~ / rigs / nullze / claude-code-hardened

nullze/claude-code-hardened

Claude Code Hardened - Secure Configs for Claude Cowork, Teams, Code, and More

↗ GitHub ★ 2 MIT updated 6mo ago project Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~868 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

$ git clone --depth 1 https://github.com/nullze/claude-code-hardened

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(~/.ssh/*)",
      "Read(~/.aws/*)",
      "Read(~/.azure/*)",
      "Read(~/.config/gcloud/*)",
      "Read(~/.kube/*)",
      "Read(~/.gnupg/*)",
      "Read(~/.netrc)",
      "Read(~/.npmrc)",
      "Read(~/.pypirc)",
      "Read(~/.gem/credentials)",
      "Read(~/.docker/config.json)",
      "Read(~/.config/gh/*)",
      "Read(~/Library/Keychains/*)",
      "Read(~/Library/Keychains/**)",
      "Read(/Library/Keychains/*)",
      "Read(/Library/Keychains/**)",
      "Read(~/Library/Application Support/1Password/*)",
      "Read(//etc/passwd)",
      "Read(//etc/shadow)",
      "Read(//etc/sudoers)",
      "Read(//etc/sudoers.d/*)",
      "Read(//private/etc/*)",
      "Read(//var/log/*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/*.pfx)",
      "Read(**/*.jks)",
      "Read(**/*.keystore)",
      "Read(**/id_rsa*)",
      "Read(**/id_ed25519*)",
      "Read(**/terraform.tfstate*)",
      "Read(**/*.tfstate)",
      "Read(**/terraform.tfvars)",
      "Read(**/credentials.json)",
      "Read(**/credentials*)",
      "Read(**/secrets/**)",
      "Read(**/service-account*.json)",
      "Read(**/*.rdp)",
      "Read(**/*.ppk)",
      "Read(/~/.ssh/*)",
      "Read(/~/.aws/*)",
      "Read(/~/.azure/*)",
      "Read(/~/.config/gcloud/*)",
      "Read(/~/.kube/*)",
      "Read(/~/.gnupg/*)",
      "Read(/~/.netrc)",
      "Read(/~/.npmrc)",
      "Read(/~/.docker/config.json)",
      "Read(/~/.config/gh/*)",
      "Read(/~/.config/systemd/*)",
      "Read(/~/.local/share/keyrings/*)",
      "Read(//root/.ssh/*)",
      "Read(//root/.aws/*)",
      "Read(//root/.kube/*)",
      "Read(//root/.gnupg/*)",
      "Read(//proc/*/environ)",
      "Read(//proc/*/cmdline)",
      "Read(//etc/crontab)",
      "Read(//etc/cron.d/*)",
      "Read(//etc/systemd/system/*)",
      "Read(//var/spool/cron/*)",
      "Read(//c~/.ssh/*)",
      "Read(//c~/.aws/*)",
      "Read(//c~/.azure/*)",
      "Read(//c~/.config/gcloud/*)",
      "Read(//c~/.kube/*)",
      "Read(//c~/.gnupg/*)",
      "Read(//c~/.docker/config.json)",
      "Read(//c~/.npmrc)",
      "Read(//c~/.netrc)",
      "Read(//c~/AppData/Roaming/Microsoft/Credentials/*)",
      "Read(//c~/AppData/Local/Microsoft/Credentials/*)",
      "Read(//c~/AppData/Roaming/Microsoft/Windows/Credentials/*)",
      "Read(//c~/AppData/Roaming/GitHub CLI/*)",
      "Read(//c~/AppData/Local/1Password/*)",
      "Read(//c~/AppData/Roaming/1Password/*)",
      "Read(//c~/AppData/Roaming/Bitwarden/*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash -c 'CMD=$(cat | jq -r \".tool_input.command // empty\"); if [ -z \"$CMD\" ]; then exit 0; fi; PATTERNS=\"(^|[;\\&\\|\\`\\$\\(])\\s*(curl|wget|nc|netcat|ncat|socat|ssh|scp|rsync|telnet|ftp|sftp|nmap)\\b\" ; PATTERNS2=\"(^|[;\\&\\|\\`\\$\\(])\\s*(sudo|su|do"
          }
        ]
      }
    ]
  }
}

Hooks (1)

eventmatcherruns
PreToolUseBashbash -c 'CMD=$(cat | jq -r ".tool_input.command // empty"); if [ -z "$CMD" ]; then exit 0; fi; PATTERNS="(^|[;\&\|\`\$\(])\s*(curl|wget|nc|netcat|ncat|socat|ssh|scp|rsync|telnet|ftp|sftp|nmap)\b" ; PATTERNS2="(^|[;\&\|\`\$\(])\s*(sudo|su|do

Permissions

deny (120)
Read(~/.ssh/*)
Read(~/.aws/*)
Read(~/.azure/*)
Read(~/.config/gcloud/*)
Read(~/.kube/*)
Read(~/.gnupg/*)
Read(~/.netrc)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.gem/credentials)
Read(~/.docker/config.json)
Read(~/.config/gh/*)
Read(~/Library/Keychains/*)
Read(~/Library/Keychains/**)
Read(/Library/Keychains/*)
Read(/Library/Keychains/**)
Read(~/Library/Application Support/1Password/*)
Read(//etc/passwd)
Read(//etc/shadow)
Read(//etc/sudoers)
Read(//etc/sudoers.d/*)
Read(//private/etc/*)
Read(//var/log/*)
Read(**/.env)
Read(**/.env.*)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pfx)
Read(**/*.jks)
Read(**/*.keystore)
Read(**/id_rsa*)
Read(**/id_ed25519*)
Read(**/terraform.tfstate*)
Read(**/*.tfstate)
Read(**/terraform.tfvars)
Read(**/credentials.json)
Read(**/credentials*)
Read(**/secrets/**)
Read(**/service-account*.json)
Read(**/*.rdp)
Read(**/*.ppk)
Read(/~/.ssh/*)
Read(/~/.aws/*)
Read(/~/.azure/*)
Read(/~/.config/gcloud/*)
Read(/~/.kube/*)
Read(/~/.gnupg/*)
Read(/~/.netrc)
Read(/~/.npmrc)
Read(/~/.docker/config.json)
Read(/~/.config/gh/*)
Read(/~/.config/systemd/*)
Read(/~/.local/share/keyrings/*)
Read(//root/.ssh/*)
Read(//root/.aws/*)
Read(//root/.kube/*)
Read(//root/.gnupg/*)
Read(//proc/*/environ)
Read(//proc/*/cmdline)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