r3dpepper/claude-dotfiles
Claude code workflow harness files. Goes to ~/.claude in user-scoped location.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ npx degit r3dpepper/claude-dotfiles/agents ./rig-claude-dotfiles/agents $ npx degit r3dpepper/claude-dotfiles/skills ./rig-claude-dotfiles/skills $ npx degit r3dpepper/claude-dotfiles/hooks ./rig-claude-dotfiles/hooks
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit r3dpepper/claude-dotfiles/skills/avoid-ai-tells .claude/skills/avoid-ai-tells $ npx degit r3dpepper/claude-dotfiles/skills/code-review .claude/skills/code-review $ npx degit r3dpepper/claude-dotfiles/skills/commit-message .claude/skills/commit-message $ npx degit r3dpepper/claude-dotfiles/skills/plan .claude/skills/plan $ npx degit r3dpepper/claude-dotfiles/skills/security-review .claude/skills/security-review $ npx degit r3dpepper/claude-dotfiles/skills/tdd-workflow .claude/skills/tdd-workflow $ npx degit r3dpepper/claude-dotfiles/skills/using-mcp-tools .claude/skills/using-mcp-tools
$ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/r3dpepper/claude-dotfiles/main/agents/code-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/r3dpepper/claude-dotfiles/main/agents/planner.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/r3dpepper/claude-dotfiles/main/agents/security-reviewer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./**/.env)",
"Read(./**/.env.*)",
"Read(./secrets/**)",
"Read(./**/secrets/**)",
"Read(./**/*.pem)",
"Read(./**/*.key)",
"Read(./**/*.p12)",
"Read(./**/*.pfx)",
"Read(./**/*.keystore)",
"Read(~/.aws/**)",
"Read(~/.ssh/**)",
"Read(~/.gnupg/**)",
"Read(~/.gcp/**)",
"Read(~/.config/gh/hosts.yml)",
"Read(./**/credentials.json)",
"Read(./**/service-account*.json)",
"Read(./**/gha-creds-*.json)",
"Read(./**/.npmrc)",
"Read(./**/.pypirc)",
"Read(~/.npmrc)",
"Read(~/.pypirc)",
"Read(~/.netrc)",
"Read(//**/id_rsa)",
"Read(//**/id_ed25519)",
"Read(//**/id_ecdsa)",
"Read(//**/.netrc)",
"Edit(./.github/workflows/**)",
"Edit(./.github/workflows.yml)",
"Edit(./.github/workflows.yaml)",
"Edit(./.gitlab-ci.yml)",
"Edit(./.circleci/**)",
"Edit(./Jenkinsfile)",
"Bash(curl *)",
"Bash(wget *)",
"Bash(nc *)",
"Bash(netcat *)",
"Bash(scp *)",
"Bash(ssh *@*)",
"Bash(ftp *)",
"Bash(tftp *)",
"Bash(dd if=*of=/dev/*)",
"Bash(mkfs*)",
"Bash(shutdown*)",
"Bash(reboot*)",
"Bash(halt*)",
"Bash(poweroff*)",
"WebFetch"
],
"ask": [
"Bash(git push*)",
"Bash(git commit*)",
"Bash(git merge*)",
"Bash(git rebase*)",
"Bash(git reset*)",
"Bash(git clean*)",
"Bash(git tag*)",
"Bash(rm *)",
"Bash(sudo *)",
"Bash(chmod *)",
"Bash(chown *)",
"Bash(brew install*)",
"Bash(brew upgrade*)",
"Bash(pip install*)",
"Bash(pip install -g*)",
"Bash(npm install -g*)",
"Bash(npm uninstall -g*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "~/.claude/hooks/block-main-commit.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/block-force-push.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/block-raw-network.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/block-destructive.sh"
}
]
},
{
"matcher": "Edit|Write|MultiEdit|NotebookEdit",
"hooks": [
{
"type": "command",
"command": "~/.claude/hooks/protect-ci-workflows.sh"
},
{
"type": "command",
"command": "~/.claude/hooks/lint-ai-tells.sh"
}
]
}
]
},
"sandbox": {
"enabled": true
}
} Skills (7)
Subagents (3)
| code-reviewer model: sonnet | Reviews code for quality, security, and maintainability. Reports findings as a structured list with file:line and concrete failure modes. |
