trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code
$ npx degit trailofbits/claude-code-config/.claude ./rig-claude-code-config # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(rm -rf *)",
"Bash(rm -fr *)",
"Bash(sudo *)",
"Bash(mkfs *)",
"Bash(dd *)",
"Bash(wget *|bash*)",
"Bash(wget *| bash*)",
"Bash(git push --force*)",
"Bash(git push *--force*)",
"Bash(git reset --hard*)",
"Edit(~/.bashrc)",
"Edit(~/.zshrc)",
"Edit(~/.ssh/**)",
"Read(~/.ssh/**)",
"Read(~/.gnupg/**)",
"Read(~/.aws/**)",
"Read(~/.azure/**)",
"Read(~/.config/gh/**)",
"Read(~/.git-credentials)",
"Read(~/.docker/config.json)",
"Read(~/.kube/**)",
"Read(~/.npmrc)",
"Read(~/.npm/**)",
"Read(~/.pypirc)",
"Read(~/.gem/credentials)",
"Read(~/Library/Keychains/**)",
"Read(~/Library/Application Support/**/metamask*/**)",
"Read(~/Library/Application Support/**/electrum*/**)",
"Read(~/Library/Application Support/**/exodus*/**)",
"Read(~/Library/Application Support/**/phantom*/**)",
"Read(~/Library/Application Support/**/solflare*/**)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo \"$CMD\" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo \"$CMD\" | grep -"
},
{
"type": "command",
"command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi"
}
]
}
]
}
} Hooks (2)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo "$CMD" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo "$CMD" | grep - |
| PreToolUse | Bash | CMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi |
Slash commands (4)
/trailofbits/config/fix-issue/merge-dependabot/review-pr
Permissions
deny (31)
Bash(rm -rf *)
Bash(rm -fr *)
Bash(sudo *)
Bash(mkfs *)
Bash(dd *)
Bash(wget *|bash*)
Bash(wget *| bash*)
Bash(git push --force*)
Bash(git push *--force*)
Bash(git reset --hard*)
Edit(~/.bashrc)
Edit(~/.zshrc)
Edit(~/.ssh/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.config/gh/**)
Read(~/.git-credentials)
Read(~/.docker/config.json)
Read(~/.kube/**)
Read(~/.npmrc)
Read(~/.npm/**)
Read(~/.pypirc)
Read(~/.gem/credentials)
Read(~/Library/Keychains/**)
Read(~/Library/Application Support/**/metamask*/**)
Read(~/Library/Application Support/**/electrum*/**)
Read(~/Library/Application Support/**/exodus*/**)
Read(~/Library/Application Support/**/phantom*/**)
Read(~/Library/Application Support/**/solflare*/**)
ask (0)
—
allow (0)
—
Similar rigs
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
happier-dev/happier
Web, Desktop & Mobile client and orchestrator for Codex, Claude Code, OpenCode, Pi, Cursor, Grok, Antigravity, Kimi, Augment Code, Qwen, fully end-to-end encrypted
Fort Knox 28.4k tok ·