nullze/claude-code-hardened
Claude Code Hardened - Secure Configs for Claude Cowork, Teams, Code, and More
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
$ git clone --depth 1 https://github.com/nullze/claude-code-hardened MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(~/.ssh/*)",
"Read(~/.aws/*)",
"Read(~/.azure/*)",
"Read(~/.config/gcloud/*)",
"Read(~/.kube/*)",
"Read(~/.gnupg/*)",
"Read(~/.netrc)",
"Read(~/.npmrc)",
"Read(~/.pypirc)",
"Read(~/.gem/credentials)",
"Read(~/.docker/config.json)",
"Read(~/.config/gh/*)",
"Read(~/Library/Keychains/*)",
"Read(~/Library/Keychains/**)",
"Read(/Library/Keychains/*)",
"Read(/Library/Keychains/**)",
"Read(~/Library/Application Support/1Password/*)",
"Read(//etc/passwd)",
"Read(//etc/shadow)",
"Read(//etc/sudoers)",
"Read(//etc/sudoers.d/*)",
"Read(//private/etc/*)",
"Read(//var/log/*)",
"Read(**/.env)",
"Read(**/.env.*)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/*.p12)",
"Read(**/*.pfx)",
"Read(**/*.jks)",
"Read(**/*.keystore)",
"Read(**/id_rsa*)",
"Read(**/id_ed25519*)",
"Read(**/terraform.tfstate*)",
"Read(**/*.tfstate)",
"Read(**/terraform.tfvars)",
"Read(**/credentials.json)",
"Read(**/credentials*)",
"Read(**/secrets/**)",
"Read(**/service-account*.json)",
"Read(**/*.rdp)",
"Read(**/*.ppk)",
"Read(/~/.ssh/*)",
"Read(/~/.aws/*)",
"Read(/~/.azure/*)",
"Read(/~/.config/gcloud/*)",
"Read(/~/.kube/*)",
"Read(/~/.gnupg/*)",
"Read(/~/.netrc)",
"Read(/~/.npmrc)",
"Read(/~/.docker/config.json)",
"Read(/~/.config/gh/*)",
"Read(/~/.config/systemd/*)",
"Read(/~/.local/share/keyrings/*)",
"Read(//root/.ssh/*)",
"Read(//root/.aws/*)",
"Read(//root/.kube/*)",
"Read(//root/.gnupg/*)",
"Read(//proc/*/environ)",
"Read(//proc/*/cmdline)",
"Read(//etc/crontab)",
"Read(//etc/cron.d/*)",
"Read(//etc/systemd/system/*)",
"Read(//var/spool/cron/*)",
"Read(//c~/.ssh/*)",
"Read(//c~/.aws/*)",
"Read(//c~/.azure/*)",
"Read(//c~/.config/gcloud/*)",
"Read(//c~/.kube/*)",
"Read(//c~/.gnupg/*)",
"Read(//c~/.docker/config.json)",
"Read(//c~/.npmrc)",
"Read(//c~/.netrc)",
"Read(//c~/AppData/Roaming/Microsoft/Credentials/*)",
"Read(//c~/AppData/Local/Microsoft/Credentials/*)",
"Read(//c~/AppData/Roaming/Microsoft/Windows/Credentials/*)",
"Read(//c~/AppData/Roaming/GitHub CLI/*)",
"Read(//c~/AppData/Local/1Password/*)",
"Read(//c~/AppData/Roaming/1Password/*)",
"Read(//c~/AppData/Roaming/Bitwarden/*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "bash -c 'CMD=$(cat | jq -r \".tool_input.command // empty\"); if [ -z \"$CMD\" ]; then exit 0; fi; PATTERNS=\"(^|[;\\&\\|\\`\\$\\(])\\s*(curl|wget|nc|netcat|ncat|socat|ssh|scp|rsync|telnet|ftp|sftp|nmap)\\b\" ; PATTERNS2=\"(^|[;\\&\\|\\`\\$\\(])\\s*(sudo|su|do"
}
]
}
]
}
} Hooks (1)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | bash -c 'CMD=$(cat | jq -r ".tool_input.command // empty"); if [ -z "$CMD" ]; then exit 0; fi; PATTERNS="(^|[;\&\|\`\$\(])\s*(curl|wget|nc|netcat|ncat|socat|ssh|scp|rsync|telnet|ftp|sftp|nmap)\b" ; PATTERNS2="(^|[;\&\|\`\$\(])\s*(sudo|su|do |
Permissions
deny (120)
Read(~/.ssh/*)
Read(~/.aws/*)
Read(~/.azure/*)
Read(~/.config/gcloud/*)
Read(~/.kube/*)
Read(~/.gnupg/*)
Read(~/.netrc)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.gem/credentials)
Read(~/.docker/config.json)
Read(~/.config/gh/*)
Read(~/Library/Keychains/*)
Read(~/Library/Keychains/**)
Read(/Library/Keychains/*)
Read(/Library/Keychains/**)
Read(~/Library/Application Support/1Password/*)
Read(//etc/passwd)
Read(//etc/shadow)
Read(//etc/sudoers)
Read(//etc/sudoers.d/*)
Read(//private/etc/*)
Read(//var/log/*)
Read(**/.env)
Read(**/.env.*)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.jks)
Read(**/*.keystore)
Read(**/id_rsa*)
Read(**/id_ed25519*)
Read(**/terraform.tfstate*)
Read(**/*.tfstate)
Read(**/terraform.tfvars)
Read(**/credentials.json)
Read(**/credentials*)
Read(**/secrets/**)
Read(**/service-account*.json)
Read(**/*.rdp)
Read(**/*.ppk)
Read(/~/.ssh/*)
Read(/~/.aws/*)
Read(/~/.azure/*)
Read(/~/.config/gcloud/*)
Read(/~/.kube/*)
Read(/~/.gnupg/*)
Read(/~/.netrc)
Read(/~/.npmrc)
Read(/~/.docker/config.json)
Read(/~/.config/gh/*)
Read(/~/.config/systemd/*)
Read(/~/.local/share/keyrings/*)
Read(//root/.ssh/*)
Read(//root/.aws/*)
Read(//root/.kube/*)
Read(//root/.gnupg/*)
Read(//proc/*/environ)
Read(//proc/*/cmdline)
ask (0)
—
allow (0)
—
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·