lyczos/claude-template
Claude Code project template — hooks, commands, settings, CLAUDE.md
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit lyczos/claude-template/.claude ./rig-claude-template # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(**/.env)",
"Read(**/.env.*)",
"Read(**/.env.local)",
"Read(**/.env.production)",
"Read(**/.env.staging)",
"Read(**/credentials)",
"Read(**/credentials.*)",
"Read(**/secrets)",
"Read(**/secrets.*)",
"Read(**/secret.*)",
"Read(~/.ssh/*)",
"Read(~/.aws/*)",
"Read(~/.npmrc)",
"Read(~/.pypirc)",
"Read(~/.netrc)",
"Edit(**/.env)",
"Edit(**/.env.*)",
"Edit(~/.bashrc)",
"Edit(~/.zshrc)",
"Edit(~/.bash_profile)",
"Edit(~/.gitconfig)",
"Edit(~/.ssh/*)",
"Write(**/.env)",
"Write(**/.env.*)",
"Write(**/credentials)",
"Write(**/credentials.*)",
"Bash(rm -rf*)",
"Bash(git push --force*)",
"Bash(git push -f*)",
"Bash(chmod 777*)",
"Bash(curl * | bash*)",
"Bash(wget * | bash*)",
"Bash(curl *|bash*)",
"Bash(*> ~/.bashrc*)",
"Bash(*> ~/.zshrc*)",
"Bash(*> ~/.bash_profile*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Read|Edit|Write",
"hooks": [
{
"type": "command",
"command": "bash .claude/hooks/block-secrets-by-content.sh"
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "bash .claude/hooks/block-dangerous-commands.sh"
}
]
}
]
}
} Hooks (3)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Read|Edit|Write | bash .claude/hooks/block-secrets-by-content.sh |
| PreToolUse | Bash | bash .claude/hooks/block-dangerous-commands.sh |
| PostToolUse | Write|Edit | bash .claude/hooks/warn-on-secrets-written.sh |
Slash commands (6)
/git-summary/new-module/perf-review/pre-commit-review/security-audit/write-tests
Permissions
deny (36)
Read(**/.env)
Read(**/.env.*)
Read(**/.env.local)
Read(**/.env.production)
Read(**/.env.staging)
Read(**/credentials)
Read(**/credentials.*)
Read(**/secrets)
Read(**/secrets.*)
Read(**/secret.*)
Read(~/.ssh/*)
Read(~/.aws/*)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.netrc)
Edit(**/.env)
Edit(**/.env.*)
Edit(~/.bashrc)
Edit(~/.zshrc)
Edit(~/.bash_profile)
Edit(~/.gitconfig)
Edit(~/.ssh/*)
Write(**/.env)
Write(**/.env.*)
Write(**/credentials)
Write(**/credentials.*)
Bash(rm -rf*)
Bash(git push --force*)
Bash(git push -f*)
Bash(chmod 777*)
Bash(curl * | bash*)
Bash(wget * | bash*)
Bash(curl *|bash*)
Bash(*> ~/.bashrc*)
Bash(*> ~/.zshrc*)
Bash(*> ~/.bash_profile*)
ask (0)
—
allow (25)
Bash(git status)
Bash(git diff*)
Bash(git log*)
Bash(git branch*)
Bash(git worktree*)
Bash(git add*)
Bash(git commit*)
Bash(git checkout*)
Bash(git stash*)
Bash(npm install*)
Bash(npm run*)
Bash(npm test*)
Bash(npm audit)
Bash(pnpm install*)
Bash(pnpm run*)
Bash(pnpm test*)
Bash(pnpm audit)
Bash(npx tsc*)
Bash(npx eslint*)
Bash(npx prettier*)
Bash(cat package.json)
Bash(cat tsconfig*)
Read
Glob
Grep
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·