~ / rigs / nocktechnologies / nocklock

nocktechnologies/nocklock

AI agent security fence. Filesystem, network, and secret isolation for coding agents. Lock your AI agents in place.

↗ GitHub ★ 2 mit updated 6d ago project Claude CodeCodex
share on X
ARCHETYPE
Minimalist
Lean instructions, few tools, tiny context tax. Lets the model think.
CONTEXT TAX · EVERY TURN
~804 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit nocktechnologies/nocklock/.claude ./rig-nocklock  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$CLAUDE_PROJECT_DIR\"/.claude/hooks/branch-lock.sh"
          }
        ]
      }
    ]
  }
}

Hooks (1)

eventmatcherruns
PreToolUseBashbash "$CLAUDE_PROJECT_DIR"/.claude/hooks/branch-lock.sh

Similar rigs

copied ✓