~ / rigs / leo-leesco / .claude

leo-leesco/.claude

Claude Code configuration: settings, hooks, plugin registry

↗ GitHub ★ 0 no license updated 4mo ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit leo-leesco/.claude/hooks ./rig-.claude/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "ask": [
      "Bash(git push*)",
      "Bash(git reset --hard*)",
      "Bash(git branch -D*)",
      "Bash(git branch -d*)",
      "Bash(git clean*)",
      "Bash(git rebase*)",
      "Bash(git merge*)",
      "Bash(rm *)",
      "Bash(rmdir *)",
      "Bash(mv *)",
      "Bash(curl *)",
      "Bash(wget *)",
      "Bash(npm install*)",
      "Bash(npm uninstall*)",
      "Bash(npm publish*)",
      "Bash(yarn add*)",
      "Bash(yarn remove*)",
      "Bash(pnpm add*)",
      "Bash(pnpm remove*)",
      "Bash(bun add*)",
      "Bash(bun remove*)",
      "Bash(pip install*)",
      "Bash(pip uninstall*)",
      "Bash(cargo add*)",
      "Bash(cargo install*)",
      "Bash(cargo publish*)",
      "Bash(gh pr create*)",
      "Bash(gh pr merge*)",
      "Bash(gh pr close*)",
      "Bash(gh issue create*)",
      "Bash(gh issue close*)",
      "Bash(gh release*)",
      "Bash(gh repo create*)",
      "Bash(gh repo delete*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Edit|Write|NotebookEdit",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/branch-guard.sh"
          }
        ]
      },
      {
        "matcher": "mcp__ide__openDiff",
        "hooks": [
          {
            "type": "command",
            "command": "[ -n \"$NVIM_TMUX_PANE\" ] && tmux select-pane -t \"$NVIM_TMUX_PANE\"; exit 0"
          }
        ]
      }
    ]
  }
}

Hooks (3)

eventmatcherruns
PreToolUseEdit|Write|NotebookEdit~/.claude/hooks/branch-guard.sh
PreToolUsemcp__ide__openDiff[ -n "$NVIM_TMUX_PANE" ] && tmux select-pane -t "$NVIM_TMUX_PANE"; exit 0
Notification*~/.claude/hooks/notify.sh

Permissions

deny (0)
—
ask (34)
Bash(git push*)
Bash(git reset --hard*)
Bash(git branch -D*)
Bash(git branch -d*)
Bash(git clean*)
Bash(git rebase*)
Bash(git merge*)
Bash(rm *)
Bash(rmdir *)
Bash(mv *)
Bash(curl *)
Bash(wget *)
Bash(npm install*)
Bash(npm uninstall*)
Bash(npm publish*)
Bash(yarn add*)
Bash(yarn remove*)
Bash(pnpm add*)
Bash(pnpm remove*)
Bash(bun add*)
Bash(bun remove*)
Bash(pip install*)
Bash(pip uninstall*)
Bash(cargo add*)
Bash(cargo install*)
Bash(cargo publish*)
Bash(gh pr create*)
Bash(gh pr merge*)
Bash(gh pr close*)
Bash(gh issue create*)
Bash(gh issue close*)
Bash(gh release*)
Bash(gh repo create*)
Bash(gh repo delete*)
allow (109)
Read
Glob
Grep
Edit
Write
NotebookEdit
WebFetch
Bash(git status*)
Bash(git diff*)
Bash(git log*)
Bash(git show*)
Bash(git branch*)
Bash(git checkout*)
Bash(git switch*)
Bash(git add*)
Bash(git restore*)
Bash(git stash*)
Bash(git fetch*)
Bash(git pull --ff-only*)
Bash(git rev-parse*)
Bash(git config --get*)
Bash(git remote -v)
Bash(git remote get-url*)
Bash(git ls-files*)
Bash(git symbolic-ref*)
Bash(git show-ref*)
Bash(git commit -m*)
Bash(npm test*)
Bash(npm run test*)
Bash(npm run lint*)
Bash(npm run build*)
Bash(npm run typecheck*)
Bash(npm run check*)
Bash(yarn test*)
Bash(yarn lint*)
Bash(yarn build*)
Bash(yarn typecheck*)
Bash(pnpm test*)
Bash(pnpm lint*)
Bash(pnpm build*)
Bash(pnpm typecheck*)
Bash(bun test*)
Bash(bun run test*)
Bash(bun run lint*)
Bash(bun run build*)
Bash(pytest*)
Bash(python -m pytest*)
Bash(python3 -m pytest*)
Bash(mypy*)
Bash(ruff*)
Bash(pyright*)
Bash(cargo build*)
Bash(cargo test*)
Bash(cargo check*)
Bash(cargo clippy*)
Bash(cargo fmt*)
Bash(go build*)
Bash(go test*)
Bash(go vet*)
Bash(go fmt*)

Similar rigs

copied ✓