sardonyx0827/dotfiles
Personal dotfiles: Zsh / Neovim / tmux / WezTerm unified with Rosé Pine, a cross-platform installer, CI-tested hooks, and agent configs for Claude Code, Codex, and Gemini CLI
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ claude mcp add playwright -- npx -y @executeautomation/playwright-mcp-server $ claude mcp add --transport http github https://api.githubcopilot.com/mcp/ -H 'Authorization: YOUR_VALUE' $ claude mcp add context7 -- npx -y @upstash/context7-mcp $ npx degit sardonyx0827/dotfiles/.claude ./rig-dotfiles # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add playwright -- npx -y @executeautomation/playwright-mcp-server $ claude mcp add --transport http github https://api.githubcopilot.com/mcp/ -H 'Authorization: YOUR_VALUE' $ claude mcp add context7 -- npx -y @upstash/context7-mcp
$ npx degit sardonyx0827/dotfiles/.claude/skills/backend-patterns .claude/skills/backend-patterns $ npx degit sardonyx0827/dotfiles/.claude/skills/clickhouse-io .claude/skills/clickhouse-io $ npx degit sardonyx0827/dotfiles/.claude/skills/codex-consultation .claude/skills/codex-consultation $ npx degit sardonyx0827/dotfiles/.claude/skills/codex-image-gen .claude/skills/codex-image-gen $ npx degit sardonyx0827/dotfiles/.claude/skills/debugging-protocol .claude/skills/debugging-protocol $ npx degit sardonyx0827/dotfiles/.claude/skills/docker-patterns .claude/skills/docker-patterns $ npx degit sardonyx0827/dotfiles/.claude/skills/eval-harness .claude/skills/eval-harness $ npx degit sardonyx0827/dotfiles/.claude/skills/frontend-patterns .claude/skills/frontend-patterns $ npx degit sardonyx0827/dotfiles/.claude/skills/github-actions-ci .claude/skills/github-actions-ci $ npx degit sardonyx0827/dotfiles/.claude/skills/golang-patterns .claude/skills/golang-patterns $ npx degit sardonyx0827/dotfiles/.claude/skills/golang-testing .claude/skills/golang-testing $ npx degit sardonyx0827/dotfiles/.claude/skills/iterative-retrieval .claude/skills/iterative-retrieval $ npx degit sardonyx0827/dotfiles/.claude/skills/migration-playbook .claude/skills/migration-playbook $ npx degit sardonyx0827/dotfiles/.claude/skills/postgres-patterns .claude/skills/postgres-patterns $ npx degit sardonyx0827/dotfiles/.claude/skills/project-guidelines-example .claude/skills/project-guidelines-example $ npx degit sardonyx0827/dotfiles/.claude/skills/python-scripting-patterns .claude/skills/python-scripting-patterns $ npx degit sardonyx0827/dotfiles/.claude/skills/release-workflow .claude/skills/release-workflow $ npx degit sardonyx0827/dotfiles/.claude/skills/request-harness .claude/skills/request-harness $ npx degit sardonyx0827/dotfiles/.claude/skills/security-review .claude/skills/security-review $ npx degit sardonyx0827/dotfiles/.claude/skills/session-report .claude/skills/session-report $ npx degit sardonyx0827/dotfiles/.claude/skills/shell-scripting-patterns .claude/skills/shell-scripting-patterns $ npx degit sardonyx0827/dotfiles/.claude/skills/subagent-prompt-design .claude/skills/subagent-prompt-design $ npx degit sardonyx0827/dotfiles/.claude/skills/tdd-workflow .claude/skills/tdd-workflow $ npx degit sardonyx0827/dotfiles/.claude/skills/typescript-testing .claude/skills/typescript-testing $ npx degit sardonyx0827/dotfiles/.claude/skills/verification-loop .claude/skills/verification-loop
