~ / rigs / mjvacas / claude_code_template

mjvacas/claude_code_template

Starter scaffold for Claude Code projects: native config, a memory + decision-log system, a session start/handoff workflow, and security defaults.

↗ GitHub ★ 1 MIT updated 3mo ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~3.2k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit mjvacas/claude_code_template/.claude ./rig-claude_code_template  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit mjvacas/claude_code_template/.claude/skills/cc-task-bench .claude/skills/cc-task-bench
$ npx degit mjvacas/claude_code_template/.claude/skills/llm-eval .claude/skills/llm-eval
$ npx degit mjvacas/claude_code_template/.claude/skills/tune-parameters .claude/skills/tune-parameters
$ npx degit mjvacas/claude_code_template/.claude/skills/verify-refactor .claude/skills/verify-refactor

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(.env)",
      "Read(.env.*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(secrets/**)",
      "Read(**/secrets/**)",
      "Read(**/credentials*)",
      "Read(**/*.pem)",
      "Read(**/id_rsa)",
      "Read(**/id_ed25519)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/*.pfx)",
      "Read(**/*.keystore)",
      "Read(**/*_key)",
      "Read(**/*_secret)",
      "Read(**/.aws/credentials)",
      "Bash(nc:*)",
      "Bash(ncat:*)",
      "Bash(telnet:*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(rm:*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR/.claude/hooks/block-dangerous.sh\""
          }
        ]
      }
    ]
  }
}

Skills (4)

Hooks (3)

eventmatcherruns
PreToolUseBash"$CLAUDE_PROJECT_DIR/.claude/hooks/block-dangerous.sh"
SessionStartstartup|resume"$CLAUDE_PROJECT_DIR/.claude/hooks/session-context.sh"
PreCompactauto|manual"$CLAUDE_PROJECT_DIR/.claude/hooks/precompact-snapshot.sh"

Slash commands (4)

/adr/commit/handoff/session-start

Permissions

deny (20)
Read(.env)
Read(.env.*)
Read(**/.env)
Read(**/.env.*)
Read(secrets/**)
Read(**/secrets/**)
Read(**/credentials*)
Read(**/*.pem)
Read(**/id_rsa)
Read(**/id_ed25519)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.keystore)
Read(**/*_key)
Read(**/*_secret)
Read(**/.aws/credentials)
Bash(nc:*)
Bash(ncat:*)
Bash(telnet:*)
ask (2)
Bash(git push:*)
Bash(rm:*)
allow (6)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git show:*)
Bash(git branch:*)
Bash(ls:*)

Similar rigs

copied ✓