~ / rigs / peopleforrester / claude-dotfiles

peopleforrester/claude-dotfiles

Configuration layer for Claude Code: 70 skills, 15 agents, 21 rules, 14 hooks, and 4 sandboxed permission profiles, all schema-validated in CI

↗ GitHub ★ 3 MIT updated 22d ago personal setup Claude CodeCodex Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~862 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit peopleforrester/claude-dotfiles/examples/demo-project/.claude ./rig-claude-dotfiles  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/architect.md
$ curl -fsSL --create-dirs -o .claude/agents/build-resolver.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/build-resolver.md
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/database-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/database-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/doc-updater.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/doc-updater.md
$ curl -fsSL --create-dirs -o .claude/agents/e2e-runner.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/e2e-runner.md
$ curl -fsSL --create-dirs -o .claude/agents/go-build-resolver.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/go-build-resolver.md
$ curl -fsSL --create-dirs -o .claude/agents/go-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/go-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/planner.md
$ curl -fsSL --create-dirs -o .claude/agents/python-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/python-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/refactor-cleaner.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/refactor-cleaner.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/security-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/spec-interviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/spec-interviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/tdd-guide.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/tdd-guide.md
$ curl -fsSL --create-dirs -o .claude/agents/worktree-isolated-example.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/worktree-isolated-example.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./secrets/**)",
      "Read(./**/credentials*)",
      "Read(~/.aws/**)",
      "Read(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Bash(rm -rf *)",
      "Bash(rm -r /)",
      "Bash(curl * | bash)",
      "Bash(curl * | sh)",
      "Bash(wget * | bash)",
      "Bash(wget * | sh)",
      "Bash(sudo *)",
      "Bash(chmod 777 *)",
      "Bash(> /dev/*)"
    ],
    "ask": [
      "Bash(git commit *)",
      "Bash(git push *)",
      "Bash(git merge *)",
      "Bash(git rebase *)",
      "Bash(rm *)",
      "Bash(docker run *)"
    ]
  },
  "sandbox": {
    "enabled": true
  }
}

Subagents (15)

architect
model: opus
|
build-resolver
model: sonnet
|
code-reviewer
model: sonnet
|
database-reviewer
model: opus
|
doc-updater
model: haiku
|
e2e-runner
model: sonnet
|
go-build-resolver
model: sonnet
|
go-reviewer
model: opus
|
planner
model: opus
|
python-reviewer
model: opus
|
refactor-cleaner
model: sonnet
|
security-reviewer
model: opus
|
spec-interviewer
model: opus
|
tdd-guide
model: sonnet
|
worktree-isolated-example
model: sonnet
|

Hooks (2)

eventmatcherruns
PostToolUseEdit|WriteFILE=$(cat | jq -r '.tool_input.file_path') && npx prettier --write "$FILE" 2>/dev/null || true
PostToolUseEdit|WriteFILE=$(cat | jq -r '.tool_input.file_path') && npx prettier --write "$FILE" 2>/dev/null || true

Permissions

deny (16)
Read(./.env)
Read(./.env.*)
Read(./secrets/**)
Read(./**/credentials*)
Read(~/.aws/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Bash(rm -rf *)
Bash(rm -r /)
Bash(curl * | bash)
Bash(curl * | sh)
Bash(wget * | bash)
Bash(wget * | sh)
Bash(sudo *)
Bash(chmod 777 *)
Bash(> /dev/*)
ask (6)
Bash(git commit *)
Bash(git push *)
Bash(git merge *)
Bash(git rebase *)
Bash(rm *)
Bash(docker run *)
allow (27)
Bash(pnpm *)
Bash(npx vitest *)
Read
Write
Edit
MultiEdit
Glob
Grep
LS
Bash(npm *)
Bash(pnpm *)
Bash(yarn *)
Bash(npx *)
Bash(node *)
Bash(git status)
Bash(git log *)
Bash(git diff *)
Bash(git branch *)
Bash(git add *)
Bash(git checkout *)
Bash(docker compose *)
Bash(docker ps *)
Bash(curl -s *)
Bash(cat *)
Bash(ls *)
Bash(mkdir *)
Bash(touch *)

Similar rigs

copied ✓