~ / rigs / nejcfurh / nejcfurh-claude

nejcfurh/nejcfurh-claude

Personal global Claude Code configuration — rules, skills, agents, hooks, and settings that apply to every project.

↗ GitHub ★ 1 MIT updated 1d ago project Claude Code Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~5.3k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit nejcfurh/nejcfurh-claude/agents ./rig-nejcfurh-claude/agents
$ npx degit nejcfurh/nejcfurh-claude/skills ./rig-nejcfurh-claude/skills
$ npx degit nejcfurh/nejcfurh-claude/hooks ./rig-nejcfurh-claude/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit nejcfurh/nejcfurh-claude/skills/address-pr-comment .claude/skills/address-pr-comment
$ npx degit nejcfurh/nejcfurh-claude/skills/animation-vocabulary .claude/skills/animation-vocabulary
$ npx degit nejcfurh/nejcfurh-claude/skills/apple-design .claude/skills/apple-design
$ npx degit nejcfurh/nejcfurh-claude/skills/commit .claude/skills/commit
$ npx degit nejcfurh/nejcfurh-claude/skills/context7-mcp .claude/skills/context7-mcp
$ npx degit nejcfurh/nejcfurh-claude/skills/debug .claude/skills/debug
$ npx degit nejcfurh/nejcfurh-claude/skills/emil-design-eng .claude/skills/emil-design-eng
$ npx degit nejcfurh/nejcfurh-claude/skills/find-animation-opportunities .claude/skills/find-animation-opportunities
$ npx degit nejcfurh/nejcfurh-claude/skills/find-docs .claude/skills/find-docs
$ npx degit nejcfurh/nejcfurh-claude/skills/grill .claude/skills/grill
$ npx degit nejcfurh/nejcfurh-claude/skills/handoff .claude/skills/handoff
$ npx degit nejcfurh/nejcfurh-claude/skills/improve-animations .claude/skills/improve-animations
$ npx degit nejcfurh/nejcfurh-claude/skills/loop-discipline .claude/skills/loop-discipline
$ npx degit nejcfurh/nejcfurh-claude/skills/pr .claude/skills/pr
$ npx degit nejcfurh/nejcfurh-claude/skills/prune .claude/skills/prune
$ npx degit nejcfurh/nejcfurh-claude/skills/rebase .claude/skills/rebase
$ npx degit nejcfurh/nejcfurh-claude/skills/retro .claude/skills/retro
$ npx degit nejcfurh/nejcfurh-claude/skills/review-animations .claude/skills/review-animations
$ npx degit nejcfurh/nejcfurh-claude/skills/review-code .claude/skills/review-code
$ npx degit nejcfurh/nejcfurh-claude/skills/review-pr .claude/skills/review-pr
$ npx degit nejcfurh/nejcfurh-claude/skills/ship .claude/skills/ship
$ npx degit nejcfurh/nejcfurh-claude/skills/spec .claude/skills/spec
$ npx degit nejcfurh/nejcfurh-claude/skills/verify-done .claude/skills/verify-done
$ npx degit nejcfurh/nejcfurh-claude/skills/verify-frontend-change .claude/skills/verify-frontend-change
$ curl -fsSL --create-dirs -o .claude/agents/ai-engineer.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/ai-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/backend-staff-engineer.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/backend-staff-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/cybersecurity-expert.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/cybersecurity-expert.md
$ curl -fsSL --create-dirs -o .claude/agents/database-master.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/database-master.md
$ curl -fsSL --create-dirs -o .claude/agents/frontend-staff-engineer.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/frontend-staff-engineer.md
$ curl -fsSL --create-dirs -o .claude/agents/product-manager.md https://raw.githubusercontent.com/nejcfurh/nejcfurh-claude/main/agents/product-manager.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.local)",
      "Read(**/.env.*.local)",
      "Read(**/.env.development)",
