montchr/dotfield
All I see is little dots – some are smeared, and some are spots.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit montchr/dotfield/src/users/cdom/config/claude/.claude ./rig-dotfield # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit montchr/dotfield/src/users/cdom/config/claude/.claude/skills/terminal-title .claude/skills/terminal-title Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf /:*)",
"Bash(rm -rf /)",
"Bash(sudo:*)",
"Bash(dd :*)",
"Bash(mkfs:*)",
"Bash(fdisk:*)",
"Bash(parted:*)",
"Bash(> /dev/sda:*)",
"Bash(> /dev/nvme:*)",
"Bash(> /dev/sd:*)",
"Bash(cat /dev/urandom > :*)",
"Bash(passwd:*)",
"Bash(nc -l:*)",
"Bash(netcat -l:*)",
"Bash(socat:*)",
"Bash(nmap:*)",
"Bash(masscan:*)",
"Bash(git push --force origin master:*)",
"Bash(git push --force origin main:*)",
"Bash(git push -f origin master:*)",
"Bash(git push -f origin main:*)",
"Bash(git reset --hard origin/master:*)",
"Bash(git reset --hard origin/main:*)",
"Bash(cat ~/.aws/:*)",
"Bash(cat ~/.ssh/id_:*)",
"Bash(cat /root/.ssh/:*)",
"Bash(env | base64:*)",
"Bash(printenv | base64:*)",
"Bash(set | base64:*)",
"Bash(bash -i >& /dev/tcp/:*)",
"Bash(sh -i >& /dev/tcp/:*)",
"Bash(docker run --privileged :*)",
"Bash(docker run --pid=host :*)",
"Bash(docker run --net=host :*)",
"Bash(docker run -v /:/host :*)",
"Bash(docker run -v /etc:/etc :*)",
"Bash(docker run -v /var/run/docker.sock:/var/run/docker.sock :*)",
"Bash(history | grep -i password:*)",
"Bash(history | grep -i token:*)",
"Bash(history | grep -i secret:*)",
"Bash(history | grep -i key:*)",
"Bash(grep -r password /etc/:*)",
"Bash(grep -r token /etc/:*)",
"Bash(find / -name id_rsa:*)",
"Bash(find / -name *.key:*)",
"Bash(find / -name *.pem:*)",
"Bash(shutdown:*)",
"Bash(reboot:*)",
"Bash(halt:*)",
"Bash(poweroff:*)",
"Bash(init 0:*)",
"Bash(init 6:*)",
"Bash(rm /var/log/:*)",
"Bash(rm -rf /var/log/:*)",
"Bash(> /var/log/:*)",
"Bash(echo > /var/log/:*)",
"Bash(truncate -s 0 /var/log/:*)",
"Bash(insmod :*)",
"Bash(rmmod :*)",
"Bash(modprobe :*)",
"Bash(sysctl -w :*)",
"Bash(chmod -R 777 /:*)",
"Bash(chmod 777 /etc/:*)",
"Bash(chmod 777 /bin/:*)",
"Bash(chmod 777 /usr/:*)",
"Bash(chown -R * /:*)",
"Bash(find / -type f -delete:*)",
"Bash(find / -type d -delete:*)",
"Bash(rm -rf ~",
"Bash(rm -rf /var/:*)",
"Bash(rm -rf /opt/:*)",
"Bash(gdb -p :*)",
"Bash(ptrace :*)",
"Bash(LD_PRELOAD=:*)",
"Bash(export PATH=:*)",
"Bash(export LD_LIBRARY_PATH=:*)",
"Bash(export PYTHONPATH=:*)",
"Bash(nsenter :*)",
"Bash(docker run --cap-add=ALL :*)",
"Bash(docker run --security-opt :*)"
],
"ask": [
"Bash(gh pr create:*)",
"Bash(git commit:*)"
]
}
} Skills (1)
Slash commands (2)
/immersion/reflect
Plugins (5)
document-skills@anthropic-agent-skillscompounding-engineering@every-marketplacerust-analyzer-lsp@claude-plugins-officialtypescript-lsp@claude-plugins-officialphp-lsp@claude-plugins-official
