nylas/cli
Nylas CLI is a unified command-line tool for Nylas API authentication, email management (GPG signing/encryption), calendar, contacts, webhooks, timezone utilities, and OTP extraction
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit nylas/cli/.claude ./rig-cli # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/code-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/code-writer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/code-writer.md $ curl -fsSL --create-dirs -o .claude/agents/codebase-explorer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/codebase-explorer.md $ curl -fsSL --create-dirs -o .claude/agents/documentation-writer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/documentation-writer.md $ curl -fsSL --create-dirs -o .claude/agents/mistake-learner.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/mistake-learner.md $ curl -fsSL --create-dirs -o .claude/agents/doc-standards.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/references/doc-standards.md $ curl -fsSL --create-dirs -o .claude/agents/helper-reference.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/references/helper-reference.md $ curl -fsSL --create-dirs -o .claude/agents/security-checklist.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/references/security-checklist.md $ curl -fsSL --create-dirs -o .claude/agents/security-auditor.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/security-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/test-writer.md https://raw.githubusercontent.com/nylas/cli/main/.claude/agents/test-writer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(git push:*)",
"Bash(git push)",
"Bash(git push origin:*)",
"Bash(git reset --hard:*)",
"Bash(git reset --hard)",
"Bash(git clean -fd:*)",
"Bash(git clean -f:*)",
"Bash(git clean -fd)",
"Bash(git clean -f)",
"Bash(rm -rf /)",
"Bash(rm -rf ~)",
"Bash(rm -rf .)",
"Bash(rm -rf /*)",
"Bash(rm -r /)",
"Bash(rm -r ~)",
"Bash(rm -r .)",
"Bash(truncate:*)",
"Bash(wget:*)",
"Bash(sudo rm -rf /)",
"Bash(sudo rm -rf ~)",
"Bash(sudo rm -rf .)",
"Bash(sudo rm -rf /*)",
"Bash(chmod 777:*)",
"Bash(eval:*)",
"Bash(ssh:*)",
"Bash(scp:*)",
"Bash(nc:*)",
"Bash(netcat:*)",
"Read(.env)",
"Read(.env.*)",
"Read(.env.local)",
"Read(.env.production)",
"Read(**/secrets/**)",
"Read(**/*.pem)",
"Read(**/*.key)",
"Read(**/*.p12)",
"Read(**/credentials.json)",
"Read(**/credentials.yaml)",
"Read(**/credentials.yml)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Read(~/.config/gh/hosts.yml)",
"Write(.env)",
"Write(.env.*)",
"Write(**/secrets/**)",
"Write(**/*.pem)",
"Write(**/*.key)",
"Edit(.env)",
"Edit(.env.*)",
"Edit(**/secrets/**)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "if echo \"$TOOL_INPUT\" | grep -q 'git commit'; then git diff --cached --name-only | grep -E '\\.(env|pem|key|p12)$' && echo '⛔ BLOCKED: Sensitive file in commit' && exit 2 || exit 0; fi"
},
{
"type": "command",
"command": "if echo \"$TOOL_INPUT\" | grep -q 'git commit'; then git diff --cached | grep -iE '(api_key|password|secret|token|nyk_v0)' && echo '⛔ BLOCKED: Possible secret in commit' && exit 2 || exit 0; fi"
}
]
},
{
"matcher": "Write",
"hooks": [
{
"type": "command",
"command": ".claude/hooks/file-size-check.sh"
}
]
}
]
}
} Subagents (10)
| code-reviewer model: opus | Independent code reviewer for quality and best practices. Use PROACTIVELY after code changes. Can run in parallel with other reviewers. |
| code-writer model: sonnet | Expert polyglot code writer for Go, JavaScript, and CSS. Writes production-ready code following project patterns. Use PROACTIVELY for implementation tasks. |
| codebase-explorer model: haiku | Explores codebase for context without coding - returns concise summaries. Supports thoroughness levels (quick, medium, thorough). |
| documentation-writer model: sonnet | Documentation specialist for public repo. Use PROACTIVELY after feature completion, API changes, or CLI modifications. Ensures docs stay in sync with code. |
| mistake-learner model: sonnet | Analyzes mistakes and updates CLAUDE.md with abstracted learnings. MUST BE USED when errors are caught or mistakes identified. |
| doc-standards | — |
| helper-reference | — |
| security-checklist | — |
| security-auditor model: opus | Security vulnerability expert for Go CLI. Use PROACTIVELY for security-sensitive code, auth changes, or before releases. CRITICAL for public repo safety. |
| test-writer model: sonnet | Expert test writer for Go unit/integration tests. Generates comprehensive, maintainable tests. Use PROACTIVELY after code-writer completes. |
Hooks (6)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | if echo "$TOOL_INPUT" | grep -q 'git commit'; then git diff --cached --name-only | grep -E '\.(env|pem|key|p12)$' && echo '⛔ BLOCKED: Sensitive file in commit' && exit 2 || exit 0; fi |
| PreToolUse | Bash | if echo "$TOOL_INPUT" | grep -q 'git commit'; then git diff --cached | grep -iE '(api_key|password|secret|token|nyk_v0)' && echo '⛔ BLOCKED: Possible secret in commit' && exit 2 || exit 0; fi |
| PreToolUse | Write | .claude/hooks/file-size-check.sh |
| PostToolUse | Bash | if echo "$TOOL_INPUT" | grep -q 'git commit'; then echo '🔒 Running post-commit security scan...' && make security; fi |
| PostToolUse | Edit | .claude/hooks/auto-format.sh |
| PostToolUse | Write | .claude/hooks/auto-format.sh |
Slash commands (9)
/add-command/add-command/references/adapter-patterns/add-command/references/cli-patterns/add-command/references/domain-patterns/generate-crud-command/templates/crud-checklist/generate-tests/review-pr/run-tests/security-scan
Permissions
deny (50)
Bash(git push:*)
Bash(git push)
Bash(git push origin:*)
Bash(git reset --hard:*)
Bash(git reset --hard)
Bash(git clean -fd:*)
Bash(git clean -f:*)
Bash(git clean -fd)
Bash(git clean -f)
Bash(rm -rf /)
Bash(rm -rf ~)
Bash(rm -rf .)