$ curl -fsSL --create-dirs -o .claude/agents/architect.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/architect.md $ curl -fsSL --create-dirs -o .claude/agents/build-error-resolver.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/build-error-resolver.md $ curl -fsSL --create-dirs -o .claude/agents/code-reviewer.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/code-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/codex-delegator.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/codex-delegator.md $ curl -fsSL --create-dirs -o .claude/agents/database-reviewer.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/database-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/doc-updater.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/doc-updater.md $ curl -fsSL --create-dirs -o .claude/agents/e2e-runner.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/e2e-runner.md $ curl -fsSL --create-dirs -o .claude/agents/go-build-resolver.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/go-build-resolver.md $ curl -fsSL --create-dirs -o .claude/agents/go-reviewer.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/go-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/planner.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/planner.md $ curl -fsSL --create-dirs -o .claude/agents/refactor-cleaner.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/refactor-cleaner.md $ curl -fsSL --create-dirs -o .claude/agents/request-worker.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/request-worker.md $ curl -fsSL --create-dirs -o .claude/agents/security-reviewer.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/security-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/tdd-guide.md https://raw.githubusercontent.com/sardonyx0827/dotfiles/main/.claude/agents/tdd-guide.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(shutdown:*)",
"Bash(reboot:*)",
"Bash(sudo:*)",
"Bash(su:*)",
"Bash(doas:*)",
"Bash(pkexec:*)",
"Bash(rm -rf:*)",
"Bash(rm -fr:*)",
"Bash(rm -r -f:*)",
"Bash(rm -f -r:*)",
"Bash(rm -r:*)",
"Bash(rm -R:*)",
"Bash(rm -Rf:*)",
"Bash(rm -fR:*)",
"Bash(rm --recursive:*)",
"Bash(rm --no-preserve-root:*)",
"Bash(dd:*)",
"Bash(shred:*)",
"Bash(mkfs:*)",
"Bash(mkfs.ext2:*)",
"Bash(mkfs.ext3:*)",
"Bash(mkfs.ext4:*)",
"Bash(mkfs.xfs:*)",
"Bash(mkfs.btrfs:*)",
"Bash(mkfs.vfat:*)",
"Read(//**/id_rsa*)",
"Read(//**/id_ed25519*)",
"Read(//**/id_ecdsa*)",
"Read(//**/*.key)",
"Read(//**/*.pem)",
"Read(//**/*.token)",
"Read(//**/.env)",
"Read(//**/.env.*)",
"Read(//**/.ssh/**)",
"Read(//**/.aws/**)",
"Read(//**/secrets/**)",
"Edit(//**/id_rsa*)",
"Edit(//**/id_ed25519*)",
"Edit(//**/id_ecdsa*)",
"Edit(//**/*.key)",
"Edit(//**/*.pem)",
"Edit(//**/*.token)",
"Edit(//**/.env)",
"Edit(//**/.env.*)",
"Edit(//**/.ssh/**)",
"Edit(//**/.aws/**)",
"Edit(//**/secrets/**)",
"Edit(//**/.git/config)",
"Read(//**/.envrc)",
"Read(//**/.git-credentials)",
"Read(//**/.zsh_secrets)",
"Read(~/.claude.json)",
"Read(~/.codex/auth.json)",
"Read(~/.config/gh/hosts.yml)",
"Read(~/.npmrc)",
"Read(~/.netrc)",
"Read(~/.pypirc)",
"Edit(//**/.envrc)",
"Edit(//**/.git-credentials)",
"Edit(//**/.zsh_secrets)",
"Edit(~/.claude.json)",
"Edit(~/.codex/auth.json)",
"Edit(~/.config/gh/hosts.yml)",
"Edit(~/.npmrc)",
"Edit(~/.netrc)",
"Edit(~/.pypirc)",
"Bash(env)",
"Bash(env -*)",
"Bash(printenv)",
"Bash(printenv:*)",
"Bash(export)",
"Bash(export -p:*)",
"Bash(set)",
"Bash(declare)",
"Bash(declare -*)",
"Bash(typeset)",
"Bash(typeset -*)",
"Bash(curl:*)",
"Bash(wget:*)",
"Bash(nc:*)"
],
"ask": [
"Bash(git push:*)",
"Edit(//**/.claude/mods/**)",
"Edit(//**/.claude/settings.json)",
"mcp__serena__replace_symbol_body",
"mcp__serena__replace_content",
"mcp__serena__replace_in_files",
"mcp__serena__insert_after_symbol",
"mcp__serena__insert_before_symbol",
"mcp__serena__rename_symbol",
"mcp__serena__safe_delete_symbol",
"mcp__serena__replace_lines",
"mcp__serena__delete_lines",
"mcp__serena__insert_at_line",
"mcp__serena__create_text_file",
