luiseiman/dotforge
Configuration governance for Claude Code. Bootstrap, audit, sync, and evolve .claude/ across projects.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit luiseiman/dotforge/.claude ./rig-dotforge # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit luiseiman/dotforge/skills/audit-project .claude/skills/audit-project $ npx degit luiseiman/dotforge/skills/bootstrap-project .claude/skills/bootstrap-project $ npx degit luiseiman/dotforge/skills/capture-practice .claude/skills/capture-practice $ npx degit luiseiman/dotforge/skills/diff-project .claude/skills/diff-project $ npx degit luiseiman/dotforge/skills/domain-extract .claude/skills/domain-extract $ npx degit luiseiman/dotforge/skills/export-config .claude/skills/export-config $ npx degit luiseiman/dotforge/skills/forge-behavior .claude/skills/forge-behavior $ npx degit luiseiman/dotforge/skills/init-project .claude/skills/init-project $ npx degit luiseiman/dotforge/skills/learn-project .claude/skills/learn-project $ npx degit luiseiman/dotforge/skills/mcp-add .claude/skills/mcp-add $ npx degit luiseiman/dotforge/skills/plugin-generator .claude/skills/plugin-generator $ npx degit luiseiman/dotforge/skills/reset-project .claude/skills/reset-project $ npx degit luiseiman/dotforge/skills/rule-effectiveness .claude/skills/rule-effectiveness $ npx degit luiseiman/dotforge/skills/scout-repos .claude/skills/scout-repos $ npx degit luiseiman/dotforge/skills/session-insights .claude/skills/session-insights $ npx degit luiseiman/dotforge/skills/sync-all-repos .claude/skills/sync-all-repos $ npx degit luiseiman/dotforge/skills/sync-template .claude/skills/sync-template $ npx degit luiseiman/dotforge/skills/update-practices .claude/skills/update-practices $ npx degit luiseiman/dotforge/skills/watch-upstream .claude/skills/watch-upstream $ npx degit <redacted> .claude/skills/hookify $ npx degit <redacted>-calendar .claude/skills/catalyst-calendar $ npx degit <redacted>-watch .claude/skills/earnings-watch $ npx degit luiseiman/dotforge/stacks/trading/skills/screen .claude/skills/screen $ npx degit luiseiman/dotforge/stacks/trading/skills/thesis-tracker .claude/skills/thesis-tracker
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf /)",
"Bash(rm -rf *)",
"Bash(git reset --hard*)",
"Bash(git push*--force*)",
"Bash(docker system prune*)",
"Bash(chmod -R 777*)",
"Read(**/.env)",
"Read(**/*.key)",
"Read(**/*.pem)",
"Read(**/*credentials*)",
"Bash(DROP TABLE*)",
"Bash(DROP DATABASE*)",
"Bash(git checkout -- *)",
"Bash(git checkout .)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": ".claude/hooks/block-destructive.sh"
},
{
"type": "command",
"command": ".claude/hooks/generated/no-destructive-git__pretooluse__bash__0.sh"
},
{
"type": "command",
"command": ".claude/hooks/generated/verify-before-done__pretooluse__bash__0.sh"
},
{
"type": "command",
"command": ".claude/hooks/generated/verify-before-done__pretooluse__bash__1.sh"
}
]
}
]
}
} Skills (24)
audit-projectbootstrap-projectcapture-practicediff-projectdomain-extractexport-configforge-behaviorinit-projectlearn-projectmcp-addplugin-generatorreset-projectrule-effectivenessscout-repossession-insightssync-all-repossync-templateupdate-practiceswatch-upstreamhookifycatalyst-calendarearnings-watchscreenthesis-tracker
Hooks (16)
| event | matcher | runs |
|---|---|---|
| SessionStart | * | .claude/hooks/check-updates.sh |
| SessionStart | * | .claude/hooks/session-restore.sh |
| SessionStart | * | .claude/hooks/session-startup.sh |
| PreToolUse | Bash | .claude/hooks/block-destructive.sh |
| PreToolUse | Bash | .claude/hooks/generated/no-destructive-git__pretooluse__bash__0.sh |
| PreToolUse | Bash | .claude/hooks/generated/verify-before-done__pretooluse__bash__0.sh |
| PreToolUse | Bash | .claude/hooks/generated/verify-before-done__pretooluse__bash__1.sh |
| PostToolUse | Write|Edit | .claude/hooks/lint-on-save.sh |
| PostToolUse | Write|Edit | .claude/hooks/detect-stack-drift.sh |
| PostToolUse | * | .claude/hooks/tool-latency.sh |
| PostCompact | * | .claude/hooks/post-compact.sh |
| Stop | * | .claude/hooks/session-report.sh |
| PermissionDenied | * | .claude/hooks/permission-denied.sh |
| Setup | init | .claude/hooks/pre-session-check.sh |
| Setup | maintenance | .claude/hooks/pre-session-check.sh |
| UserPromptSubmit | * | .claude/hooks/pre-compact-warning.sh |
Slash commands (4)
/audit/debug/health/review
Permissions
deny (14)
Bash(rm -rf /)
Bash(rm -rf *)
Bash(git reset --hard*)
Bash(git push*--force*)
Bash(docker system prune*)
Bash(chmod -R 777*)
Read(**/.env)
Read(**/*.key)
Read(**/*.pem)
Read(**/*credentials*)
Bash(DROP TABLE*)
Bash(DROP DATABASE*)
Bash(git checkout -- *)
Bash(git checkout .)
ask (0)
—
allow (11)
Bash(ls *)
Bash(git *)
Bash(ln -s *)
Bash(chmod *)
Bash(cat *)
Bash(wc *)
Read
Write
Edit
Glob
Grep
Similar rigs
kristiansnts/claude-dotfiles
—
Minimalist 1.8k tok ·
przadka/configure-cc
Claude Code configuration agent — bootstraps and audits your global CC setup
Pragmatist 1.7k tok ·
KJ-devs/setupClaudeCode
—
Fort Knox 2.2k tok ·
ilovefiniki/agent-skills
Production-grade AI Agent Skills & Governance for Claude Code, Antigravity, Gemini, and Cursor.
Pragmatist 717 tok ·