~ / rigs / nferrer-dev / claude-dotfiles

nferrer-dev/claude-dotfiles

No description.

↗ GitHub ★ 0 no license updated 6mo ago personal setup Claude Code
share on X
ARCHETYPE
YOLO Cowboy
Permissions? Never heard of 'em. Ships at the speed of `--dangerously-skip-permissions`.
CONTEXT TAX · EVERY TURN
~3.6k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · details

Copy this rig

# review before running: this installs third-party code
$ npx degit nferrer-dev/claude-dotfiles/agents ./rig-claude-dotfiles/agents
$ npx degit nferrer-dev/claude-dotfiles/commands ./rig-claude-dotfiles/commands
$ npx degit nferrer-dev/claude-dotfiles/skills ./rig-claude-dotfiles/skills
$ npx degit nferrer-dev/claude-dotfiles/hooks ./rig-claude-dotfiles/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit nferrer-dev/claude-dotfiles/skills/alpha-vantage .claude/skills/alpha-vantage
$ npx degit nferrer-dev/claude-dotfiles/skills/article-extractor .claude/skills/article-extractor
$ npx degit nferrer-dev/claude-dotfiles/skills/deep-research .claude/skills/deep-research
$ npx degit nferrer-dev/claude-dotfiles/skills/edgartools .claude/skills/edgartools
$ npx degit nferrer-dev/claude-dotfiles/skills/exploratory-data-analysis .claude/skills/exploratory-data-analysis
$ npx degit nferrer-dev/claude-dotfiles/skills/fred-economic-data .claude/skills/fred-economic-data
$ npx degit nferrer-dev/claude-dotfiles/skills/hedgefundmonitor .claude/skills/hedgefundmonitor
$ npx degit nferrer-dev/claude-dotfiles/skills/hugging-face-datasets .claude/skills/hugging-face-datasets
$ npx degit nferrer-dev/claude-dotfiles/skills/iterative-retrieval .claude/skills/iterative-retrieval
$ npx degit nferrer-dev/claude-dotfiles/skills/langsmith-fetch .claude/skills/langsmith-fetch
$ npx degit nferrer-dev/claude-dotfiles/skills/matplotlib .claude/skills/matplotlib
$ npx degit nferrer-dev/claude-dotfiles/skills/mcp-builder .claude/skills/mcp-builder
$ npx degit nferrer-dev/claude-dotfiles/skills/networkx .claude/skills/networkx
$ npx degit nferrer-dev/claude-dotfiles/skills/notebooklm .claude/skills/notebooklm
$ npx degit nferrer-dev/claude-dotfiles/skills/pdf .claude/skills/pdf
$ npx degit nferrer-dev/claude-dotfiles/skills/plotly .claude/skills/plotly
$ npx degit nferrer-dev/claude-dotfiles/skills/polars .claude/skills/polars
$ npx degit nferrer-dev/claude-dotfiles/skills/pymc .claude/skills/pymc
$ npx degit nferrer-dev/claude-dotfiles/skills/scikit-learn .claude/skills/scikit-learn
$ npx degit nferrer-dev/claude-dotfiles/skills/seaborn .claude/skills/seaborn
$ npx degit nferrer-dev/claude-dotfiles/skills/shap .claude/skills/shap
$ npx degit nferrer-dev/claude-dotfiles/skills/skill-creator .claude/skills/skill-creator
$ npx degit nferrer-dev/claude-dotfiles/skills/statistical-analysis .claude/skills/statistical-analysis
$ npx degit nferrer-dev/claude-dotfiles/skills/statsmodels .claude/skills/statsmodels
$ npx degit nferrer-dev/claude-dotfiles/skills/sympy .claude/skills/sympy
$ npx degit nferrer-dev/claude-dotfiles/skills/tapestry .claude/skills/tapestry
$ npx degit nferrer-dev/claude-dotfiles/skills/timesfm-forecasting .claude/skills/timesfm-forecasting
$ npx degit nferrer-dev/claude-dotfiles/skills/verification-loop .claude/skills/verification-loop
