peopleforrester/claude-dotfiles
Configuration layer for Claude Code: 70 skills, 15 agents, 21 rules, 14 hooks, and 4 sandboxed permission profiles, all schema-validated in CI
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit peopleforrester/claude-dotfiles/examples/demo-project/.claude ./rig-claude-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/architect.md $ curl -fsSL --create-dirs -o .claude/agents/build-resolver.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/build-resolver.md $ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/code-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/database-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/database-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/doc-updater.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/doc-updater.md $ curl -fsSL --create-dirs -o .claude/agents/e2e-runner.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/e2e-runner.md $ curl -fsSL --create-dirs -o .claude/agents/go-build-resolver.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/go-build-resolver.md $ curl -fsSL --create-dirs -o .claude/agents/go-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/go-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/planner.md $ curl -fsSL --create-dirs -o .claude/agents/python-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/python-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/refactor-cleaner.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/refactor-cleaner.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/spec-interviewer.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/spec-interviewer.md $ curl -fsSL --create-dirs -o .claude/agents/tdd-guide.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/tdd-guide.md $ curl -fsSL --create-dirs -o .claude/agents/worktree-isolated-example.md https://raw.githubusercontent.com/peopleforrester/claude-dotfiles/main/agents/worktree-isolated-example.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./secrets/**)",
"Read(./**/credentials*)",
"Read(~/.aws/**)",
"Read(~/.ssh/**)",
"Read(~/.gnupg/**)",
"Bash(rm -rf *)",
"Bash(rm -r /)",
"Bash(curl * | bash)",
"Bash(curl * | sh)",
"Bash(wget * | bash)",
"Bash(wget * | sh)",
"Bash(sudo *)",
"Bash(chmod 777 *)",
"Bash(> /dev/*)"
],
"ask": [
"Bash(git commit *)",
"Bash(git push *)",
"Bash(git merge *)",
"Bash(git rebase *)",
"Bash(rm *)",
"Bash(docker run *)"
]
},
"sandbox": {
"enabled": true
}
} Subagents (15)
| architect model: opus | | |
| build-resolver model: sonnet | | |
| code-reviewer model: sonnet | | |
| database-reviewer model: opus | | |
| doc-updater model: haiku | | |
| e2e-runner model: sonnet | | |
| go-build-resolver model: sonnet | | |
| go-reviewer model: opus | | |
| planner model: opus | | |
| python-reviewer model: opus | | |
| refactor-cleaner model: sonnet | | |
| security-reviewer model: opus | | |
| spec-interviewer model: opus | | |
| tdd-guide model: sonnet | | |
| worktree-isolated-example model: sonnet | | |
Hooks (2)
| event | matcher | runs |
|---|---|---|
| PostToolUse | Edit|Write | FILE=$(cat | jq -r '.tool_input.file_path') && npx prettier --write "$FILE" 2>/dev/null || true |
| PostToolUse | Edit|Write | FILE=$(cat | jq -r '.tool_input.file_path') && npx prettier --write "$FILE" 2>/dev/null || true |
Permissions
deny (16)
Read(./.env)
Read(./.env.*)
Read(./secrets/**)
Read(./**/credentials*)
Read(~/.aws/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Bash(rm -rf *)
Bash(rm -r /)
Bash(curl * | bash)
Bash(curl * | sh)
Bash(wget * | bash)
Bash(wget * | sh)
Bash(sudo *)
Bash(chmod 777 *)
Bash(> /dev/*)
ask (6)
Bash(git commit *)
Bash(git push *)
Bash(git merge *)
Bash(git rebase *)
Bash(rm *)
Bash(docker run *)
allow (27)
Bash(pnpm *)
Bash(npx vitest *)
Read
Write
Edit
MultiEdit
Glob
Grep
LS
Bash(npm *)
Bash(pnpm *)
Bash(yarn *)
Bash(npx *)
Bash(node *)
Bash(git status)
Bash(git log *)
Bash(git diff *)
Bash(git branch *)
Bash(git add *)
Bash(git checkout *)
Bash(docker compose *)
Bash(docker ps *)
Bash(curl -s *)
Bash(cat *)
Bash(ls *)
Bash(mkdir *)
Bash(touch *)
Similar rigs
Feramirr/frc-claude-config
Shared Claude Code config for FRC Team 1868 — rules, agents, commands, and skills for robot development
Orchestrator 1.4k tok ·
RohiRIK/claude-code-config
Personal Claude Code global config — hooks, agents, skills, commands
YOLO Cowboy 2.8k tok ·
Yuutokata/claude-code-setup
🔄 One Claude Code setup for my desktop and MacBook, synced through git, with guardrails that keep secrets out.
Fort Knox 1.1k tok ·
VersoXBT/claude-initial-setup
75 skills, 14 agents, 15 commands for Claude Code. Plug-and-play starter kit covering TypeScript, Python, Go, Rust, React, Next.js, FastAPI, Django, Docker, CI/CD, security, testing, and more. Cross-AI support for Cursor, Copilot, and Codex
Orchestrator 5.1k tok ·