~ / rigs / r3dpepper / claude-dotfiles

r3dpepper/claude-dotfiles

Claude code workflow harness files. Goes to ~/.claude in user-scoped location.

↗ GitHub ★ 0 MIT updated 1mo ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.5k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit r3dpepper/claude-dotfiles/agents ./rig-claude-dotfiles/agents
$ npx degit r3dpepper/claude-dotfiles/skills ./rig-claude-dotfiles/skills
$ npx degit r3dpepper/claude-dotfiles/hooks ./rig-claude-dotfiles/hooks

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit r3dpepper/claude-dotfiles/skills/avoid-ai-tells .claude/skills/avoid-ai-tells
$ npx degit r3dpepper/claude-dotfiles/skills/code-review .claude/skills/code-review
$ npx degit r3dpepper/claude-dotfiles/skills/commit-message .claude/skills/commit-message
$ npx degit r3dpepper/claude-dotfiles/skills/plan .claude/skills/plan
$ npx degit r3dpepper/claude-dotfiles/skills/security-review .claude/skills/security-review
$ npx degit r3dpepper/claude-dotfiles/skills/tdd-workflow .claude/skills/tdd-workflow
$ npx degit r3dpepper/claude-dotfiles/skills/using-mcp-tools .claude/skills/using-mcp-tools
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/r3dpepper/claude-dotfiles/main/agents/code-reviewer.md
$ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/r3dpepper/claude-dotfiles/main/agents/planner.md
$ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/r3dpepper/claude-dotfiles/main/agents/security-reviewer.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)",
      "Read(./**/.env)",
      "Read(./**/.env.*)",
      "Read(./secrets/**)",
      "Read(./**/secrets/**)",
      "Read(./**/*.pem)",
      "Read(./**/*.key)",
      "Read(./**/*.p12)",
      "Read(./**/*.pfx)",
      "Read(./**/*.keystore)",
      "Read(~/.aws/**)",
      "Read(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.gcp/**)",
      "Read(~/.config/gh/hosts.yml)",
      "Read(./**/credentials.json)",
      "Read(./**/service-account*.json)",
      "Read(./**/gha-creds-*.json)",
      "Read(./**/.npmrc)",
      "Read(./**/.pypirc)",
      "Read(~/.npmrc)",
      "Read(~/.pypirc)",
      "Read(~/.netrc)",
      "Read(//**/id_rsa)",
      "Read(//**/id_ed25519)",
      "Read(//**/id_ecdsa)",
      "Read(//**/.netrc)",
      "Edit(./.github/workflows/**)",
      "Edit(./.github/workflows.yml)",
      "Edit(./.github/workflows.yaml)",
      "Edit(./.gitlab-ci.yml)",
      "Edit(./.circleci/**)",
      "Edit(./Jenkinsfile)",
      "Bash(curl *)",
      "Bash(wget *)",
      "Bash(nc *)",
      "Bash(netcat *)",
      "Bash(scp *)",
      "Bash(ssh *@*)",
      "Bash(ftp *)",
      "Bash(tftp *)",
      "Bash(dd if=*of=/dev/*)",
      "Bash(mkfs*)",
      "Bash(shutdown*)",
      "Bash(reboot*)",
      "Bash(halt*)",
      "Bash(poweroff*)",
      "WebFetch"
    ],
    "ask": [
      "Bash(git push*)",
      "Bash(git commit*)",
      "Bash(git merge*)",
      "Bash(git rebase*)",
      "Bash(git reset*)",
      "Bash(git clean*)",
      "Bash(git tag*)",
      "Bash(rm *)",
      "Bash(sudo *)",
      "Bash(chmod *)",
      "Bash(chown *)",
      "Bash(brew install*)",
      "Bash(brew upgrade*)",
      "Bash(pip install*)",
      "Bash(pip install -g*)",
      "Bash(npm install -g*)",
      "Bash(npm uninstall -g*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-main-commit.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/block-force-push.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/block-raw-network.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/block-destructive.sh"
          }
        ]
      },
      {
        "matcher": "Edit|Write|MultiEdit|NotebookEdit",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/protect-ci-workflows.sh"
          },
          {
            "type": "command",
            "command": "~/.claude/hooks/lint-ai-tells.sh"
          }
        ]
      }
    ]
  },
  "sandbox": {
    "enabled": true
  }
}

