~ / rigs / nylas / cli

nylas/cli

Nylas CLI is a unified command-line tool for Nylas API authentication, email management (GPG signing/encryption), calendar, contacts, webhooks, timezone utilities, and OTP extraction

↗ GitHub ★ 75 mit updated 8d ago project Claude CodeCodex
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.8k tokens
Featherweight · median rig: 2.2k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit nylas/cli/.claude ./rig-cli  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/code-writer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/code-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/codebase-explorer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/codebase-explorer.md
$ curl -fsSL --create-dirs -o .claude/agents/documentation-writer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/documentation-writer.md
$ curl -fsSL --create-dirs -o .claude/agents/mistake-learner.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/mistake-learner.md
$ curl -fsSL --create-dirs -o .claude/agents/doc-standards.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/references/doc-standards.md
$ curl -fsSL --create-dirs -o .claude/agents/helper-reference.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/references/helper-reference.md
$ curl -fsSL --create-dirs -o .claude/agents/security-checklist.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/references/security-checklist.md
$ curl -fsSL --create-dirs -o .claude/agents/security-auditor.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/security-auditor.md
$ curl -fsSL --create-dirs -o .claude/agents/test-writer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/test-writer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(git push:*)",
      "Bash(git push)",
      "Bash(git push origin:*)",
      "Bash(git reset --hard:*)",
      "Bash(git reset --hard)",
      "Bash(git clean -fd:*)",
      "Bash(git clean -f:*)",
      "Bash(git clean -fd)",
      "Bash(git clean -f)",
      "Bash(rm -rf /)",
      "Bash(rm -rf ~)",
      "Bash(rm -rf .)",
      "Bash(rm -rf /*)",
      "Bash(rm -r /)",
      "Bash(rm -r ~)",
      "Bash(rm -r .)",
      "Bash(truncate:*)",
      "Bash(wget:*)",
      "Bash(sudo rm -rf /)",
      "Bash(sudo rm -rf ~)",
      "Bash(sudo rm -rf .)",
      "Bash(sudo rm -rf /*)",
      "Bash(chmod 777:*)",
      "Bash(eval:*)",
      "Bash(ssh:*)",
      "Bash(scp:*)",
      "Bash(nc:*)",
      "Bash(netcat:*)",
      "Read(.env)",
      "Read(.env.*)",
      "Read(.env.local)",
      "Read(.env.production)",
      "Read(**/secrets/**)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Read(**/*.p12)",
      "Read(**/credentials.json)",
      "Read(**/credentials.yaml)",
      "Read(**/credentials.yml)",
      "Read(~/.ssh/**)",
      "Read(~/.aws/**)",
      "Read(~/.config/gh/hosts.yml)",
      "Write(.env)",
      "Write(.env.*)",
      "Write(**/secrets/**)",
      "Write(**/*.pem)",
      "Write(**/*.key)",
      "Edit(.env)",
      "Edit(.env.*)",
      "Edit(**/secrets/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "if echo \"$TOOL_INPUT\" | grep -q 'git commit'; then git diff --cached --name-only | grep -E '\\.(env|pem|key|p12)$' && echo '⛔ BLOCKED: Sensitive file in commit' && exit 2 || exit 0; fi"
          },
          {
            "type": "command",
            "command": "if echo \"$TOOL_INPUT\" | grep -q 'git commit'; then git diff --cached | grep -iE '(api_key|password|secret|token|nyk_v0)' && echo '⛔ BLOCKED: Possible secret in commit' && exit 2 || exit 0; fi"
          }
        ]
      },
      {
        "matcher": "Write",
        "hooks": [
          {
            "type": "command",
            "command": ".claude/hooks/file-size-check.sh"
          }
        ]
      }
    ]
  }
}

Subagents (10)

code-reviewer
model: opus
Independent code reviewer for quality and best practices. Use PROACTIVELY after code changes. Can run in parallel with other reviewers.
code-writer
model: sonnet
Expert polyglot code writer for Go, JavaScript, and CSS. Writes production-ready code following project patterns. Use PROACTIVELY for implementation tasks.
codebase-explorer
model: haiku
Explores codebase for context without coding - returns concise summaries. Supports thoroughness levels (quick, medium, thorough).
documentation-writer
model: sonnet
Documentation specialist for public repo. Use PROACTIVELY after feature completion, API changes, or CLI modifications. Ensures docs stay in sync with code.
mistake-learner
model: sonnet
Analyzes mistakes and updates CLAUDE.md with abstracted learnings. MUST BE USED when errors are caught or mistakes identified.
doc-standards—
helper-reference—
security-checklist—
security-auditor
model: opus
Security vulnerability expert for Go CLI. Use PROACTIVELY for security-sensitive code, auth changes, or before releases. CRITICAL for public repo safety.
test-writer
model: sonnet
Expert test writer for Go unit/integration tests. Generates comprehensive, maintainable tests. Use PROACTIVELY after code-writer completes.