"mcp__serena__execute_shell_command"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "bash ~/.claude/hooks/bash-review-launcher.sh"
},
{
"type": "command",
"command": "bash ~/.claude/hooks/git-push-review.sh"
}
]
}
]
}
} MCP servers (3)
| server | source | est. tokens |
|---|---|---|
| @executeautomation/playwright-mcp-server · "playwright" | npm | 2.5k |
| GitHub MCP · "github" | remote · remote | 18.0k |
| Context7 | npm | 1.2k |
Skills (25)
backend-patternsclickhouse-iocodex-consultationcodex-image-gendebugging-protocoldocker-patternseval-harnessfrontend-patternsgithub-actions-cigolang-patternsgolang-testingiterative-retrievalmigration-playbookpostgres-patternsproject-guidelines-examplepython-scripting-patternsrelease-workflowrequest-harnesssecurity-reviewsession-reportshell-scripting-patternssubagent-prompt-designtdd-workflowtypescript-testingverification-loop
Subagents (14)
| architect model: opus | Software architecture specialist for system design, scalability, and technical decision-making. Use for system-level design before a new feature or a large refactor, and for architectural decisions. |
| build-error-resolver model: sonnet | Build and TypeScript error resolution specialist. Use when a build fails or type errors are mechanical to clear. Fixes build/type errors only with minimal diffs, no architectural edits. Focuses on get |
| code-reviewer model: sonnet | Expert code review specialist for quality, security, and maintainability. Use before a commit or PR. |
| codex-delegator model: sonnet | >- |
| database-reviewer model: sonnet | PostgreSQL database specialist for query optimization, schema design, security, and performance. Use when writing SQL, creating migrations, designing schemas, or troubleshooting database performance. |
| doc-updater model: sonnet | Documentation and codemap specialist. Use for updating codemaps and documentation. Backs the /update-codemaps and /update-docs commands; generates docs/CODEMAPS/*, updates READMEs and guides. |
| e2e-runner model: sonnet | End-to-end testing specialist using Vercel Agent Browser (preferred) with Playwright fallback. Use for generating, maintaining, and running E2E tests. Manages test journeys, quarantines flaky tests, u |
| go-build-resolver model: sonnet | Go build, vet, and compilation error resolution specialist. Fixes build errors, go vet issues, and linter warnings with minimal changes. Use when Go builds fail. |
| go-reviewer model: sonnet | Expert Go code reviewer specializing in idiomatic Go, concurrency patterns, error handling, and performance. Use in place of code-reviewer when the change is Go code. |
| planner model: opus | Expert planning specialist for complex features and refactoring. Use before writing code for a new feature or a refactor spanning more than a couple of files. |
| refactor-cleaner model: opus | Dead code cleanup and consolidation specialist. Use for removing unused code, duplicates, and refactoring. Runs analysis tools (knip, depcheck, ts-prune) to identify dead code and safely removes it. |
| request-worker model: sonnet | General-purpose chore executor for a single docs/requests ticket (code, visual materials, research, writing). Use when the request-harness skill processes multiple independent tickets in parallel. Inp |
| security-reviewer model: sonnet | Security vulnerability detection and remediation specialist. Use before a commit or PR that touches user input, authentication, API endpoints, secrets, payments, or file uploads, and after dependency |
| tdd-guide model: sonnet | Test-Driven Development specialist enforcing write-tests-first methodology. Use when writing new features, fixing bugs, or refactoring code test-first. Verifies coverage against the project's threshol |
Hooks (4)