| planner model: sonnet | Turns a feature request into a structured implementation plan with grounded patterns, ordered tasks, and validation steps. Returns the plan only — does not write code. |
| security-reviewer model: sonnet | Deep security review of recent changes. Focused on auth, secrets, network, file I/O, untrusted input, and crypto. Returns findings by severity with concrete attack scenarios and proposed fixes. |
Hooks (8)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | ~/.claude/hooks/block-main-commit.sh |
| PreToolUse | Bash | ~/.claude/hooks/block-force-push.sh |
| PreToolUse | Bash | ~/.claude/hooks/block-raw-network.sh |
| PreToolUse | Bash | ~/.claude/hooks/block-destructive.sh |
| PreToolUse | Edit|Write|MultiEdit|NotebookEdit | ~/.claude/hooks/protect-ci-workflows.sh |
| PreToolUse | Edit|Write|MultiEdit|NotebookEdit | ~/.claude/hooks/lint-ai-tells.sh |
| PostToolUse | Edit|Write|MultiEdit | ~/.claude/hooks/audit-writes.sh |
| SessionStart | startup|resume | ~/.claude/hooks/session-guard.sh |
Permissions
deny (49)
Read(./.env)
Read(./.env.*)
Read(./**/.env)
Read(./**/.env.*)
Read(./secrets/**)
Read(./**/secrets/**)
Read(./**/*.pem)
Read(./**/*.key)
Read(./**/*.p12)
Read(./**/*.pfx)
Read(./**/*.keystore)
Read(~/.aws/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.gcp/**)
Read(~/.config/gh/hosts.yml)
Read(./**/credentials.json)
Read(./**/service-account*.json)
Read(./**/gha-creds-*.json)
Read(./**/.npmrc)
Read(./**/.pypirc)
Read(~/.npmrc)
Read(~/.pypirc)
Read(~/.netrc)
Read(//**/id_rsa)
Read(//**/id_ed25519)
Read(//**/id_ecdsa)
Read(//**/.netrc)
Edit(./.github/workflows/**)
Edit(./.github/workflows.yml)
Edit(./.github/workflows.yaml)
Edit(./.gitlab-ci.yml)
Edit(./.circleci/**)
Edit(./Jenkinsfile)
Bash(curl *)
Bash(wget *)
Bash(nc *)
Bash(netcat *)
Bash(scp *)
Bash(ssh *@*)
Bash(ftp *)
Bash(tftp *)
Bash(dd if=*of=/dev/*)
Bash(mkfs*)
Bash(shutdown*)
Bash(reboot*)
Bash(halt*)
Bash(poweroff*)
WebFetch
ask (17)
Bash(git push*)
Bash(git commit*)
Bash(git merge*)
Bash(git rebase*)
Bash(git reset*)
Bash(git clean*)
Bash(git tag*)
Bash(rm *)
Bash(sudo *)
Bash(chmod *)
Bash(chown *)
Bash(brew install*)
Bash(brew upgrade*)
Bash(pip install*)
Bash(pip install -g*)
Bash(npm install -g*)
Bash(npm uninstall -g*)
allow (26)
Bash(npm run *)
Bash(npm test *)
Bash(npx *)
Bash(yarn *)
Bash(pnpm *)
Bash(bun *)
Bash(make *)
Bash(cargo *)
Bash(cargo build *)
Bash(go test *)
Bash(go build *)
Bash(pytest *)
Bash(python -m pytest *)
Bash(git status)
Bash(git diff*)
Bash(git log*)
Bash(git branch*)
Bash(git show*)
Bash(git stash*)
Bash(git fetch*)
Bash(git checkout -b *)
Bash(git switch -c *)
Bash(git add *)
Bash(ls *)
Bash(pwd)
Bash(echo *)
Similar rigs
cfrs2005/claude-init
Claude Code 中文开发套件 - 为中国开发者定制的零门槛 AI 编程环境。一键安装完整中文化体验,集成 MCP 服务器、智能上下文管理、安全扫描,支持免翻墙访问。让 AI 编程更简单。
Orchestrator 1.5k tok ·
mh2-lee/everything-claude-code
Complete Claude Code configuration collection - agents, skills, hooks, commands, rules, MCPs. Battle-tested configs from an Anthropic hackathon winner.
Orchestrator 1.2k tok ·
hirokami3/everything-claude-code
Claude Code configs collection - agents, skills, hooks, commands, rules, and MCP configurations
Orchestrator 1.2k tok ·
mrpilot01/everything-claude-code
Complete Claude Code configuration collection - agents, skills, hooks, commands, rules, MCPs. Battle-tested configs from an Anthropic hackathon winner.
Orchestrator 1.2k tok ·