe@typesafe-ai
Permissions
deny (76)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.*.local)
Read(**/.env.production)
Read(**/.env.development)
Read(**/.env.staging)
Read(**/.env.test)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.jks)
Read(**/*.keystore)
Read(**/*.ppk)
Read(**/*.asc)
Read(**/*.gpg)
Read(**/*.p8)
Read(**/*.kdbx)
Read(**/*.ovpn)
Read(**/id_rsa)
Read(**/id_dsa)
Read(**/id_ecdsa)
Read(**/id_ed25519)
Read(**/.ssh/**)
Read(**/.aws/**)
Read(**/.gnupg/**)
Read(**/.kube/**)
Read(**/.docker/**)
Read(**/.azure/**)
Read(**/.config/gcloud/**)
Read(**/.local/share/keyrings/**)
Read(**/.password-store/**)
Read(**/.netrc)
Read(**/.npmrc)
Read(**/.pypirc)
Read(**/.git-credentials)
Read(**/.htpasswd)
Read(**/.pgpass)
Read(**/.my.cnf)
Read(**/.authinfo)
Read(**/.authinfo.gpg)
Read(**/credentials)
Read(**/credentials.json)
Read(**/credentials.yaml)
Read(**/credentials.yml)
Read(**/credentials.toml)
Read(**/credentials.ini)
Read(**/credentials.csv)
Read(**/.credentials.json)
Read(**/.credentials.yaml)
Read(**/.credentials.yml)
Read(**/secret.json)
Read(**/secret.yaml)
Read(**/secret.yml)
Read(**/secrets.json)
Read(**/secrets.yaml)
Read(**/secrets.yml)
Read(**/secrets.toml)
Read(**/secrets.ini)
Read(**/secrets.txt)
ask (13)
Bash(rm -rf *)
Bash(rm -fr *)
Bash(git push *--force*)
Bash(git push -f*)
Bash(git push * -f)
Bash(git push * -f *)
Bash(git reset --hard*)
Bash(git clean -f*)
Bash(config push *--force*)
Bash(config push -f*)
Bash(config push * -f)
Bash(config push * -f *)
Bash(config reset --hard*)
allow (0)
—
Similar rigs
weimeng23/claude-code-dotfiles
Personal Claude Code dotfiles for global instructions, settings, hooks, agents, and reusable setup scripts.
Pragmatist 984 tok ·
nahyun2215-stack/claude-dotfiles
claude-dotfiles
Minimalist 155 tok ·
pysan3/dotfiles
☕ My Dot Files
Pragmatist 797 tok ·
mirosval/dotfiles
macOS, nix, neovim
Pragmatist 57 tok ·