~ / rigs / poshan0126 / dotclaude

poshan0126/dotclaude

The standard .claude/ folder structure for everyday development.

↗ GitHub ★ 871 MIT updated 1mo ago personal setup Claude Code Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.7k tokens
Featherweight · median rig: 2.2k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit poshan0126/dotclaude/agents ./rig-dotclaude/agents
$ npx degit poshan0126/dotclaude/skills ./rig-dotclaude/skills
$ npx degit poshan0126/dotclaude/hooks ./rig-dotclaude/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit poshan0126/dotclaude/skills/catchup .claude/skills/catchup
$ npx degit poshan0126/dotclaude/skills/claude-md .claude/skills/claude-md
$ npx degit poshan0126/dotclaude/skills/context-budget .claude/skills/context-budget
$ npx degit poshan0126/dotclaude/skills/debug-fix .claude/skills/debug-fix
$ npx degit poshan0126/dotclaude/skills/explain .claude/skills/explain
$ npx degit poshan0126/dotclaude/skills/fix-issue .claude/skills/fix-issue
$ npx degit poshan0126/dotclaude/skills/onboard .claude/skills/onboard
$ npx degit poshan0126/dotclaude/skills/pr-review .claude/skills/pr-review
$ npx degit poshan0126/dotclaude/skills/refactor .claude/skills/refactor
$ npx degit poshan0126/dotclaude/skills/setupdotclaude .claude/skills/setupdotclaude
$ npx degit poshan0126/dotclaude/skills/ship .claude/skills/ship
$ npx degit poshan0126/dotclaude/skills/spec .claude/skills/spec
$ npx degit poshan0126/dotclaude/skills/tdd .claude/skills/tdd
$ npx degit poshan0126/dotclaude/skills/test-writer .claude/skills/test-writer
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/poshan0126/dotclaude/main/agents/code-reviewer/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/doc-reviewer.md https://raw.githubusercontent.com/poshan0126/dotclaude/main/agents/doc-reviewer/doc-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/frontend-designer.md https://raw.githubusercontent.com/poshan0126/dotclaude/main/agents/frontend-designer/frontend-designer.md
$ curl -fsSL --create-dirs -o .claude/agents/performance-reviewer.md https://raw.githubusercontent.<redacted>-reviewer/performance-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/pr-test-analyzer.md https://raw.githubusercontent.com/poshan0126/dotclaude/main/agents/pr-test-analyzer/pr-test-analyzer.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/poshan0126/dotclaude/main/agents/security-reviewer/security-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/silent-failure-hunter.md https://raw.githubusercontent.com/poshan0126/dotclaude/main/agents/silent-failure-hunter/silent-failure-hunter.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(**/secrets/**)",
      "Read(**/*.pem)",
      "Read(**/*.key)",
      "Write(**/.env)",
      "Write(**/.env.*)",
      "Write(**/secrets/**)",
      "Write(**/*.pem)",
      "Write(**/*.key)",
      "Edit(**/.env)",
      "Edit(**/.env.*)",
      "Edit(**/secrets/**)",
      "Edit(**/*.pem)",
      "Edit(**/*.key)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Edit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/protect-files.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/warn-large-files.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/scan-secrets.sh"
          }
        ]
      },
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-dangerous-commands.sh"
          }
        ]
      }
    ]
  }
}

Skills (14)

Subagents (7)

code-reviewerUse after any code change, before committing, or when a PR or diff needs review. Catches real bugs — off-by-ones, null derefs, logic inversions, race conditions, swallowed errors, complexity — with ev
doc-reviewerUse after .md, docstring, JSDoc, or API-doc changes — or when code changes may have invalidated existing docs. Cross-references docs against actual source: stale references, wrong signatures, missing
frontend-designerUse when building or restyling any web UI — pages, dashboards, components. Designs tokens-first with a deliberate design principle, avoids generic AI aesthetics, enforces accessibility. States its pla
performance-reviewerUse proactively after changes to hot paths, API endpoints, DB queries, loops over collections, or rendering code. Finds measurable bottlenecks — N+1 queries, memory leaks, blocking I/O, re-renders — n
pr-test-analyzerUse when a diff adds or changes tests, or changes behavior without touching tests. Judges whether the tests actually verify the change — catches assertion-free tests, mock theater, tests that can't fa
security-reviewerUse after changes to auth, input handling, queries, file paths, tokens, or crypto — and before deploying any of those. OWASP-style static analysis: injection, authz flaws, data exposure, weak crypto.
silent-failure-hunterUse after any change that touches error handling, catch blocks, fallbacks, retries, or async flows — and on every PR review. Finds code that fails silently: swallowed errors, failures masked as succes

Hooks (8)

eventmatcherruns
PreToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/protect-files.sh
PreToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/warn-large-files.sh
PreToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/scan-secrets.sh
PreToolUseBash$CLAUDE_PROJECT_DIR/.claude/hooks/block-dangerous-commands.sh
PostToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/format-on-save.sh
PostToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/auto-test.sh
SessionStartstartup|resume|clear$CLAUDE_PROJECT_DIR/.claude/hooks/session-start.sh
Notification*$CLAUDE_PROJECT_DIR/.claude/hooks/notify.sh

Permissions

deny (15)
Read(**/.env)
Read(**/.env.*)
Read(**/secrets/**)
Read(**/*.pem)
Read(**/*.key)
Write(**/.env)
Write(**/.env.*)
Write(**/secrets/**)
Write(**/*.pem)
Write(**/*.key)
Edit(**/.env)
Edit(**/.env.*)
Edit(**/secrets/**)
Edit(**/*.pem)
Edit(**/*.key)
ask (0)
—
allow (17)
Bash(npm run lint *)
Bash(npm run test *)
Bash(npm run typecheck)
Bash(npm run build)
Bash(git status)
Bash(git diff *)
Bash(git log *)
Bash(git branch *)
Bash(git stash *)
Bash(git add *)
Bash(git commit *)
Bash(git fetch *)
Bash(git checkout *)
Bash(git switch *)
Bash(gh pr *)
Bash(gh issue *)
Bash(gh run *)

Similar rigs

copied ✓