$ npx degit nferrer-dev/claude-dotfiles/skills/xlsx .claude/skills/xlsx
$ npx degit nferrer-dev/claude-dotfiles/skills/youtube-transcript .claude/skills/youtube-transcript
$ curl -fsSL --create-dirs -o .claude/agents/general-code-reviewer.md https://raw.githubusercontent.com/nferrer-dev/claude-dotfiles/main/agents/general-code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/nferrer-dev/claude-dotfiles/main/agents/security-reviewer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf *)",
      "Bash(rm -fr *)",
      "Bash(rm -r *)",
      "Bash(sudo *)",
      "Bash(mkfs *)",
      "Bash(dd *)",
      "Bash(shred *)",
      "Bash(truncate *)",
      "Bash(wget *|bash*)",
      "Bash(wget *| bash*)",
      "Bash(curl *|bash*)",
      "Bash(curl *| bash*)",
      "Bash(curl *|sh*)",
      "Bash(curl *| sh*)",
      "Bash(git push --force*)",
      "Bash(git push *--force*)",
      "Bash(git push -f*)",
      "Bash(git push *-f *)",
      "Bash(git push * -f)",
      "Bash(git reset --hard*)",
      "Bash(git clean -f*)",
      "Bash(git checkout -- *)",
      "Bash(git restore *)",
      "Bash(> /*)",
      "Bash(> ~/*)",
      "Bash(FORMAT *)",
      "Bash(format *)",
      "Bash(diskpart*)",
      "Bash(taskkill /F*)",
      "Bash(taskkill /f*)",
      "Bash(shutdown *)",
      "Bash(Restart-Computer*)",
      "Bash(Stop-Computer*)",
      "Bash(chmod 777 *)",
      "Bash(chmod -R 777 *)",
      "Bash(* /dev/sda*)",
      "Bash(* /dev/nvme*)",
      "Edit(~/.bashrc)",
      "Edit(~/.zshrc)",
      "Edit(~/.profile)",
      "Edit(~/.bash_profile)",
      "Edit(~/.ssh/**)",
      "Read(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.aws/**)",
      "Read(~/.azure/**)",
      "Read(~/.config/gh/**)",
      "Read(~/.git-credentials)",
      "Read(~/.docker/config.json)",
      "Read(~/.kube/**)",
      "Read(~/.npmrc)",
      "Read(~/.npm/**)",
      "Read(~/.pypirc)",
      "Read(~/.gem/credentials)",
      "Read(~/.claude/.credentials.json)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Edit",
        "hooks": [
          {
            "type": "command",
            "command": "bash ~/.claude/hooks/config-protection.sh"
          }
        ]
      },
      {
        "matcher": "Write",
        "hooks": [
          {
            "type": "command",
            "command": "bash ~/.claude/hooks/config-protection.sh"
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo \"$CMD\" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo \"$CMD\" | grep -"
          },
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi"
          },
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(^|[;&|[:space:]])(kill[[:space:]]+-9|killall[[:space:]]|pkill[[:space:]])'; then echo 'BLOCKED: Process killing requires confirmation — run manually' >&2; exit 2; fi"
          },
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(^|[;&|[:space:]])(rmdir|unlink)[[:space:]]'; then echo 'BLOCKED: Directory/file removal requires confirmation' >&2; exit 2; fi"
          },
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE 'wsl[[:space:]]+--unregister'; then echo 'BLOCKED: WSL unregister is destructive — run manually' >&2; exit 2; fi"
          }
        ]
      }
    ]
  }
}