Skills (7)

Subagents (3)

code-reviewer
model: sonnet
Reviews code for quality, security, and maintainability. Reports findings as a structured list with file:line and concrete failure modes.
planner
model: sonnet
Turns a feature request into a structured implementation plan with grounded patterns, ordered tasks, and validation steps. Returns the plan only — does not write code.
security-reviewer
model: sonnet
Deep security review of recent changes. Focused on auth, secrets, network, file I/O, untrusted input, and crypto. Returns findings by severity with concrete attack scenarios and proposed fixes.

Hooks (8)

eventmatcherruns
PreToolUseBash~/.claude/hooks/block-main-commit.sh
PreToolUseBash~/.claude/hooks/block-force-push.sh
PreToolUseBash~/.claude/hooks/block-raw-network.sh
PreToolUseBash~/.claude/hooks/block-destructive.sh
PreToolUseEdit|Write|MultiEdit|NotebookEdit~/.claude/hooks/protect-ci-workflows.sh
PreToolUseEdit|Write|MultiEdit|NotebookEdit~/.claude/hooks/lint-ai-tells.sh
PostToolUseEdit|Write|MultiEdit~/.claude/hooks/audit-writes.sh
SessionStartstartup|resume~/.claude/hooks/session-guard.sh

Permissions

deny (49)
Read(./.env)
Read(./.env.*)
Read(./**/.env)
Read(./**/.env.*)
Read(./secrets/**)
Read(./**/secrets/**)
Read(./**/*.pem)
Read(./**/*.key)
Read(./**/*.p12)
Read(./**/*.pfx)
Read(./**/*.keystore)
Read(~/.aws/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.gcp/**)
Read(~/.config/gh/hosts.yml)
Read(./**/credentials.json)
Read(./**/service-account*.json)
Read(./**/gha-creds-*.json)
Read(./**/.npmrc)
Read(./**/.pypirc)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.netrc)
Read(//**/id_rsa)
Read(//**/id_ed25519)
Read(//**/id_ecdsa)
Read(//**/.netrc)
Edit(./.github/workflows/**)
Edit(./.github/workflows.yml)
Edit(./.github/workflows.yaml)
Edit(./.gitlab-ci.yml)
Edit(./.circleci/**)
Edit(./Jenkinsfile)
Bash(curl *)
Bash(wget *)
Bash(nc *)
Bash(netcat *)
Bash(scp *)
Bash(ssh *@*)
Bash(ftp *)
Bash(tftp *)
Bash(dd if=*of=/dev/*)
Bash(mkfs*)
Bash(shutdown*)
Bash(reboot*)
Bash(halt*)
Bash(poweroff*)
WebFetch
ask (17)
Bash(git push*)
Bash(git commit*)
Bash(git merge*)
Bash(git rebase*)
Bash(git reset*)
Bash(git clean*)
Bash(git tag*)
Bash(rm *)
Bash(sudo *)
Bash(chmod *)
Bash(chown *)
Bash(brew install*)
Bash(brew upgrade*)
Bash(pip install*)
Bash(pip install -g*)
Bash(npm install -g*)
Bash(npm uninstall -g*)
allow (26)
Bash(npm run *)
Bash(npm test *)
Bash(npx *)
Bash(yarn *)
Bash(pnpm *)
Bash(bun *)
Bash(make *)
Bash(cargo *)
Bash(cargo build *)
Bash(go test *)
Bash(go build *)
Bash(pytest *)
Bash(python -m pytest *)
Bash(git status)
Bash(git diff*)
Bash(git log*)
Bash(git branch*)
Bash(git show*)
Bash(git stash*)
Bash(git fetch*)
Bash(git checkout -b *)
Bash(git switch -c *)
Bash(git add *)
Bash(ls *)
Bash(pwd)
Bash(echo *)

Similar rigs

copied ✓