shortcuts/dotfiles
📁 tmux, ghostty, fish, nvim, claude code, aerospace
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit shortcuts/dotfiles/.claude ./rig-dotfiles # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit shortcuts/dotfiles/.claude/skills/documentation .claude/skills/documentation $ npx degit shortcuts/dotfiles/.claude/skills/explain .claude/skills/explain $ npx degit shortcuts/dotfiles/.claude/skills/no-ai-slop .claude/skills/no-ai-slop $ npx degit shortcuts/dotfiles/.claude/skills/onboard .claude/skills/onboard $ npx degit shortcuts/dotfiles/.claude/skills/release-notes .claude/skills/release-notes $ npx degit shortcuts/dotfiles/.claude/skills/self-review .claude/skills/self-review $ npx degit shortcuts/dotfiles/.claude/skills/test-audit .claude/skills/test-audit
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(make deploy)",
"Bash(terraform apply)",
"Bash(terraform apply *)",
"Bash(terraform destroy)",
"Bash(terraform destroy *)"
],
"ask": [
"Bash(chmod *)",
"Bash(chmod 777:*)",
"Bash(chown *)",
"Bash(docker *)",
"Bash(eval:*)",
"Bash(fdisk *)",
"Bash(gcloud *)",
"Bash(git clean -fd:*)",
"Bash(git reset *)",
"Bash(git rebase *)",
"Bash(kubectl *)",
"Bash(mkfs *)",
"Bash(npm publish*)",
"Bash(pnpm publish*)",
"Bash(rmdir *)",
"Bash(shred *)",
"Bash(sudo:*)",
"Bash(unlink *)",
"Bash(wget *)",
"Bash(yarn publish*)",
"Read(**/*.key)",
"Read(**/*.pem)",
"Read(**/*credential*)",
"Read(**/*secret*)",
"Read(**/.env)",
"Read(**/.env.*)",
"Read(~/.aws/**)",
"Read(~/.azure/**)",
"Read(~/.ssh/**)",
"Bash(cat *.key)",
"Bash(cat *.pem)",
"Bash(cat *credential*)",
"Bash(cat *secret*)",
"Bash(cat .env)",
"Bash(cat .env.*)",
"Bash(cat ~/.aws/*)",
"Bash(cat ~/.azure/*)",
"Bash(cat ~/.ssh/*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "rtk hook claude"
}
]
},
{
"matcher": "Grep|Glob|Bash",
"hooks": [
{
"type": "command",
"command": "~/.local/bin/codebase-memory-mcp"
}
]
}
]
}
} Skills (7)
Hooks (8)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | rtk hook claude |
| PreToolUse | Grep|Glob|Bash | ~/.local/bin/codebase-memory-mcp |
| SessionStart | startup | ~/.local/bin/codebase-memory-mcp |
| SessionStart | resume | ~/.local/bin/codebase-memory-mcp |
| SessionStart | clear | ~/.local/bin/codebase-memory-mcp |
| SessionStart | compact | ~/.local/bin/codebase-memory-mcp |
| PostToolUse | Read | ~/.local/bin/codebase-memory-mcp |
| SubagentStart | * | ~/.local/bin/codebase-memory-mcp |
Plugins (10)
caveman@cavemanlua-lsp@claude-plugins-officialclangd-lsp@claude-plugins-officialfrontend-design@claude-plugins-officialponytail@ponytailgopls-lsp@claude-plugins-officialmattpocock-skills@claude-plugins-officialpyright-lsp@claude-plugins-officialinterfaces@interfacestmux-agent-sidebar@hiroppy
Permissions
deny (5)
Bash(make deploy)
Bash(terraform apply)
Bash(terraform apply *)
Bash(terraform destroy)
Bash(terraform destroy *)
ask (38)
Bash(chmod *)
Bash(chmod 777:*)
Bash(chown *)
Bash(docker *)
Bash(eval:*)
Bash(fdisk *)
Bash(gcloud *)
Bash(git clean -fd:*)
Bash(git reset *)
Bash(git rebase *)
Bash(kubectl *)
Bash(mkfs *)
Bash(npm publish*)
Bash(pnpm publish*)
Bash(rmdir *)
Bash(shred *)
Bash(sudo:*)
Bash(unlink *)
Bash(wget *)
Bash(yarn publish*)
Read(**/*.key)
Read(**/*.pem)
Read(**/*credential*)
Read(**/*secret*)
Read(**/.env)
Read(**/.env.*)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.ssh/**)
Bash(cat *.key)
Bash(cat *.pem)
Bash(cat *credential*)
Bash(cat *secret*)
Bash(cat .env)
Bash(cat .env.*)
Bash(cat ~/.aws/*)
Bash(cat ~/.azure/*)
Bash(cat ~/.ssh/*)
allow (1)
Bash(./gradlew *)
Similar rigs
RAIT-09/obsidian-agent-client
Bring AI agents into Obsidian via Agent Client Protocol (ACP), such as Claude Code, Codex and Gemini CLI.
Pragmatist 4.8k tok ·
kotek-7/dotfiles
My dotfiles managed using chezmoi
YOLO Cowboy 738 tok ·
michaelbarton/dotfiles
Various configuration files
Minimalist 276 tok ·
scotthuang/agent-knock-knock
Control local Codex and Claude Code from OpenClaw through shared tmux terminals, with seamless human-agent handoff.
Minimalist 389 tok ·