nejcfurh/nejcfurh-claude
Personal global Claude Code configuration — rules, skills, agents, hooks, and settings that apply to every project.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ npx degit nejcfurh/nejcfurh-claude/agents ./rig-nejcfurh-claude/agents $ npx degit nejcfurh/nejcfurh-claude/skills ./rig-nejcfurh-claude/skills $ npx degit nejcfurh/nejcfurh-claude/hooks ./rig-nejcfurh-claude/hooks
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit nejcfurh/nejcfurh-claude/skills/address-pr-comment .claude/skills/address-pr-comment $ npx degit nejcfurh/nejcfurh-claude/skills/animation-vocabulary .claude/skills/animation-vocabulary $ npx degit nejcfurh/nejcfurh-claude/skills/apple-design .claude/skills/apple-design $ npx degit nejcfurh/nejcfurh-claude/skills/commit .claude/skills/commit $ npx degit nejcfurh/nejcfurh-claude/skills/context7-mcp .claude/skills/context7-mcp $ npx degit nejcfurh/nejcfurh-claude/skills/debug .claude/skills/debug $ npx degit nejcfurh/nejcfurh-claude/skills/emil-design-eng .claude/skills/emil-design-eng $ npx degit nejcfurh/nejcfurh-claude/skills/find-animation-opportunities .claude/skills/find-animation-opportunities $ npx degit nejcfurh/nejcfurh-claude/skills/find-docs .claude/skills/find-docs $ npx degit nejcfurh/nejcfurh-claude/skills/grill .claude/skills/grill $ npx degit nejcfurh/nejcfurh-claude/skills/handoff .claude/skills/handoff $ npx degit nejcfurh/nejcfurh-claude/skills/improve-animations .claude/skills/improve-animations $ npx degit nejcfurh/nejcfurh-claude/skills/loop-discipline .claude/skills/loop-discipline $ npx degit nejcfurh/nejcfurh-claude/skills/pr .claude/skills/pr $ npx degit nejcfurh/nejcfurh-claude/skills/prune .claude/skills/prune $ npx degit nejcfurh/nejcfurh-claude/skills/rebase .claude/skills/rebase $ npx degit nejcfurh/nejcfurh-claude/skills/retro .claude/skills/retro $ npx degit nejcfurh/nejcfurh-claude/skills/review-animations .claude/skills/review-animations $ npx degit nejcfurh/nejcfurh-claude/skills/review-code .claude/skills/review-code $ npx degit nejcfurh/nejcfurh-claude/skills/review-pr .claude/skills/review-pr $ npx degit nejcfurh/nejcfurh-claude/skills/ship .claude/skills/ship $ npx degit nejcfurh/nejcfurh-claude/skills/spec .claude/skills/spec $ npx degit nejcfurh/nejcfurh-claude/skills/verify-done .claude/skills/verify-done $ npx degit nejcfurh/nejcfurh-claude/skills/verify-frontend-change .claude/skills/verify-frontend-change
$ curl -fsSL --create-dirs -o .claude/agents/ai-engineer.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/ai-engineer.md $ curl -fsSL --create-dirs -o .claude/agents/backend-staff-engineer.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/backend-staff-engineer.md $ curl -fsSL --create-dirs -o .claude/agents/cybersecurity-expert.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/cybersecurity-expert.md $ curl -fsSL --create-dirs -o .claude/agents/database-master.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/database-master.md $ curl -fsSL --create-dirs -o .claude/agents/frontend-staff-engineer.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/frontend-staff-engineer.md $ curl -fsSL --create-dirs -o .claude/agents/product-manager.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/product-manager.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(**/.env)",
"Read(**/.env.local)",
"Read(**/.env.*.local)",
"Read(**/.env.development)",
"Read(**/.env.production)",
"Read(**/.env.staging)",
"Read(**/.env.test)",
"Read(**/.env.dev)",
"Read(**/.env.prod)",
"Read(**/.env.preview)",
"Read(**/.env.stage)",
"Read(**/.envrc)",
"Read(~/.ssh/**)",
"Read(~/.gnupg/**)",
"Read(~/.aws/**)",
"Read(~/.config/gcloud/**)",
"Read(~/.config/gh/hosts.yml)",
"Read(~/.kube/**)",
"Read(~/.docker/config.json)",
"Read(~/.npmrc)",
"Read(~/.netrc)",
"Read(~/.pypirc)",
"Read(~/.vault-token)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/*.p12)",
"Read(**/*.pfx)",
"Read(**/*.jks)",
"Read(**/*-key.json)",
"Read(**/service-account*.json)",
"Read(**/credentials.json)",
"Read(**/.vault-token)",
"Read(**/.htpasswd)",
"Read(~/.git-credentials)",
"Read(~/.zsh_history)",
"Read(~/.bash_history)",
"Read(**/*.kubeconfig)",
"Read(~/.azure/**)",
"Edit(**/.env)",
"Edit(**/.env.local)",
"Edit(**/.env.*.local)",
"Edit(**/.env.development)",
"Edit(**/.env.production)",
"Edit(**/.env.staging)",
"Edit(**/.env.test)",
"Edit(**/.env.dev)",
