runnithan/claudex-setup
Portable Claude Code and Codex configuration: slash commands, subagents, hooks, skills, and a transcript-to-lessons pipeline. Installable as a plugin.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit runnithan/claudex-setup/.claude ./rig-claudex-setup # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit runnithan/claudex-setup/skills/claude-md-improver .claude/skills/claude-md-improver $ npx degit runnithan/claudex-setup/skills/frontend-design .claude/skills/frontend-design $ npx degit runnithan/claudex-setup/skills/session-handoff .claude/skills/session-handoff
$ curl -fsSL --create-dirs -o .claude/agents/backend-dev.md https://raw.githubusercontent.com/runnithan/claudex-setup/main/agents/backend-dev.md $ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/runnithan/claudex-setup/main/agents/code-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/code-simplifier.md https://raw.githubusercontent.com/runnithan/claudex-setup/main/agents/code-simplifier.md $ curl -fsSL --create-dirs -o .claude/agents/frontend-dev.md https://raw.githubusercontent.com/runnithan/claudex-setup/main/agents/frontend-dev.md $ curl -fsSL --create-dirs -o .claude/agents/pr-test-analyzer.md https://raw.githubusercontent.com/runnithan/claudex-setup/main/agents/pr-test-analyzer.md $ curl -fsSL --create-dirs -o .claude/agents/qa.md https://raw.githubusercontent.com/runnithan/claudex-setup/main/agents/qa.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(backend/.env)",
"Edit(backend/.env)",
"Read(frontend/.env)",
"Edit(frontend/.env)",
"Read(firebase-service-account.json)",
"Edit(firebase-service-account.json)",
"Read(**/.env)",
"Edit(**/.env)",
"Read(**/.env.*)",
"Edit(**/.env.*)",
"Read(**/*.pem)",
"Edit(**/*.pem)",
"Read(**/*.key)",
"Edit(**/*.key)",
"Read(**/*.p12)",
"Edit(**/*.p12)",
"Read(**/id_rsa)",
"Edit(**/id_rsa)",
"Read(**/.ssh/**)",
"Edit(**/.ssh/**)",
"Read(**/.aws/**)",
"Edit(**/.aws/**)",
"Read(**/*service-account*.json)",
"Edit(**/*service-account*.json)",
"Bash(cat *.env*)",
"Bash(cat *.pem)",
"Bash(cat *.key)",
"Bash(cat *.p12)",
"Bash(cat *id_rsa*)",
"Bash(cat *service-account*.json)",
"Bash(cat *.ssh/*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git push --delete:*)",
"Bash(git push --mirror:*)",
"Bash(git push --prune:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git push --delete:*)",
"Bash(git push --mirror:*)",
"Bash(git push --prune:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write|MultiEdit",
"hooks": [
{
"type": "command",
"command": "python3 .claude/hooks/security_reminder_hook.py"
}
]
},
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "python3 .claude/hooks/block-destructive-push.py"
},
{
"type": "command",
"command": "for f in \"$CLAUDE_PROJECT_DIR/.claude/hooks/block-destructive-push.py\" .claude/hooks/block-destructive-push.py \"$CLAUDE_PROJECT_DIR/hooks/block-destructive-push.py\" hooks/block-destructive-push.py; do [ -f \"$f\" ] && exec python3 \"$f\"; done;"
}
]
}
]
}
} Skills (3)
Subagents (6)
| backend-dev model: sonnet | Backend engineer. Handles code changes, backend tests, database migrations, and commits. Use for any backend-only work. |
| code-reviewer model: opus | Use this agent when you need to review code for adherence to project guidelines, style guides, and best practices. Use when asked, or after completing a multi-file coding task, especially before commi |
| code-simplifier model: opus | | |
| frontend-dev model: sonnet | Frontend engineer. Handles UI code changes, component development, lint/build verification, and commits. Use for any frontend-only work. |
| pr-test-analyzer model: inherit | Use this agent when you need to review a pull request for test coverage quality and completeness. This agent should be invoked after a PR is created or updated to ensure tests adequately cover new fun |
