~ / rigs / lyczos / claude-template

lyczos/claude-template

Claude Code project template — hooks, commands, settings, CLAUDE.md

↗ GitHub ★ 0 no license updated 8mo ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.7k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit lyczos/claude-template/.claude ./rig-claude-template  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/.env.local)",
      "Read(**/.env.production)",
      "Read(**/.env.staging)",
      "Read(**/credentials)",
      "Read(**/credentials.*)",
      "Read(**/secrets)",
      "Read(**/secrets.*)",
      "Read(**/secret.*)",
      "Read(~/.ssh/*)",
      "Read(~/.aws/*)",
      "Read(~/.npmrc)",
      "Read(~/.pypirc)",
      "Read(~/.netrc)",
      "Edit(**/.env)",
      "Edit(**/.env.*)",
      "Edit(~/.bashrc)",
      "Edit(~/.zshrc)",
      "Edit(~/.bash_profile)",
      "Edit(~/.gitconfig)",
      "Edit(~/.ssh/*)",
      "Write(**/.env)",
      "Write(**/.env.*)",
      "Write(**/credentials)",
      "Write(**/credentials.*)",
      "Bash(rm -rf*)",
      "Bash(git push --force*)",
      "Bash(git push -f*)",
      "Bash(chmod 777*)",
      "Bash(curl * | bash*)",
      "Bash(wget * | bash*)",
      "Bash(curl *|bash*)",
      "Bash(*> ~/.bashrc*)",
      "Bash(*> ~/.zshrc*)",
      "Bash(*> ~/.bash_profile*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Read|Edit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "bash .claude/hooks/block-secrets-by-content.sh"
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash .claude/hooks/block-dangerous-commands.sh"
          }
        ]
      }
    ]
  }
}

Hooks (3)

eventmatcherruns
PreToolUseRead|Edit|Writebash .claude/hooks/block-secrets-by-content.sh
PreToolUseBashbash .claude/hooks/block-dangerous-commands.sh
PostToolUseWrite|Editbash .claude/hooks/warn-on-secrets-written.sh

Slash commands (6)

/git-summary/new-module/perf-review/pre-commit-review/security-audit/write-tests

Permissions

deny (36)
Read(**/.env)
Read(**/.env.*)
Read(**/.env.local)
Read(**/.env.production)
Read(**/.env.staging)
Read(**/credentials)
Read(**/credentials.*)
Read(**/secrets)
Read(**/secrets.*)
Read(**/secret.*)
Read(~/.ssh/*)
Read(~/.aws/*)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.netrc)
Edit(**/.env)
Edit(**/.env.*)
Edit(~/.bashrc)
Edit(~/.zshrc)
Edit(~/.bash_profile)
Edit(~/.gitconfig)
Edit(~/.ssh/*)
Write(**/.env)
Write(**/.env.*)
Write(**/credentials)
Write(**/credentials.*)
Bash(rm -rf*)
Bash(git push --force*)
Bash(git push -f*)
Bash(chmod 777*)
Bash(curl * | bash*)
Bash(wget * | bash*)
Bash(curl *|bash*)
Bash(*> ~/.bashrc*)
Bash(*> ~/.zshrc*)
Bash(*> ~/.bash_profile*)
ask (0)
—
allow (25)
Bash(git status)
Bash(git diff*)
Bash(git log*)
Bash(git branch*)
Bash(git worktree*)
Bash(git add*)
Bash(git commit*)
Bash(git checkout*)
Bash(git stash*)
Bash(npm install*)
Bash(npm run*)
Bash(npm test*)
Bash(npm audit)
Bash(pnpm install*)
Bash(pnpm run*)
Bash(pnpm test*)
Bash(pnpm audit)
Bash(npx tsc*)
Bash(npx eslint*)
Bash(npx prettier*)
Bash(cat package.json)
Bash(cat tsconfig*)
Read
Glob
Grep

Similar rigs

copied ✓