| event | matcher | runs |
|---|---|---|
| PostToolUse | Write|Edit|MultiEdit | bash ~/.claude/hooks/format-then-lint.sh |
| PreToolUse | Bash | bash ~/.claude/hooks/bash-review-launcher.sh |
| PreToolUse | Bash | bash ~/.claude/hooks/git-push-review.sh |
| Stop | * | bash ~/.claude/hooks/stop-audit.sh |
Slash commands (21)
/architect/auto-improve/build-fix/checkpoint/db-review/e2e/eval/go-build/go-review/go-test/learn/orchestrate/plan/refactor-clean/requests-watch/requests/tdd/test-coverage/update-codemaps/update-docs/verify
Plugins (3)
document-skills@anthropic-agent-skillscode-review@claude-plugins-officialcodex@openai-codex
Permissions
deny (96)
Bash(shutdown:*)
Bash(reboot:*)
Bash(sudo:*)
Bash(su:*)
Bash(doas:*)
Bash(pkexec:*)
Bash(rm -rf:*)
Bash(rm -fr:*)
Bash(rm -r -f:*)
Bash(rm -f -r:*)
Bash(rm -r:*)
Bash(rm -R:*)
Bash(rm -Rf:*)
Bash(rm -fR:*)
Bash(rm --recursive:*)
Bash(rm --no-preserve-root:*)
Bash(dd:*)
Bash(shred:*)
Bash(mkfs:*)
Bash(mkfs.ext2:*)
Bash(mkfs.ext3:*)
Bash(mkfs.ext4:*)
Bash(mkfs.xfs:*)
Bash(mkfs.btrfs:*)
Bash(mkfs.vfat:*)
Read(//**/id_rsa*)
Read(//**/id_ed25519*)
Read(//**/id_ecdsa*)
Read(//**/*.key)
Read(//**/*.pem)
Read(//**/*.token)
Read(//**/.env)
Read(//**/.env.*)
Read(//**/.ssh/**)
Read(//**/.aws/**)
Read(//**/secrets/**)
Edit(//**/id_rsa*)
Edit(//**/id_ed25519*)
Edit(//**/id_ecdsa*)
Edit(//**/*.key)
Edit(//**/*.pem)
Edit(//**/*.token)
Edit(//**/.env)
Edit(//**/.env.*)
Edit(//**/.ssh/**)
Edit(//**/.aws/**)
Edit(//**/secrets/**)
Edit(//**/.git/config)
Read(//**/.envrc)
Read(//**/.git-credentials)
Read(//**/.zsh_secrets)
Read(~/.claude.json)
Read(~/.codex/auth.json)
Read(~/.config/gh/hosts.yml)
Read(~/.npmrc)
Read(~/.netrc)
Read(~/.pypirc)
Edit(//**/.envrc)
Edit(//**/.git-credentials)
Edit(//**/.zsh_secrets)
ask (15)
Bash(git push:*)
Edit(//**/.claude/mods/**)
Edit(//**/.claude/settings.json)
mcp__serena__replace_symbol_body
mcp__serena__replace_content
mcp__serena__replace_in_files
mcp__serena__insert_after_symbol
mcp__serena__insert_before_symbol
mcp__serena__rename_symbol
mcp__serena__safe_delete_symbol
mcp__serena__replace_lines
mcp__serena__delete_lines
mcp__serena__insert_at_line
mcp__serena__create_text_file
mcp__serena__execute_shell_command
allow (96)
Read
Edit
Write
Glob
Grep
WebSearch
WebFetch
Agent
TaskCreate
TaskUpdate
TaskList
TaskGet
Bash(tmux ls:*)
Bash(tmux list-sessions:*)
Bash(tmux list-windows:*)
Bash(tmux list-panes:*)
Bash(tmux has-session:*)
Bash(tmux display-message:*)
Bash(tmux show-options:*)
Bash(tmux capture-pane:*)
Bash(ls:*)
Bash(sed:*)
Bash(awk:*)
Bash(sort:*)
Bash(uniq:*)
Bash(diff:*)
Bash(echo:*)
Bash(printf:*)
Bash(pwd:*)
Bash(cp:*)
Bash(mv:*)
Bash(cat:*)
Bash(find:*)
Bash(grep:*)
Bash(rg:*)
Bash(tree:*)
Bash(head:*)
Bash(tail:*)
Bash(wc:*)
Bash(cut:*)
Bash(tr:*)
Bash(touch:*)
Bash(ln:*)
Bash(realpath:*)
Bash(basename:*)
Bash(dirname:*)
Bash(xargs:*)
Bash(tee:*)
Bash(date:*)
Bash(sleep:*)
Bash(uname:*)
Bash(git:*)
Bash(which:*)
Bash(whereis:*)
Bash(jq:*)
Bash(gh:*)
Bash(next:*)
Bash(npx:*)
Bash(pnpm:*)
Bash(yarn:*)
Similar rigs
ndhananj/codex-agent-setup
A set up agent frameworks based on "affaan/everything-claude-code"
Orchestrator 2.2k tok ·
WorldFlowAI/everything-claude-code
Claude Code toolkit - agents, commands, skills, rules, and hooks for productive AI-assisted development
Orchestrator 1.5k tok ·
HABUBUSS/everything-claude-code
Discover production-ready Claude Code configs: agents, skills, hooks, commands, rules, and MCP setups from an Anthropic hackathon winner.
Orchestrator 1.5k tok ·
OsamaA140/agent-trials
Prove an agent does its job before you trust it: employee templates, deterministic pass^k trials, zero-token safety hooks, token-lean Claude Code config.
Orchestrator 1.5k tok ·