~ / rigs / shortcuts / dotfiles

shortcuts/dotfiles

📁 tmux, ghostty, fish, nvim, claude code, aerospace

↗ GitHub ★ 18 no license updated 7d ago personal setup Claude CodeCodex
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~1.6k tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ npx degit shortcuts/dotfiles/.claude ./rig-dotfiles  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit shortcuts/dotfiles/.claude/skills/documentation .claude/skills/documentation
$ npx degit shortcuts/dotfiles/.claude/skills/explain .claude/skills/explain
$ npx degit shortcuts/dotfiles/.claude/skills/no-ai-slop .claude/skills/no-ai-slop
$ npx degit shortcuts/dotfiles/.claude/skills/onboard .claude/skills/onboard
$ npx degit shortcuts/dotfiles/.claude/skills/release-notes .claude/skills/release-notes
$ npx degit shortcuts/dotfiles/.claude/skills/self-review .claude/skills/self-review
$ npx degit shortcuts/dotfiles/.claude/skills/test-audit .claude/skills/test-audit

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(make deploy)",
      "Bash(terraform apply)",
      "Bash(terraform apply *)",
      "Bash(terraform destroy)",
      "Bash(terraform destroy *)"
    ],
    "ask": [
      "Bash(chmod *)",
      "Bash(chmod 777:*)",
      "Bash(chown *)",
      "Bash(docker *)",
      "Bash(eval:*)",
      "Bash(fdisk *)",
      "Bash(gcloud *)",
      "Bash(git clean -fd:*)",
      "Bash(git reset *)",
      "Bash(git rebase *)",
      "Bash(kubectl *)",
      "Bash(mkfs *)",
      "Bash(npm publish*)",
      "Bash(pnpm publish*)",
      "Bash(rmdir *)",
      "Bash(shred *)",
      "Bash(sudo:*)",
      "Bash(unlink *)",
      "Bash(wget *)",
      "Bash(yarn publish*)",
      "Read(**/*.key)",
      "Read(**/*.pem)",
      "Read(**/*credential*)",
      "Read(**/*secret*)",
      "Read(**/.env)",
      "Read(**/.env.*)",
      "Read(~/.aws/**)",
      "Read(~/.azure/**)",
      "Read(~/.ssh/**)",
      "Bash(cat *.key)",
      "Bash(cat *.pem)",
      "Bash(cat *credential*)",
      "Bash(cat *secret*)",
      "Bash(cat .env)",
      "Bash(cat .env.*)",
      "Bash(cat ~/.aws/*)",
      "Bash(cat ~/.azure/*)",
      "Bash(cat ~/.ssh/*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "rtk hook claude"
          }
        ]
      },
      {
        "matcher": "Grep|Glob|Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.local/bin/codebase-memory-mcp"
          }
        ]
      }
    ]
  }
}

Skills (7)

Hooks (8)

eventmatcherruns
PreToolUseBashrtk hook claude
PreToolUseGrep|Glob|Bash~/.local/bin/codebase-memory-mcp
SessionStartstartup~/.local/bin/codebase-memory-mcp
SessionStartresume~/.local/bin/codebase-memory-mcp
SessionStartclear~/.local/bin/codebase-memory-mcp
SessionStartcompact~/.local/bin/codebase-memory-mcp
PostToolUseRead~/.local/bin/codebase-memory-mcp
SubagentStart*~/.local/bin/codebase-memory-mcp

Plugins (10)

caveman@cavemanlua-lsp@claude-plugins-officialclangd-lsp@claude-plugins-officialfrontend-design@claude-plugins-officialponytail@ponytailgopls-lsp@claude-plugins-officialmattpocock-skills@claude-plugins-officialpyright-lsp@claude-plugins-officialinterfaces@interfacestmux-agent-sidebar@hiroppy

Permissions

deny (5)
Bash(make deploy)
Bash(terraform apply)
Bash(terraform apply *)
Bash(terraform destroy)
Bash(terraform destroy *)
ask (38)
Bash(chmod *)
Bash(chmod 777:*)
Bash(chown *)
Bash(docker *)
Bash(eval:*)
Bash(fdisk *)
Bash(gcloud *)
Bash(git clean -fd:*)
Bash(git reset *)
Bash(git rebase *)
Bash(kubectl *)
Bash(mkfs *)
Bash(npm publish*)
Bash(pnpm publish*)
Bash(rmdir *)
Bash(shred *)
Bash(sudo:*)
Bash(unlink *)
Bash(wget *)
Bash(yarn publish*)
Read(**/*.key)
Read(**/*.pem)
Read(**/*credential*)
Read(**/*secret*)
Read(**/.env)
Read(**/.env.*)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.ssh/**)
Bash(cat *.key)
Bash(cat *.pem)
Bash(cat *credential*)
Bash(cat *secret*)
Bash(cat .env)
Bash(cat .env.*)
Bash(cat ~/.aws/*)
Bash(cat ~/.azure/*)
Bash(cat ~/.ssh/*)
allow (1)
Bash(./gradlew *)

Similar rigs

copied ✓