"Edit(**/.env.prod)",
"Edit(**/.env.preview)",
"Edit(**/.env.stage)",
"Edit(**/.envrc)",
"Edit(~/.ssh/**)",
"Edit(~/.gnupg/**)",
"Edit(~/.aws/**)",
"Edit(~/.npmrc)",
"Edit(~/.netrc)",
"Edit(~/.docker/config.json)",
"Edit(~/.kube/**)",
"Edit(~/.config/gcloud/**)",
"Edit(~/.azure/**)",
"Edit(**/*.pem)",
"Edit(**/*.key)",
"Edit(**/*-key.json)",
"Bash(rm -rf*)",
"Bash(rm -fr*)",
"Bash(rm -Rf*)",
"Bash(rm -fR*)",
"Bash(rm -r -f*)",
"Bash(rm -f -r*)",
"Bash(rm -R -f*)",
"Bash(rm -f -R*)",
"Bash(sudo *)",
"Bash(dd *)",
"Bash(mkfs *)",
"Bash(shred *)",
"Bash(chmod * ~/.ssh/*)",
"Bash(chmod * ~/.gnupg/*)",
"Bash(git reset --hard *)",
"Bash(gh repo delete *)",
"Bash(git push origin main *)",
"Bash(git push * main)"
],
"ask": [
"Bash(git clean*)",
"Bash(npm publish*)",
"Bash(rm -r*)",
"Bash(rm -R*)",
"Bash(rm --recursive*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/git-gate-dispatch.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/gh-gate-dispatch.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-bash-pipe-status-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-bash-build-dev-server-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-bash-shell-authored-source-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-bash-tmpdir-sandbox-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-bash-gh-sandbox-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-bash-zsh-modifier-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
}
]
},
{
"matcher": "Write|Edit",
"hooks": [
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-edit-branch-drift-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
},
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-write-comment-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
}
]
},
{
"matcher": "mcp__.*__notion-update-page",
"hooks": [
{
"type": "command",
"command": "HOOK=\"$HOME/.claude/hooks/pre-doc-full-rewrite-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
}
]
}
]
},
"sandbox": {
"enabled": true
}
} Skills (24)
address-pr-commentanimation-vocabularyapple-designcommitcontext7-mcpdebugemil-design-engfind-animation-opportunitiesfind-docsgrillhandoffimprove-animationsloop-disciplineprprunerebaseretroreview-animationsreview-codereview-prshipspecverify-doneverify-frontend-change
Subagents (6)
| ai-engineer | Use for building AI/LLM features — agents, tool-calling flows, LLM endpoints, prompt pipelines, evals. Covers eval design (outcome + trajectory), harness guardrails, and the distributed-systems rules |
| backend-staff-engineer | Use for backend architecture and API design (REST, GraphQL, WebSocket), NestJS/Node.js service design, event-driven systems and queues, caching strategy, resilience patterns, and observability reviews |
| cybersecurity-expert | Use for security reviews, threat modeling, authentication and authorization design, vulnerability analysis (OWASP Top 10 — XSS, SQLi, SSRF, CSRF, IDOR), secrets handling, and dependency/supply-chain a |
| database-master | Use for database work across PostgreSQL (primary), MySQL, MongoDB, and Redis — schema and data modeling, query optimization, indexing strategy, safe zero-downtime migrations, connection pooling, and c |
| frontend-staff-engineer | Use for frontend architecture, React/React Native/Next.js component and state design, TypeScript in UI code, web performance (Core Web Vitals), and accessibility reviews. |
| product-manager | Use when scoping an MVP, prototype, or v1, deciding whether to build a feature at all, planning what ships first, or when a plan smells like scope creep. Argues the user-value and smallest-testable-sc |
Hooks (22)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/git-gate-dispatch.sh"; [ -x "$HOOK" ] && exec "$HOOK" |
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/gh-gate-dispatch.sh"; [ -x "$HOOK" ] && exec "$HOOK" |
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/pre-bash-pipe-status-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/pre-bash-build-dev-server-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/pre-bash-shell-authored-source-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/pre-bash-tmpdir-sandbox-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/pre-bash-gh-sandbox-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PreToolUse | Bash | HOOK="$HOME/.claude/hooks/pre-bash-zsh-modifier-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PreToolUse | Write|Edit | HOOK="$HOME/.claude/hooks/pre-edit-branch-drift-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PreToolUse | Write|Edit | HOOK="$HOME/.claude/hooks/pre-write-comment-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK" |
