mbd-s/dotfiles
My personal dotfiles and assorted config
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit mbd-s/dotfiles/claude/.claude ./rig-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(sudo:*)",
"Bash(rm -rf:*)",
"Bash(rm -fr:*)",
"Bash(git push * main*)",
"Bash(git push * master*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(aws * delete*)",
"Bash(aws * terminate*)",
"Bash(aws s3 rm:*)",
"Bash(aws s3 rb:*)",
"Bash(aws iam create*)",
"Bash(aws iam attach*)",
"Bash(aws iam put*)",
"Bash(aws iam update*)",
"Bash(aws iam delete*)",
"Bash(terraform destroy*)",
"Bash(terraform force-unlock:*)",
"Read(~/.ssh/id_*)",
"Read(~/.aws/**)",
"Read(~/.gnupg/**)",
"Read(**/.env)",
"Read(**/.env.*)"
],
"ask": [
"Bash(rm:*)"
]
}
} Hooks (4)
| event | matcher | runs |
|---|---|---|
| PostToolUse | Write|Edit | file=$(jq -r '.tool_input.file_path // empty'); if [[ "$file" == *.tf ]]; then dir=$(dirname "$file"); terraform fmt "$dir" && (cd "$dir" && terraform validate); fi |
| PostToolUse | Write|Edit | file=$(jq -r '.tool_input.file_path // empty'); if [[ "$file" == *.md ]]; then prettier --write "$file"; fi |
| PreCompact | auto | echo '{"continue": false, "stopReason": "Auto-compaction blocked. Run /compact manually if you want to proceed."}' |
| Notification | * | msg=$(jq -r '.message // empty'); if [ -n "$msg" ] && [ "$msg" != "Claude is waiting for your input" ] && [ -x "$HOME/.local/bin/claude-slack-send" ]; then "$HOME/.local/bin/claude-slack-send" "$msg" >/dev/null 2>&1; fi |
Permissions
deny (23)
Bash(sudo:*)
Bash(rm -rf:*)
Bash(rm -fr:*)
Bash(git push * main*)
Bash(git push * master*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(aws * delete*)
Bash(aws * terminate*)
Bash(aws s3 rm:*)
Bash(aws s3 rb:*)
Bash(aws iam create*)
Bash(aws iam attach*)
Bash(aws iam put*)
Bash(aws iam update*)
Bash(aws iam delete*)
Bash(terraform destroy*)
Bash(terraform force-unlock:*)
Read(~/.ssh/id_*)
Read(~/.aws/**)
Read(~/.gnupg/**)
Read(**/.env)
Read(**/.env.*)
ask (1)
Bash(rm:*)
allow (0)
—
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·