| qa model: sonnet | QA engineer. Runs tests, lint, and build checks. Validates PRs before merge. Reports failures to team lead. Does NOT modify code. |
Hooks (10)
| event | matcher | runs |
|---|---|---|
| SessionStart | * | node .claude/hooks/gsd-check-update.js |
| PreToolUse | Edit|Write|MultiEdit | python3 .claude/hooks/security_reminder_hook.py |
| PreToolUse | Bash | python3 .claude/hooks/block-destructive-push.py |
| PostToolUse | * | node .claude/hooks/gsd-context-monitor.js |
| PostToolUse | Write | bash .claude/hooks/auto-format.sh |
| PostToolUse | Edit | bash .claude/hooks/auto-format.sh |
| Stop | * | printf '{"terminalSequence":"\\u0007"}' |
| Stop | * | .claude/scripts/ralph-stop-hook.sh |
| Notification | * | printf '{"terminalSequence":"\\u0007"}' |
| PreToolUse | Bash | for f in "$CLAUDE_PROJECT_DIR/.claude/hooks/block-destructive-push.py" .claude/hooks/block-destructive-push.py "$CLAUDE_PROJECT_DIR/hooks/block-destructive-push.py" hooks/block-destructive-push.py; do [ -f "$f" ] && exec python3 "$f"; done; |
Slash commands (19)
/cancel-ralph/changelog-claude/changelog-codex/claude-loop/codex-loop/consolidate-lessons/extract-lessons/extract-social-lessons/fact-check/optimise/pr/quiz-me/ralph-help/ralph-loop/review-pr/revise-claude-md/test/ticket/top-tips
Permissions
deny (41)
Read(backend/.env)
Edit(backend/.env)
Read(frontend/.env)
Edit(frontend/.env)
Read(firebase-service-account.json)
Edit(firebase-service-account.json)
Read(**/.env)
Edit(**/.env)
Read(**/.env.*)
Edit(**/.env.*)
Read(**/*.pem)
Edit(**/*.pem)
Read(**/*.key)
Edit(**/*.key)
Read(**/*.p12)
Edit(**/*.p12)
Read(**/id_rsa)
Edit(**/id_rsa)
Read(**/.ssh/**)
Edit(**/.ssh/**)
Read(**/.aws/**)
Edit(**/.aws/**)
Read(**/*service-account*.json)
Edit(**/*service-account*.json)
Bash(cat *.env*)
Bash(cat *.pem)
Bash(cat *.key)
Bash(cat *.p12)
Bash(cat *id_rsa*)
Bash(cat *service-account*.json)
Bash(cat *.ssh/*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git push --delete:*)
Bash(git push --mirror:*)
Bash(git push --prune:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git push --delete:*)
Bash(git push --mirror:*)
Bash(git push --prune:*)
ask (0)
—
allow (29)
Bash(npm run *)
Bash(npx prettier *)
Bash(uv run *)
Bash(git *)
Bash(docker compose *)
Bash(ls *)
Bash(pwd)
Bash(cat *)
Bash(wc *)
Bash(psql:*)
Bash(where:*)
Bash(bun:*)
Bash(claude:*)
Bash(cd:*)
Bash(jq:*)
Bash(test:*)
Bash(python3:*)
Bash(ln:*)
Bash(chmod +x:*)
Bash(npx get-shit-done-cc@latest:*)
WebSearch
WebFetch(domain:github.com)
WebFetch(domain:raw.githubusercontent.com)
WebFetch(domain:developers.openai.com)
mcp__github__create_pull_request
mcp__github__merge_pull_request
mcp__github__update_pull_request_branch
mcp__github__create_branch
mcp__github__pull_request_read
Similar rigs
Rohankundra2009/claude-agents-forge
Build and run production-ready Claude Code agents with full agent specs, including turn limits, permissions, memory, and tool orchestration.
Orchestrator 1.3k tok ·
Mationetap/claude-agents-forge
Production-hardened agent system for Claude Code — uses the full agent spec (maxTurns, permissionMode, disallowedTools, Task() orchestration, memory scopes, MCP integration)
Orchestrator 1.3k tok ·
Iski08/dotclaude
Multi-agent config for Claude Code with specialized agents and templates to speed code review, refactoring, security audits, tech-lead guidance, and UX evaluations across CI pipelines. 🐙
Orchestrator 677 tok ·
sami-abdul/claude-predev-setup
A portable system that bootstraps any Claude Code project with production-grade infrastructure: multi-agent pipelines, skills, rules, hooks, and a full-stack development orchestrator inspired by the FullStack-Agent paper.
Orchestrator 1.3k tok ·