Permissions
deny (86)
Bash(rm -rf /:*)
Bash(rm -rf /)
Bash(sudo:*)
Bash(dd :*)
Bash(mkfs:*)
Bash(fdisk:*)
Bash(parted:*)
Bash(> /dev/sda:*)
Bash(> /dev/nvme:*)
Bash(> /dev/sd:*)
Bash(cat /dev/urandom > :*)
Bash(passwd:*)
Bash(nc -l:*)
Bash(netcat -l:*)
Bash(socat:*)
Bash(nmap:*)
Bash(masscan:*)
Bash(git push --force origin master:*)
Bash(git push --force origin main:*)
Bash(git push -f origin master:*)
Bash(git push -f origin main:*)
Bash(git reset --hard origin/master:*)
Bash(git reset --hard origin/main:*)
Bash(cat ~/.aws/:*)
Bash(cat ~/.ssh/id_:*)
Bash(cat /root/.ssh/:*)
Bash(env | base64:*)
Bash(printenv | base64:*)
Bash(set | base64:*)
Bash(bash -i >& /dev/tcp/:*)
Bash(sh -i >& /dev/tcp/:*)
Bash(docker run --privileged :*)
Bash(docker run --pid=host :*)
Bash(docker run --net=host :*)
Bash(docker run -v /:/host :*)
Bash(docker run -v /etc:/etc :*)
Bash(docker run -v /var/run/docker.sock:/var/run/docker.sock :*)
Bash(history | grep -i password:*)
Bash(history | grep -i token:*)
Bash(history | grep -i secret:*)
Bash(history | grep -i key:*)
Bash(grep -r password /etc/:*)
Bash(grep -r token /etc/:*)
Bash(find / -name id_rsa:*)
Bash(find / -name *.key:*)
Bash(find / -name *.pem:*)
Bash(shutdown:*)
Bash(reboot:*)
Bash(halt:*)
Bash(poweroff:*)
Bash(init 0:*)
Bash(init 6:*)
Bash(rm /var/log/:*)
Bash(rm -rf /var/log/:*)
Bash(> /var/log/:*)
Bash(echo > /var/log/:*)
Bash(truncate -s 0 /var/log/:*)
Bash(insmod :*)
Bash(rmmod :*)
Bash(modprobe :*)
ask (2)
Bash(gh pr create:*)
Bash(git commit:*)
allow (45)
Bash(git add:*)
Bash(ls:*)
Bash(cat :*)
Bash(less :*)
Bash(more :*)
Bash(head :*)
Bash(tail :*)
Bash(grep :*)
Bash(egrep :*)
Bash(fgrep :*)
Bash(cut :*)
Bash(sort :*)
Bash(uniq :*)
Bash(wc :*)
Bash(diff :*)
Bash(tree :*)
Bash(pwd :*)
Bash(cd :*)
Bash(pushd :*)
Bash(popd :*)
Bash(basename :*)
Bash(dirname :*)
Bash(realpath :*)
Bash(readlink :*)
Bash(npm ci:*)
Bash(npm test:*)
Bash(npm start:*)
Bash(npm build:*)
Bash(npm run build:*)
Bash(npm run test:*)
Bash(npm run dev:*)
Bash(npm run lint:*)
Bash(npm list:*)
Bash(pnpm run build:*)
Bash(pnpm run test:*)
Bash(pnpm run dev:*)
Bash(pnpm run lint:*)
Bash(cargo :*)
WebFetch(domain:github.com)
WebFetch(domain:raw.githubusercontent.com)
WebFetch(domain:api.github.com)
WebFetch(domain:cgit.git.savannah.gnu.org)
WebFetch(domain:gitlab.com)
WebFetch(domain:sourceforge.net)
WebSearch
Similar rigs
henno/.claude
Personal Claude Code configuration: skills, commands, hooks, and settings
YOLO Cowboy 1.8k tok ·
ShunmeiCho/dotclaude
Collection of Claude Code skills for easy setup across different environments
Skill Collector 7.6k tok ·
ShunmeiCho/claude-config
Claude Code one-click deployment configuration
Skill Collector 9.3k tok ·
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·