~ / rigs / lil-lon / .claude

lil-lon/.claude

🎨 My Claude Code config. Build something interesting and fun.

↗ GitHub ★ 2 MIT updated 4mo ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~839 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit lil-lon/.claude/skills ./rig-.claude/skills

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit lil-lon/.claude/skills/agent-worktree .claude/skills/agent-worktree
$ npx degit lil-lon/.claude/skills/codex-review .claude/skills/codex-review
$ npx degit lil-lon/.claude/skills/complete-implementation .claude/skills/complete-implementation
$ npx degit lil-lon/.claude/skills/gh-cli .claude/skills/gh-cli
$ npx degit lil-lon/.claude/skills/ideation .claude/skills/ideation
$ npx degit lil-lon/.claude/skills/podcast-prep .claude/skills/podcast-prep

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(env)",
      "Bash(env *)",
      "Bash(printenv)",
      "Bash(printenv *)",
      "Bash(awk *)",
      "Bash(git -C *)",
      "Bash(python *)",
      "Bash(python3 *)",
      "Bash(wc *)",
      "Bash(wget *)",
      "Bash(cat *)",
      "Bash(curl *)",
      "Bash(echo *)",
      "Bash(find *)",
      "Bash(grep *)",
      "Bash(head *)",
      "Bash(printf *)",
      "Bash(rg *)",
      "Bash(sed *)",
      "Bash(tail *)",
      "Bash(touch *)",
      "Bash(tree)",
      "Bash(tree *)",
      "Bash(rm *)",
      "Bash(kill *)",
      "Bash(chmod *)",
      "Write(**/settings.json)",
      "Edit(**/settings.json)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/.envrc)",
      "Read(**/secrets/**)",
      "Read(**/*secret*)",
      "Read(**/*credentials*)",
      "Write(**/.env)",
      "Write(**/.env.*)",
      "Write(**/.envrc)",
      "Write(**/secrets/**)",
      "Write(**/*secret*)",
      "Write(**/*credentials*)",
      "Edit(**/.env)",
      "Edit(**/.env.*)",
      "Edit(**/.envrc)",
      "Edit(**/secrets/**)",
      "Edit(**/*secret*)",
      "Edit(**/*credentials*)",
      "Grep(**/.env)",
      "Grep(**/.env.*)",
      "Grep(**/.envrc)",
      "Grep(**/secrets/**)",
      "Grep(**/*secret*)",
      "Grep(**/*credentials*)",
      "Glob(**/.env)",
      "Glob(**/.env.*)",
      "Glob(**/.envrc)",
      "Glob(**/secrets/**)",
      "Glob(**/*secret*)",
      "Glob(**/*credentials*)"
    ],
    "ask": [
      "Bash(git push *)",
      "WebFetch"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_CONFIG_DIR/bin/validate_bash.py"
          }
        ]
      }
    ]
  },
  "sandbox": {
    "enabled": true
  }
}

Skills (6)

Hooks (1)

eventmatcherruns
PreToolUseBash$CLAUDE_CONFIG_DIR/bin/validate_bash.py

Permissions

deny (58)
Bash(env)
Bash(env *)
Bash(printenv)
Bash(printenv *)
Bash(awk *)
Bash(git -C *)
Bash(python *)
Bash(python3 *)
Bash(wc *)
Bash(wget *)
Bash(cat *)
Bash(curl *)
Bash(echo *)
Bash(find *)
Bash(grep *)
Bash(head *)
Bash(printf *)
Bash(rg *)
Bash(sed *)
Bash(tail *)
Bash(touch *)
Bash(tree)
Bash(tree *)
Bash(rm *)
Bash(kill *)
Bash(chmod *)
Write(**/settings.json)
Edit(**/settings.json)
Read(**/.env)
Read(**/.env.*)
Read(**/.envrc)
Read(**/secrets/**)
Read(**/*secret*)
Read(**/*credentials*)
Write(**/.env)
Write(**/.env.*)
Write(**/.envrc)
Write(**/secrets/**)
Write(**/*secret*)
Write(**/*credentials*)
Edit(**/.env)
Edit(**/.env.*)
Edit(**/.envrc)
Edit(**/secrets/**)
Edit(**/*secret*)
Edit(**/*credentials*)
Grep(**/.env)
Grep(**/.env.*)
Grep(**/.envrc)
Grep(**/secrets/**)
Grep(**/*secret*)
Grep(**/*credentials*)
Glob(**/.env)
Glob(**/.env.*)
Glob(**/.envrc)
Glob(**/secrets/**)
Glob(**/*secret*)
Glob(**/*credentials*)
ask (2)
Bash(git push *)
WebFetch
allow (36)
Write
Edit
WebSearch
Grep
Glob
Bash(ls)
Bash(ls *)
Bash(git add *)
Bash(git commit *)
Bash(git diff *)
Bash(git log *)
Bash(git branch *)
Bash(git checkout -b *)
Bash(git switch -c *)
Bash(git status)
Bash(uv run pytest *)
Bash(uv run ruff check *)
Bash(uv run ruff format *)
Bash(uv sync --frozen *)
Bash(gh api repos/*/*/issues/*/comments)
Bash(gh api repos/*/*/pulls/*/comments)
Bash(gh api repos/*/*/pulls/*/reviews)
Bash(gh issue list *)
Bash(gh issue view *)
Bash(gh pr checks *)
Bash(gh pr diff *)
Bash(gh pr list *)
Bash(gh pr view *)
Bash(gh repo view *)
Bash(gh run list *)
Bash(gh run view *)
Bash(gh search *)
Skill(ideation)
Skill(codex-review)
Skill(complete-implementation)
Skill(gh-cli)

Similar rigs

copied ✓