      "Read(**/.env.production)",
      "Read(**/.env.staging)",
      "Read(**/.env.test)",
      "Read(**/.env.dev)",
      "Read(**/.env.prod)",
      "Read(**/.env.preview)",
      "Read(**/.env.stage)",
      "Read(**/.envrc)",
      "Read(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.aws/**)",
      "Read(~/.config/gcloud/**)",
      "Read(~/.config/gh/hosts.yml)",
      "Read(~/.kube/**)",
      "Read(~/.docker/config.json)",
      "Read(~/.npmrc)",
      "Read(~/.netrc)",
      "Read(~/.pypirc)",
      "Read(~/.vault-token)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/*.pfx)",
      "Read(**/*.jks)",
      "Read(**/*-key.json)",
      "Read(**/service-account*.json)",
      "Read(**/credentials.json)",
      "Read(**/.vault-token)",
      "Read(**/.htpasswd)",
      "Read(~/.git-credentials)",
      "Read(~/.zsh_history)",
      "Read(~/.bash_history)",
      "Read(**/*.kubeconfig)",
      "Read(~/.azure/**)",
      "Edit(**/.env)",
      "Edit(**/.env.local)",
      "Edit(**/.env.*.local)",
      "Edit(**/.env.development)",
      "Edit(**/.env.production)",
      "Edit(**/.env.staging)",
      "Edit(**/.env.test)",
      "Edit(**/.env.dev)",
      "Edit(**/.env.prod)",
      "Edit(**/.env.preview)",
      "Edit(**/.env.stage)",
      "Edit(**/.envrc)",
      "Edit(~/.ssh/**)",
      "Edit(~/.gnupg/**)",
      "Edit(~/.aws/**)",
      "Edit(~/.npmrc)",
      "Edit(~/.netrc)",
      "Edit(~/.docker/config.json)",
      "Edit(~/.kube/**)",
      "Edit(~/.config/gcloud/**)",
      "Edit(~/.azure/**)",
      "Edit(**/*.pem)",
      "Edit(**/*.key)",
      "Edit(**/*-key.json)",
      "Bash(rm -rf*)",
      "Bash(rm -fr*)",
      "Bash(rm -Rf*)",
      "Bash(rm -fR*)",
      "Bash(rm -r -f*)",
      "Bash(rm -f -r*)",
      "Bash(rm -R -f*)",
      "Bash(rm -f -R*)",
      "Bash(sudo *)",
      "Bash(dd *)",
      "Bash(mkfs *)",
      "Bash(shred *)",
      "Bash(chmod * ~/.ssh/*)",
      "Bash(chmod * ~/.gnupg/*)",
      "Bash(git reset --hard *)",
      "Bash(gh repo delete *)",
      "Bash(git push origin main *)",
      "Bash(git push * main)"
    ],
    "ask": [
      "Bash(git clean*)",
      "Bash(npm publish*)",
      "Bash(rm -r*)",
      "Bash(rm -R*)",
      "Bash(rm --recursive*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/git-gate-dispatch.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/gh-gate-dispatch.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-bash-pipe-status-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-bash-build-dev-server-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-bash-shell-authored-source-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-bash-tmpdir-sandbox-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-bash-gh-sandbox-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-bash-zsh-modifier-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          }
        ]
      },
      {
        "matcher": "Write|Edit",
        "hooks": [
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-edit-branch-drift-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          },
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-write-comment-gate.sh\"; [ -x \"$HOOK\" ] && exec \"$HOOK\""
          }
        ]
      },
      {
        "matcher": "mcp__.*__notion-update-page",
        "hooks": [
          {
            "type": "command",
            "command": "HOOK=\"$HOME/.claude/hooks/pre-doc-full-rewrite-gate.sh\"; [ -x \"$HOOK\" ] && \"$HOOK\" || true"
          }
        ]
      }
    ]
  },
  "sandbox": {
    "enabled": true
  }
}