| PreToolUse | mcp__.*__notion-update-page | HOOK="$HOME/.claude/hooks/pre-doc-full-rewrite-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PostToolUse | Write|Edit | HOOK="$HOME/.claude/hooks/auto-format.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PostToolUse | Write|Edit | HOOK="$HOME/.claude/hooks/invalidate-verify-marker.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| PostToolUse | Bash | HOOK="$HOME/.claude/hooks/post-pr-return-to-base.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| Notification | permission_prompt|idle_prompt | "$HOME/.claude/scripts/notify.sh" "Claude Code needs your attention" |
| Notification | permission_prompt|idle_prompt | "$HOME/.claude/scripts/chime.sh" 1.5 |
| Stop | * | "$HOME/.claude/scripts/chime.sh" 2 |
| Stop | * | HOOK="$HOME/.claude/hooks/retro-nudge.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| Stop | * | HOOK="$HOME/.claude/hooks/context-nudge.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| SessionStart | compact | echo 'Reminder: follow the global workflow. Minimal fix first for bugs. One question per turn. Run /verify-done before pushing. Never add AI attribution to commits.' |
| SessionStart | startup | HOOK="$HOME/.claude/hooks/symlink-check.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
| SessionStart | startup | HOOK="$HOME/.claude/hooks/auto-sync-config.sh"; [ -x "$HOOK" ] && "$HOOK" || true |
Plugins (5)
frontend-design@claude-plugins-officialtypescript-lsp@claude-plugins-officialfigma@claude-plugins-officialrefactoring-ui-skills@refactoring-ui-pluginconfig-status@nejcfurh-claude
Permissions
deny (91)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.*.local)
Read(**/.env.development)
Read(**/.env.production)
Read(**/.env.staging)
Read(**/.env.test)
Read(**/.env.dev)
Read(**/.env.prod)
Read(**/.env.preview)
Read(**/.env.stage)
Read(**/.envrc)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(~/.config/gh/hosts.yml)
Read(~/.kube/**)
Read(~/.docker/config.json)
Read(~/.npmrc)
Read(~/.netrc)
Read(~/.pypirc)
Read(~/.vault-token)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.jks)
Read(**/*-key.json)
Read(**/service-account*.json)
Read(**/credentials.json)
Read(**/.vault-token)
Read(**/.htpasswd)
Read(~/.git-credentials)
Read(~/.zsh_history)
Read(~/.bash_history)
Read(**/*.kubeconfig)
Read(~/.azure/**)
Edit(**/.env)
Edit(**/.env.local)
Edit(**/.env.*.local)
Edit(**/.env.development)
Edit(**/.env.production)
Edit(**/.env.staging)
Edit(**/.env.test)
Edit(**/.env.dev)
Edit(**/.env.prod)
Edit(**/.env.preview)
Edit(**/.env.stage)
Edit(**/.envrc)
Edit(~/.ssh/**)
Edit(~/.gnupg/**)
Edit(~/.aws/**)
Edit(~/.npmrc)
Edit(~/.netrc)
Edit(~/.docker/config.json)
Edit(~/.kube/**)
Edit(~/.config/gcloud/**)
Edit(~/.azure/**)
Edit(**/*.pem)
ask (5)
Bash(git clean*)
Bash(npm publish*)
Bash(rm -r*)
Bash(rm -R*)
Bash(rm --recursive*)
allow (33)
Bash(awk *)
Bash(cat:*)
Bash(find:*)
Bash(gh api:*)
Bash(gh auth:*)
Bash(gh pr:*)
Bash(git *)
Bash(grep:*)
Bash(ls:*)
Bash(node *)
Bash(npm install:*)
Bash(npm run *)
Bash(npm uninstall:*)
Bash(npx eslint:*)
Bash(npx tsc:*)
Bash(pnpm run *)
Bash(yarn run *)
Bash(bun run *)
Bash(rm:*)
Bash(wc:*)
Read(//tmp/**)
Read(**/.env.example)
Read(**/.env.sample)
Edit(**/.env.example)
Edit(**/.env.sample)
WebFetch(domain:docs.anthropic.com)
WebFetch(domain:github.com)
WebFetch(domain:docs.github.com)
mcp__context7__resolve-library-id
mcp__context7__query-docs
mcp__plugin_figma_figma__get_design_context
mcp__plugin_figma_figma__get_metadata
mcp__plugin_figma_figma__get_screenshot
Similar rigs
emilkowalski/skills
Skills for Designers and Engineers.
Skill Collector 1.1k tok ·
0oAstro/dots
chezmoi dotfiles: zsh, git, mise modules, agent harnesses; one command per machine
Skill Collector 3.6k tok ·
domengabrovsek/agent-config
Shared agent configuration for Claude Code, Codex, and Pi. One AGENTS.md instruction source, 35 portable skills, 16 expert personas, and host adapters that wire each runtime to the same rules, hooks, and permission boundaries.
Fort Knox 25.5k tok ·
ahonn/dotfiles
💎 My vim/neovim, claude code, nix, git, and tmux configuration files
YOLO Cowboy 3.3k tok ·