lil-lon/.claude
🎨 My Claude Code config. Build something interesting and fun.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit lil-lon/.claude/skills ./rig-.claude/skills MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit lil-lon/.claude/skills/agent-worktree .claude/skills/agent-worktree $ npx degit lil-lon/.claude/skills/codex-review .claude/skills/codex-review $ npx degit lil-lon/.claude/skills/complete-implementation .claude/skills/complete-implementation $ npx degit lil-lon/.claude/skills/gh-cli .claude/skills/gh-cli $ npx degit lil-lon/.claude/skills/ideation .claude/skills/ideation $ npx degit lil-lon/.claude/skills/podcast-prep .claude/skills/podcast-prep
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(env)",
"Bash(env *)",
"Bash(printenv)",
"Bash(printenv *)",
"Bash(awk *)",
"Bash(git -C *)",
"Bash(python *)",
"Bash(python3 *)",
"Bash(wc *)",
"Bash(wget *)",
"Bash(cat *)",
"Bash(curl *)",
"Bash(echo *)",
"Bash(find *)",
"Bash(grep *)",
"Bash(head *)",
"Bash(printf *)",
"Bash(rg *)",
"Bash(sed *)",
"Bash(tail *)",
"Bash(touch *)",
"Bash(tree)",
"Bash(tree *)",
"Bash(rm *)",
"Bash(kill *)",
"Bash(chmod *)",
"Write(**/settings.json)",
"Edit(**/settings.json)",
"Read(**/.env)",
"Read(**/.env.*)",
"Read(**/.envrc)",
"Read(**/secrets/**)",
"Read(**/*secret*)",
"Read(**/*credentials*)",
"Write(**/.env)",
"Write(**/.env.*)",
"Write(**/.envrc)",
"Write(**/secrets/**)",
"Write(**/*secret*)",
"Write(**/*credentials*)",
"Edit(**/.env)",
"Edit(**/.env.*)",
"Edit(**/.envrc)",
"Edit(**/secrets/**)",
"Edit(**/*secret*)",
"Edit(**/*credentials*)",
"Grep(**/.env)",
"Grep(**/.env.*)",
"Grep(**/.envrc)",
"Grep(**/secrets/**)",
"Grep(**/*secret*)",
"Grep(**/*credentials*)",
"Glob(**/.env)",
"Glob(**/.env.*)",
"Glob(**/.envrc)",
"Glob(**/secrets/**)",
"Glob(**/*secret*)",
"Glob(**/*credentials*)"
],
"ask": [
"Bash(git push *)",
"WebFetch"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "$CLAUDE_CONFIG_DIR/bin/validate_bash.py"
}
]
}
]
},
"sandbox": {
"enabled": true
}
} Skills (6)
Hooks (1)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | $CLAUDE_CONFIG_DIR/bin/validate_bash.py |
Permissions
deny (58)
Bash(env)
Bash(env *)
Bash(printenv)
Bash(printenv *)
Bash(awk *)
Bash(git -C *)
Bash(python *)
Bash(python3 *)
Bash(wc *)
Bash(wget *)
Bash(cat *)
Bash(curl *)
Bash(echo *)
Bash(find *)
Bash(grep *)
Bash(head *)
Bash(printf *)
Bash(rg *)
Bash(sed *)
Bash(tail *)
Bash(touch *)
Bash(tree)
Bash(tree *)
Bash(rm *)
Bash(kill *)
Bash(chmod *)
Write(**/settings.json)
Edit(**/settings.json)
Read(**/.env)
Read(**/.env.*)
Read(**/.envrc)
Read(**/secrets/**)
Read(**/*secret*)
Read(**/*credentials*)
Write(**/.env)
Write(**/.env.*)
Write(**/.envrc)
Write(**/secrets/**)
Write(**/*secret*)
Write(**/*credentials*)
Edit(**/.env)
Edit(**/.env.*)
Edit(**/.envrc)
Edit(**/secrets/**)
Edit(**/*secret*)
Edit(**/*credentials*)
Grep(**/.env)
Grep(**/.env.*)
Grep(**/.envrc)
Grep(**/secrets/**)
Grep(**/*secret*)
Grep(**/*credentials*)
Glob(**/.env)
Glob(**/.env.*)
Glob(**/.envrc)
Glob(**/secrets/**)
Glob(**/*secret*)
Glob(**/*credentials*)
ask (2)
Bash(git push *)
WebFetch
allow (36)
Write
Edit
WebSearch
Grep
Glob
Bash(ls)
Bash(ls *)
Bash(git add *)
Bash(git commit *)
Bash(git diff *)
Bash(git log *)
Bash(git branch *)
Bash(git checkout -b *)
Bash(git switch -c *)
Bash(git status)
Bash(uv run pytest *)
Bash(uv run ruff check *)
Bash(uv run ruff format *)
Bash(uv sync --frozen *)
Bash(gh api repos/*/*/issues/*/comments)
Bash(gh api repos/*/*/pulls/*/comments)
Bash(gh api repos/*/*/pulls/*/reviews)
Bash(gh issue list *)
Bash(gh issue view *)
Bash(gh pr checks *)
Bash(gh pr diff *)
Bash(gh pr list *)
Bash(gh pr view *)
Bash(gh repo view *)
Bash(gh run list *)
Bash(gh run view *)
Bash(gh search *)
Skill(ideation)
Skill(codex-review)
Skill(complete-implementation)
Skill(gh-cli)
Similar rigs
chaseai-yt/claudex-loop
Claude Code skill: four-phase plan hardening (recon, interrogate, Codex adversarial review, cross-model build & inspection) — two AI models harden your plan before a line of code exists, then swap jobs to build it. Whoever built it never gr
Minimalist 272 tok ·
agentlogbooks/logbooks
Structured state for agent skills
Minimalist 180 tok ·
jeremyckahn/dotfiles
This is what I use to get things done!
Pragmatist 2.6k tok ·
will-pagane/claude-superdev-harness
Minha config pessoal do Claude Code — CLAUDE.md global, statusline custom, stack de plugins/skills
Pragmatist 2.0k tok ·