Hooks (6)

eventmatcherruns
PreToolUseBashif echo "$TOOL_INPUT" | grep -q 'git commit'; then git diff --cached --name-only | grep -E '\.(env|pem|key|p12)$' && echo '⛔ BLOCKED: Sensitive file in commit' && exit 2 || exit 0; fi
PreToolUseBashif echo "$TOOL_INPUT" | grep -q 'git commit'; then git diff --cached | grep -iE '(api_key|password|secret|token|nyk_v0)' && echo '⛔ BLOCKED: Possible secret in commit' && exit 2 || exit 0; fi
PreToolUseWrite.claude/hooks/file-size-check.sh
PostToolUseBashif echo "$TOOL_INPUT" | grep -q 'git commit'; then echo '🔒 Running post-commit security scan...' && make security; fi
PostToolUseEdit.claude/hooks/auto-format.sh
PostToolUseWrite.claude/hooks/auto-format.sh

Slash commands (9)

/add-command/add-command/references/adapter-patterns/add-command/references/cli-patterns/add-command/references/domain-patterns/generate-crud-command/templates/crud-checklist/generate-tests/review-pr/run-tests/security-scan

Permissions

deny (50)
Bash(git push:*)
Bash(git push)
Bash(git push origin:*)
Bash(git reset --hard:*)
Bash(git reset --hard)
Bash(git clean -fd:*)
Bash(git clean -f:*)
Bash(git clean -fd)
Bash(git clean -f)
Bash(rm -rf /)
Bash(rm -rf ~)
Bash(rm -rf .)
Bash(rm -rf /*)
Bash(rm -r /)
Bash(rm -r ~)
Bash(rm -r .)
Bash(truncate:*)
Bash(wget:*)
Bash(sudo rm -rf /)
Bash(sudo rm -rf ~)
Bash(sudo rm -rf .)
Bash(sudo rm -rf /*)
Bash(chmod 777:*)
Bash(eval:*)
Bash(ssh:*)
Bash(scp:*)
Bash(nc:*)
Bash(netcat:*)
Read(.env)
Read(.env.*)
Read(.env.local)
Read(.env.production)
Read(**/secrets/**)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/credentials.json)
Read(**/credentials.yaml)
Read(**/credentials.yml)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gh/hosts.yml)
Write(.env)
Write(.env.*)
Write(**/secrets/**)
Write(**/*.pem)
Write(**/*.key)
Edit(.env)
Edit(.env.*)
Edit(**/secrets/**)
ask (0)
—
allow (73)
Read
Edit
Write(internal/**)
Write(cmd/**)
Write(docs/**)
Write(.claude/**)
Write(.github/**)
Write(*.md)
Write(*.go)
Write(Makefile)
Write(.goreleaser.yml)
Write(go.mod)
Write(go.sum)
Bash(go build:*)
Bash(go test:*)
Bash(go run:*)
Bash(go mod:*)
Bash(go fmt:*)
Bash(go vet:*)
Bash(go generate:*)
Bash(go install:*)
Bash(golangci-lint:*)
Bash(make:*)
Bash(make build:*)
Bash(make test:*)
Bash(make ci:*)
Bash(make ci-full:*)
Bash(make lint:*)
Bash(make security:*)
Bash(./bin/nylas:*)
Bash(~/go/bin/goreleaser:*)
Bash(git add:*)
Bash(git commit:*)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git branch:*)
Bash(git checkout:*)
Bash(git stash:*)
Bash(git show:*)
Bash(git pull:*)
Bash(ls:*)
Bash(mkdir:*)
Bash(rm *.test:*)
Bash(rm ./bin/*:*)
Bash(rm -f ./bin/*:*)
Bash(cat:*)
Bash(head:*)
Bash(tail:*)
Bash(wc:*)
Bash(which:*)
Bash(grep:*)
Bash(pwd)
Bash(curl:*)
Bash(gh issue:*)
Bash(gh pr:*)
Bash(gh repo:*)
Bash(gh api:*)
Bash(gh auth status)
Bash(gh workflow:*)

Similar rigs

copied ✓