leo-leesco/.claude
Claude Code configuration: settings, hooks, plugin registry
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit leo-leesco/.claude/hooks ./rig-.claude/hooks MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"ask": [
"Bash(git push*)",
"Bash(git reset --hard*)",
"Bash(git branch -D*)",
"Bash(git branch -d*)",
"Bash(git clean*)",
"Bash(git rebase*)",
"Bash(git merge*)",
"Bash(rm *)",
"Bash(rmdir *)",
"Bash(mv *)",
"Bash(curl *)",
"Bash(wget *)",
"Bash(npm install*)",
"Bash(npm uninstall*)",
"Bash(npm publish*)",
"Bash(yarn add*)",
"Bash(yarn remove*)",
"Bash(pnpm add*)",
"Bash(pnpm remove*)",
"Bash(bun add*)",
"Bash(bun remove*)",
"Bash(pip install*)",
"Bash(pip uninstall*)",
"Bash(cargo add*)",
"Bash(cargo install*)",
"Bash(cargo publish*)",
"Bash(gh pr create*)",
"Bash(gh pr merge*)",
"Bash(gh pr close*)",
"Bash(gh issue create*)",
"Bash(gh issue close*)",
"Bash(gh release*)",
"Bash(gh repo create*)",
"Bash(gh repo delete*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write|NotebookEdit",
"hooks": [
{
"type": "command",
"command": "~/.claude/hooks/branch-guard.sh"
}
]
},
{
"matcher": "mcp__ide__openDiff",
"hooks": [
{
"type": "command",
"command": "[ -n \"$NVIM_TMUX_PANE\" ] && tmux select-pane -t \"$NVIM_TMUX_PANE\"; exit 0"
}
]
}
]
}
} Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Edit|Write|NotebookEdit | ~/.claude/hooks/branch-guard.sh |
| PreToolUse | mcp__ide__openDiff | [ -n "$NVIM_TMUX_PANE" ] && tmux select-pane -t "$NVIM_TMUX_PANE"; exit 0 |
| Notification | * | ~/.claude/hooks/notify.sh |
Permissions
deny (0)
—
ask (34)
Bash(git push*)
Bash(git reset --hard*)
Bash(git branch -D*)
Bash(git branch -d*)
Bash(git clean*)
Bash(git rebase*)
Bash(git merge*)
Bash(rm *)
Bash(rmdir *)
Bash(mv *)
Bash(curl *)
Bash(wget *)
Bash(npm install*)
Bash(npm uninstall*)
Bash(npm publish*)
Bash(yarn add*)
Bash(yarn remove*)
Bash(pnpm add*)
Bash(pnpm remove*)
Bash(bun add*)
Bash(bun remove*)
Bash(pip install*)
Bash(pip uninstall*)
Bash(cargo add*)
Bash(cargo install*)
Bash(cargo publish*)
Bash(gh pr create*)
Bash(gh pr merge*)
Bash(gh pr close*)
Bash(gh issue create*)
Bash(gh issue close*)
Bash(gh release*)
Bash(gh repo create*)
Bash(gh repo delete*)
allow (109)
Read
Glob
Grep
Edit
Write
NotebookEdit
WebFetch
Bash(git status*)
Bash(git diff*)
Bash(git log*)
Bash(git show*)
Bash(git branch*)
Bash(git checkout*)
Bash(git switch*)
Bash(git add*)
Bash(git restore*)
Bash(git stash*)
Bash(git fetch*)
Bash(git pull --ff-only*)
Bash(git rev-parse*)
Bash(git config --get*)
Bash(git remote -v)
Bash(git remote get-url*)
Bash(git ls-files*)
Bash(git symbolic-ref*)
Bash(git show-ref*)
Bash(git commit -m*)
Bash(npm test*)
Bash(npm run test*)
Bash(npm run lint*)
Bash(npm run build*)
Bash(npm run typecheck*)
Bash(npm run check*)
Bash(yarn test*)
Bash(yarn lint*)
Bash(yarn build*)
Bash(yarn typecheck*)
Bash(pnpm test*)
Bash(pnpm lint*)
Bash(pnpm build*)
Bash(pnpm typecheck*)
Bash(bun test*)
Bash(bun run test*)
Bash(bun run lint*)
Bash(bun run build*)
Bash(pytest*)
Bash(python -m pytest*)
Bash(python3 -m pytest*)
Bash(mypy*)
Bash(ruff*)
Bash(pyright*)
Bash(cargo build*)
Bash(cargo test*)
Bash(cargo check*)
Bash(cargo clippy*)
Bash(cargo fmt*)
Bash(go build*)
Bash(go test*)
Bash(go vet*)
Bash(go fmt*)
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·