~ / rigs / oryband / dotfiles

oryband/dotfiles

My main working machine setup. Here be cyber dragons 🐉 and optional bugs 🐛.

↗ GitHub ★ 37 no license updated 3mo ago personal setup Claude Code
share on X
ARCHETYPE
YOLO Cowboy
Permissions? Never heard of 'em. Ships at the speed of `--dangerously-skip-permissions`.
CONTEXT TAX · EVERY TURN
~8.3k tokens
Heavy · median rig: 2.3k · breakdown
GUARDRAILS
2/5
Protects secrets · Pre-tool screening hook · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add sequential-thinking -e PATH=YOUR_PATH -- npx -y @modelcontextprotocol/server-sequential-thinking@latest
$ claude mcp add --transport http context7 https://mcp.context7.com/mcp -H 'CONTEXT7_API_KEY: YOUR_VALUE'
$ claude mcp add --transport http tavily https://mcp.tavily.com/mcp/ -H 'Authorization: YOUR_VALUE'
$ npx degit oryband/dotfiles/.claude ./rig-dotfiles  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add sequential-thinking -e PATH=YOUR_PATH -- npx -y @modelcontextprotocol/server-sequential-thinking@latest
$ claude mcp add --transport http context7 https://mcp.context7.com/mcp -H 'CONTEXT7_API_KEY: YOUR_VALUE'
$ claude mcp add --transport http tavily https://mcp.tavily.com/mcp/ -H 'Authorization: YOUR_VALUE'

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(op *)",
      "Read(**/.ssh/**)",
      "Read(**/.gnupg/**)",
      "Read(**/private-keys-v1.d/**)",
      "Read(**/openpgp-revocs.d/**)",
      "Read(**/*.asc)",
      "Read(**/*.rev)",
      "Read(**/*.gpg)",
      "Read(**/*.jks)",
      "Read(**/*.key)",
      "Read(**/*.keystore)",
      "Read(**/*.p12)",
      "Read(**/*.pem)",
      "Read(**/*.pfx)",
      "Read(**/*.pgp)",
      "Read(**/*.ppk)",
      "Read(**/*.tfstate)",
      "Read(**/*credential*)",
      "Read(**/*password*)",
      "Read(**/*secret*)",
      "Read(**/*vault_pass*)",
      "Read(**/.aws/**)",
      "Read(**/.aws/credentials)",
      "Read(**/.azure/**)",
      "Read(**/.bash_history)",
      "Read(**/.config/gcloud/**)",
      "Read(**/.docker/config.json)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/.git-credentials)",
      "Read(**/.htpasswd)",
      "Read(**/.kube/**)",
      "Read(**/.kube/config)",
      "Read(**/.my.cnf)",
      "Read(**/.netrc)",
      "Read(**/.npmrc)",
      "Read(**/.pgpass)",
      "Read(**/.pypirc)",
      "Read(**/.ssh/id_*)",
      "Read(**/.yarnrc)",
      "Read(**/.zsh-work)",
      "Read(**/.zsh_history)",
      "Read(**/credentials.json)",
      "Read(**/id_ed25519)",
      "Read(**/id_rsa)",
      "Read(**/secrets.json)",
      "Read(**/secrets.yaml)",
      "Read(**/secrets.yml)",
      "Read(**/secrets/**)",
      "Read(.awscreds)",
      "Read(.certs/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.local/bin/dcg"
          }
        ]
      }
    ]
  }
}

MCP servers (4)

serversourceest. tokens
Sequential Thinking · "sequential-thinking"
env: PATH
npm 900
Context7 remote · remote 1.2k
Tavily remote · remote 2.0k
exa local / custom · remote 2.5k

Hooks (6)

eventmatcherruns
PreToolUseBash~/.local/bin/dcg
SessionStart*~/.claude/scripts/tmux-rename.sh ○ force
UserPromptSubmit*~/.claude/scripts/tmux-rename.sh ✻
Notification*~/.claude/scripts/tmux-rename.sh !
Stop*~/.claude/scripts/tmux-rename.sh ✓
SessionEnd*[ -n "$TMUX_PANE" ] && tmux set-window-option -t $(tmux display-message -p -t "$TMUX_PANE" '#I') automatic-rename on 2>/dev/null; true

Plugins (4)

typescript-lsp@claude-plugins-officialpyright-lsp@claude-plugins-officialslack@claude-plugins-officialastral@astral-sh

Permissions

deny (51)
Bash(op *)
Read(**/.ssh/**)
Read(**/.gnupg/**)
Read(**/private-keys-v1.d/**)
Read(**/openpgp-revocs.d/**)
Read(**/*.asc)
Read(**/*.rev)
Read(**/*.gpg)
Read(**/*.jks)
Read(**/*.key)
Read(**/*.keystore)
Read(**/*.p12)
Read(**/*.pem)
Read(**/*.pfx)
Read(**/*.pgp)
Read(**/*.ppk)
Read(**/*.tfstate)
Read(**/*credential*)
Read(**/*password*)
Read(**/*secret*)
Read(**/*vault_pass*)
Read(**/.aws/**)
Read(**/.aws/credentials)
Read(**/.azure/**)
Read(**/.bash_history)
Read(**/.config/gcloud/**)
Read(**/.docker/config.json)
Read(**/.env)
Read(**/.env.*)
Read(**/.git-credentials)
Read(**/.htpasswd)
Read(**/.kube/**)
Read(**/.kube/config)
Read(**/.my.cnf)
Read(**/.netrc)
Read(**/.npmrc)
Read(**/.pgpass)
Read(**/.pypirc)
Read(**/.ssh/id_*)
Read(**/.yarnrc)
Read(**/.zsh-work)
Read(**/.zsh_history)
Read(**/credentials.json)
Read(**/id_ed25519)
Read(**/id_rsa)
Read(**/secrets.json)
Read(**/secrets.yaml)
Read(**/secrets.yml)
Read(**/secrets/**)
Read(.awscreds)
Read(.certs/**)
ask (0)
—
allow (21)
Bash(*)
Edit(/tmp/**)
Edit(/var/tmp/**)
Read(/tmp/**)
Read(/var/tmp/**)
Read(~/Development/**)
Skill(*)
WebFetch
WebSearch
Write(/tmp/**)
Write(/var/tmp/**)
mcp__chrome-devtools
mcp__context7
mcp__exa
mcp__github
mcp__obsidian
mcp__playwright
mcp__plugin_slack_slack
mcp__postman
mcp__sequential-thinking
mcp__tavily

Similar rigs

copied ✓