lfrodrigues/packt-claude-code-course-auth
No description.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ claude mcp add --transport http sentry https://mcp.sentry.dev/mcp $ claude mcp add semble -- uvx --from 'semble[mcp]' semble $ claude mcp add --transport http neon https://mcp.neon.tech/mcp $ claude mcp add --transport http render https://mcp.render.com/mcp -H 'Authorization: YOUR_VALUE' $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude ./rig-packt-claude-code-course-auth # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add --transport http sentry https://mcp.sentry.dev/mcp $ claude mcp add semble -- uvx --from 'semble[mcp]' semble $ claude mcp add --transport http neon https://mcp.neon.tech/mcp $ claude mcp add --transport http render https://mcp.render.com/mcp -H 'Authorization: YOUR_VALUE'
$ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/db-migrate .claude/skills/db-migrate $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/deploy .claude/skills/deploy $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/fix .claude/skills/fix $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/plan .claude/skills/plan $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/pr .claude/skills/pr $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/ship .claude/skills/ship $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/smoke .claude/skills/smoke $ npx degit lfrodrigues/packt-claude-code-course-auth/.claude/skills/verify .claude/skills/verify
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(./.env)",
"Edit(./.env)",
"Read(./.env.*)",
"Edit(./.env.*)",
"Edit(./.husky/**)",
"Edit(./.github/workflows/**)",
"Edit(./.claude/**)",
"Edit(./.gitleaks.toml)",
"Edit(./apps/api/src/db/schema.ts)",
"Edit(./package-lock.json)",
"Bash(git push origin main:*)",
"Bash(git push origin master:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git commit --no-verify:*)",
"Bash(rm -rf:*)"
],
"ask": [
"Edit(./apps/api/src/auth.ts)",
"Edit(./packages/shared/**)",
"Bash(npm run db:migrate:*)",
"Bash(drizzle-kit migrate:*)",
"Bash(docker compose down:*)",
"Bash(git push:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR/.claude/hooks/protect-files.sh\""
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR/.claude/hooks/guard-bash.sh\""
}
]
}
]
}
} MCP servers (4)
| server | source | est. tokens |
|---|---|---|
| Sentry | remote · remote | 4.5k |
| semble[mcp] · "semble" | pypi | 2.5k |
| mcp.neon.tech · "neon" | remote · remote | 2.5k |
| mcp.render.com · "render" | remote · remote | 2.5k |
Skills (8)
Hooks (5)
| event | matcher | runs |
|---|---|---|
| SessionStart | * | "$CLAUDE_PROJECT_DIR/.claude/hooks/check-postgres.sh" |
| PreToolUse | Edit|Write | "$CLAUDE_PROJECT_DIR/.claude/hooks/protect-files.sh" |
| PreToolUse | Bash | "$CLAUDE_PROJECT_DIR/.claude/hooks/guard-bash.sh" |
| PostToolUse | Edit|Write | "$CLAUDE_PROJECT_DIR/.claude/hooks/format-file.sh" |
| Stop | * | "$CLAUDE_PROJECT_DIR/.claude/hooks/typecheck-changed.sh" |
Permissions
deny (16)
Read(./.env)
Edit(./.env)
Read(./.env.*)
Edit(./.env.*)
Edit(./.husky/**)
Edit(./.github/workflows/**)
Edit(./.claude/**)
Edit(./.gitleaks.toml)
Edit(./apps/api/src/db/schema.ts)
Edit(./package-lock.json)
Bash(git push origin main:*)
Bash(git push origin master:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git commit --no-verify:*)
Bash(rm -rf:*)
ask (6)
Edit(./apps/api/src/auth.ts)
Edit(./packages/shared/**)
Bash(npm run db:migrate:*)
Bash(drizzle-kit migrate:*)
Bash(docker compose down:*)
Bash(git push:*)
allow (18)
Bash(npm run verify)
Bash(npm run verify:full)
Bash(npm test:*)
Bash(npm run typecheck)
Bash(npm run typecheck:incremental)
Bash(npm run lint)
Bash(npm run lint:fix)
Bash(npm run e2e)
Bash(npm run smoke)
Bash(npx vitest *)
Bash(docker compose up -d)
mcp__neon__create_project
mcp__neon__get_database_tables
mcp__render__update_environment_variables
mcp__render__list_deploys
mcp__render__list_logs
mcp__render__get_deploy
mcp__render__get_service
Similar rigs
lcsmas/orchestra
Run parallel Claude Code and Codex agents in isolated git worktrees
Pragmatist 2.6k tok ·
tercel/code-forge
Complete development workflow — from TDD-driven implementation plans to execution, debugging, code review, git worktree management, branch lifecycle, and parallel agent dispatch.
Skill Collector 110 tok ·
chengxuniucode/ForgeTeam
AI coding framework — one person, full team delivery. Pure Shell+Markdown, zero dependencies, works with Claude Code / Cursor / Codex / OpenCode. 开源 AI 编码框架,一人全栈交付。
Skill Collector 748 tok ·
HumanDealer/vibeproof
Vibe-code anything. Ship like a senior. A drop-in rulebook + skills that turn any AI coding agent (Codex, Claude Code, Cursor) into a disciplined senior engineer — built for domain experts who build with AI.
Pragmatist 2.0k tok ·