Skills (24)

Subagents (6)

ai-engineerUse for building AI/LLM features — agents, tool-calling flows, LLM endpoints, prompt pipelines, evals. Covers eval design (outcome + trajectory), harness guardrails, and the distributed-systems rules
backend-staff-engineerUse for backend architecture and API design (REST, GraphQL, WebSocket), NestJS/Node.js service design, event-driven systems and queues, caching strategy, resilience patterns, and observability reviews
cybersecurity-expertUse for security reviews, threat modeling, authentication and authorization design, vulnerability analysis (OWASP Top 10 — XSS, SQLi, SSRF, CSRF, IDOR), secrets handling, and dependency/supply-chain a
database-masterUse for database work across PostgreSQL (primary), MySQL, MongoDB, and Redis — schema and data modeling, query optimization, indexing strategy, safe zero-downtime migrations, connection pooling, and c
frontend-staff-engineerUse for frontend architecture, React/React Native/Next.js component and state design, TypeScript in UI code, web performance (Core Web Vitals), and accessibility reviews.
product-managerUse when scoping an MVP, prototype, or v1, deciding whether to build a feature at all, planning what ships first, or when a plan smells like scope creep. Argues the user-value and smallest-testable-sc

Hooks (22)

eventmatcherruns
PreToolUseBashHOOK="$HOME/.claude/hooks/git-gate-dispatch.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$HOME/.claude/hooks/gh-gate-dispatch.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUseBashHOOK="$HOME/.claude/hooks/pre-bash-pipe-status-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PreToolUseBashHOOK="$HOME/.claude/hooks/pre-bash-build-dev-server-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PreToolUseBashHOOK="$HOME/.claude/hooks/pre-bash-shell-authored-source-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PreToolUseBashHOOK="$HOME/.claude/hooks/pre-bash-tmpdir-sandbox-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PreToolUseBashHOOK="$HOME/.claude/hooks/pre-bash-gh-sandbox-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PreToolUseBashHOOK="$HOME/.claude/hooks/pre-bash-zsh-modifier-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PreToolUseWrite|EditHOOK="$HOME/.claude/hooks/pre-edit-branch-drift-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PreToolUseWrite|EditHOOK="$HOME/.claude/hooks/pre-write-comment-gate.sh"; [ -x "$HOOK" ] && exec "$HOOK"
PreToolUsemcp__.*__notion-update-pageHOOK="$HOME/.claude/hooks/pre-doc-full-rewrite-gate.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PostToolUseWrite|EditHOOK="$HOME/.claude/hooks/auto-format.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PostToolUseWrite|EditHOOK="$HOME/.claude/hooks/invalidate-verify-marker.sh"; [ -x "$HOOK" ] && "$HOOK" || true
PostToolUseBashHOOK="$HOME/.claude/hooks/post-pr-return-to-base.sh"; [ -x "$HOOK" ] && "$HOOK" || true
Notificationpermission_prompt|idle_prompt"$HOME/.claude/scripts/notify.sh" "Claude Code needs your attention"
Notificationpermission_prompt|idle_prompt"$HOME/.claude/scripts/chime.sh" 1.5
Stop*"$HOME/.claude/scripts/chime.sh" 2
Stop*HOOK="$HOME/.claude/hooks/retro-nudge.sh"; [ -x "$HOOK" ] && "$HOOK" || true
Stop*HOOK="$HOME/.claude/hooks/context-nudge.sh"; [ -x "$HOOK" ] && "$HOOK" || true
SessionStartcompactecho 'Reminder: follow the global workflow. Minimal fix first for bugs. One question per turn. Run /verify-done before pushing. Never add AI attribution to commits.'
SessionStartstartupHOOK="$HOME/.claude/hooks/symlink-check.sh"; [ -x "$HOOK" ] && "$HOOK" || true
SessionStartstartupHOOK="$HOME/.claude/hooks/auto-sync-config.sh"; [ -x "$HOOK" ] && "$HOOK" || true

Plugins (5)

frontend-design@claude-plugins-officialtypescript-lsp@claude-plugins-officialfigma@claude-plugins-officialrefactoring-ui-skills@refactoring-ui-pluginconfig-status@nejcfurh-claude

Permissions

deny (91)
Read(**/.env)
Read(**/.env.local)
Read(**/.env.*.local)
Read(**/.env.development)
Read(**/.env.production)
Read(**/.env.staging)
Read(**/.env.test)
Read(**/.env.dev)
Read(**/.env.prod)
Read(**/.env.preview)
Read(**/.env.stage)
Read(**/.envrc)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.config/gcloud/**)
Read(~/.config/gh/hosts.yml)
Read(~/.kube/**)
Read(~/.docker/config.json)
Read(~/.npmrc)
Read(~/.netrc)
Read(~/.pypirc)
Read(~/.vault-token)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.jks)
Read(**/*-key.json)
Read(**/service-account*.json)
Read(**/credentials.json)
Read(**/.vault-token)
Read(**/.htpasswd)
Read(~/.git-credentials)
Read(~/.zsh_history)
Read(~/.bash_history)
Read(**/*.kubeconfig)
Read(~/.azure/**)
Edit(**/.env)
Edit(**/.env.local)
Edit(**/.env.*.local)
Edit(**/.env.development)
Edit(**/.env.production)
Edit(**/.env.staging)
Edit(**/.env.test)
Edit(**/.env.dev)
Edit(**/.env.prod)
Edit(**/.env.preview)
Edit(**/.env.stage)
Edit(**/.envrc)
Edit(~/.ssh/**)
Edit(~/.gnupg/**)
Edit(~/.aws/**)
Edit(~/.npmrc)
Edit(~/.netrc)
Edit(~/.docker/config.json)
Edit(~/.kube/**)
Edit(~/.config/gcloud/**)
Edit(~/.azure/**)
Edit(**/*.pem)
ask (5)
Bash(git clean*)
Bash(npm publish*)
Bash(rm -r*)
Bash(rm -R*)
Bash(rm --recursive*)
allow (33)
Bash(awk *)
Bash(cat:*)
Bash(find:*)
Bash(gh api:*)
Bash(gh auth:*)
Bash(gh pr:*)
Bash(git *)
Bash(grep:*)
Bash(ls:*)
Bash(node *)
Bash(npm install:*)
Bash(npm run *)
Bash(npm uninstall:*)
Bash(npx eslint:*)
Bash(npx tsc:*)
Bash(pnpm run *)
Bash(yarn run *)
Bash(bun run *)
Bash(rm:*)
Bash(wc:*)
Read(//tmp/**)
Read(**/.env.example)
Read(**/.env.sample)
Edit(**/.env.example)
Edit(**/.env.sample)
WebFetch(domain:docs.anthropic.com)
WebFetch(domain:github.com)
WebFetch(domain:docs.github.com)
mcp__context7__resolve-library-id
mcp__context7__query-docs
mcp__plugin_figma_figma__get_design_context
mcp__plugin_figma_figma__get_metadata
mcp__plugin_figma_figma__get_screenshot

Similar rigs

copied ✓