Bash(rm -rf /*)
Bash(rm -r /)
Bash(rm -r ~)
Bash(rm -r .)
Bash(truncate:*)
Bash(wget:*)
Bash(sudo rm -rf /)
Bash(sudo rm -rf ~)
Bash(sudo rm -rf .)
Bash(sudo rm -rf /*)
Bash(chmod 777:*)
Bash(eval:*)
Bash(ssh:*)
Bash(scp:*)
Bash(nc:*)
Bash(netcat:*)
Read(.env)
Read(.env.*)
Read(.env.local)
Read(.env.production)
Read(**/secrets/**)
Read(**/*.pem)
Read(**/*.key)
Read(**/*.p12)
Read(**/credentials.json)
Read(**/credentials.yaml)
Read(**/credentials.yml)
Read(~/.ssh/**)
Read(~/.aws/**)
Read(~/.config/gh/hosts.yml)
Write(.env)
Write(.env.*)
Write(**/secrets/**)
Write(**/*.pem)
Write(**/*.key)
Edit(.env)
Edit(.env.*)
Edit(**/secrets/**)
ask (0)
—
allow (73)
Read
Edit
Write(internal/**)
Write(cmd/**)
Write(docs/**)
Write(.claude/**)
Write(.github/**)
Write(*.md)
Write(*.go)
Write(Makefile)
Write(.goreleaser.yml)
Write(go.mod)
Write(go.sum)
Bash(go build:*)
Bash(go test:*)
Bash(go run:*)
Bash(go mod:*)
Bash(go fmt:*)
Bash(go vet:*)
Bash(go generate:*)
Bash(go install:*)
Bash(golangci-lint:*)
Bash(make:*)
Bash(make build:*)
Bash(make test:*)
Bash(make ci:*)
Bash(make ci-full:*)
Bash(make lint:*)
Bash(make security:*)
Bash(./bin/nylas:*)
Bash(~/go/bin/goreleaser:*)
Bash(git add:*)
Bash(git commit:*)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git branch:*)
Bash(git checkout:*)
Bash(git stash:*)
Bash(git show:*)
Bash(git pull:*)
Bash(ls:*)
Bash(mkdir:*)
Bash(rm *.test:*)
Bash(rm ./bin/*:*)
Bash(rm -f ./bin/*:*)
Bash(cat:*)
Bash(head:*)
Bash(tail:*)
Bash(wc:*)
Bash(which:*)
Bash(grep:*)
Bash(pwd)
Bash(curl:*)
Bash(gh issue:*)
Bash(gh pr:*)
Bash(gh repo:*)
Bash(gh api:*)
Bash(gh auth status)
Bash(gh workflow:*)
Similar rigs
MCKRUZ/claude-code-mastery
The definitive Claude Code setup, configuration, and mastery skill — CLAUDE.md engineering, MCP servers, agent teams, hooks, CI/CD, and self-updating knowledge base
Minimalist 1.0k tok ·
maryam-bahrami/claude-code-project-structure
A practical Claude Code project template showcasing best practices for CLAUDE.md, commands, skills, agents, MCP integrations, and team workflows.
Pragmatist 3.0k tok ·
Yassinekrn/claude-setup
Personal Claude Code setup — orchestrator/subagent delegation policy, custom agents, and a colored PowerShell statusline (git branch, model+effort, tokens, cost, rate limits).
Orchestrator 1.2k tok ·
sbstnppl/multi-agent-project-template
A comprehensive template for Python projects with Claude Code integration, featuring a professional multi-agent workflow system for development, testing, documentation, and deployment.
Orchestrator 4.3k tok ·