Skills (30)

Subagents (2)

general-code-reviewer
model: opus
Expert code review specialist. Reviews code for quality, security, and maintainability. Use after writing or modifying code for a broad quality check (distinct from the plan-alignment code-reviewer in
security-reviewer
model: opus
Security vulnerability detection and remediation specialist. Use PROACTIVELY after writing code that handles user input, authentication, API endpoints, or sensitive data. Flags secrets, SSRF, injectio

Hooks (16)

eventmatcherruns
UserPromptSubmit*bash ~/.claude/hooks/interface-guard.sh
UserPromptSubmit*bash -c 'set -o pipefail; jq -r .prompt | PYTHONIOENCODING=utf-8 claude-trace-compactor --stdin | jq -Rs "{\"updatedPrompt\": .}"'
PreToolUseEditbash ~/.claude/hooks/config-protection.sh
PreToolUseWritebash ~/.claude/hooks/config-protection.sh
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo "$CMD" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo "$CMD" | grep -
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(^|[;&|[:space:]])(kill[[:space:]]+-9|killall[[:space:]]|pkill[[:space:]])'; then echo 'BLOCKED: Process killing requires confirmation — run manually' >&2; exit 2; fi
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(^|[;&|[:space:]])(rmdir|unlink)[[:space:]]'; then echo 'BLOCKED: Directory/file removal requires confirmation' >&2; exit 2; fi
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE 'wsl[[:space:]]+--unregister'; then echo 'BLOCKED: WSL unregister is destructive — run manually' >&2; exit 2; fi
PostToolUseBashCMD=$(jq -r '.tool_input.command'); echo "$(date -Iseconds) $CMD" >> ~/.claude/bash-commands.log
PostToolUseBashbash -c 'set -o pipefail; jq -r ".tool_response.stdout // \"\"" | PYTHONIOENCODING=utf-8 claude-trace-compactor --stdin | jq -Rs "{\"hookSpecificOutput\": {\"hookEventName\": \"PostToolUse\", \"updatedResponse\": {\"stdout\": .}}}"'
PostToolUseReaduv run ~/.claude/hooks/prompt-injection-defender/post-tool-defender.py
PostToolUseWebFetchuv run ~/.claude/hooks/prompt-injection-defender/post-tool-defender.py
PostToolUseBashuv run ~/.claude/hooks/prompt-injection-defender/post-tool-defender.py
PostToolUseGrepuv run ~/.claude/hooks/prompt-injection-defender/post-tool-defender.py
PostToolUseTaskuv run ~/.claude/hooks/prompt-injection-defender/post-tool-defender.py

Slash commands (4)

/desktop/orchestrate/telegram/update

Plugins (11)

superpowers@claude-plugins-officialcontext7@claude-plugins-officialpyright-lsp@claude-plugins-officialhookify@claude-plugins-officialmodern-python@trailofbitsproperty-based-testing@trailofbitsstatic-analysis@trailofbitsdx@ykdojosanctum@claude-night-marketclaude-notifications-go@claude-notifications-goflow-next@gmickel-claude-marketplace

Permissions

deny (55)
Bash(rm -rf *)
Bash(rm -fr *)
Bash(rm -r *)
Bash(sudo *)
Bash(mkfs *)
Bash(dd *)
Bash(shred *)
Bash(truncate *)
Bash(wget *|bash*)
Bash(wget *| bash*)
Bash(curl *|bash*)
Bash(curl *| bash*)
Bash(curl *|sh*)
Bash(curl *| sh*)
Bash(git push --force*)
Bash(git push *--force*)
Bash(git push -f*)
Bash(git push *-f *)
Bash(git push * -f)
Bash(git reset --hard*)
Bash(git clean -f*)
Bash(git checkout -- *)
Bash(git restore *)
Bash(> /*)
Bash(> ~/*)
Bash(FORMAT *)
Bash(format *)
Bash(diskpart*)
Bash(taskkill /F*)
Bash(taskkill /f*)
Bash(shutdown *)
Bash(Restart-Computer*)
Bash(Stop-Computer*)
Bash(chmod 777 *)
Bash(chmod -R 777 *)
Bash(* /dev/sda*)
Bash(* /dev/nvme*)
Edit(~/.bashrc)
Edit(~/.zshrc)
Edit(~/.profile)
Edit(~/.bash_profile)
Edit(~/.ssh/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.config/gh/**)
Read(~/.git-credentials)
Read(~/.docker/config.json)
Read(~/.kube/**)
Read(~/.npmrc)
Read(~/.npm/**)
Read(~/.pypirc)
Read(~/.gem/credentials)
Read(~/.claude/.credentials.json)
ask (0)
—
allow (30)
Bash(*)
Read(*)
Edit(*)
Write(*)
Glob(*)
Grep(*)
WebSearch(*)
WebFetch(*)
Agent(*)
NotebookEdit(*)
Skill(*)
TeamCreate(*)
TeamDelete(*)
SendMessage(*)
TaskCreate(*)
TaskGet(*)
TaskList(*)
TaskOutput(*)
TaskStop(*)
TaskUpdate(*)
mcp__*
EnterPlanMode
ExitPlanMode
EnterWorktree
ExitWorktree
CronCreate(*)
CronDelete(*)
CronList
ListMcpResourcesTool(*)
ReadMcpResourceTool(*)

Similar rigs

copied ✓