~ / rigs / trailofbits / claude-code-config

trailofbits/claude-code-config

Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits

↗ GitHub ★ 2,120 no license updated 2mo ago personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit trailofbits/claude-code-config/.claude ./rig-claude-code-config  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(rm -rf *)",
      "Bash(rm -fr *)",
      "Bash(sudo *)",
      "Bash(mkfs *)",
      "Bash(dd *)",
      "Bash(wget *|bash*)",
      "Bash(wget *| bash*)",
      "Bash(git push --force*)",
      "Bash(git push *--force*)",
      "Bash(git reset --hard*)",
      "Edit(~/.bashrc)",
      "Edit(~/.zshrc)",
      "Edit(~/.ssh/**)",
      "Read(~/.ssh/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.aws/**)",
      "Read(~/.azure/**)",
      "Read(~/.config/gh/**)",
      "Read(~/.git-credentials)",
      "Read(~/.docker/config.json)",
      "Read(~/.kube/**)",
      "Read(~/.npmrc)",
      "Read(~/.npm/**)",
      "Read(~/.pypirc)",
      "Read(~/.gem/credentials)",
      "Read(~/Library/Keychains/**)",
      "Read(~/Library/Application Support/**/metamask*/**)",
      "Read(~/Library/Application Support/**/electrum*/**)",
      "Read(~/Library/Application Support/**/exodus*/**)",
      "Read(~/Library/Application Support/**/phantom*/**)",
      "Read(~/Library/Application Support/**/solflare*/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo \"$CMD\" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo \"$CMD\" | grep -"
          },
          {
            "type": "command",
            "command": "CMD=$(jq -r '.tool_input.command'); if echo \"$CMD\" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi"
          }
        ]
      }
    ]
  }
}

Hooks (2)

eventmatcherruns
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qiE '(^|;[[:space:]]*|&&[[:space:]]*|[|][|][[:space:]]*|[|][[:space:]]*)rm[[:space:]]' && echo "$CMD" | grep -qiE '(^|[[:space:]])-[a-zA-Z]*[rR]|--recursive' && echo "$CMD" | grep -
PreToolUseBashCMD=$(jq -r '.tool_input.command'); if echo "$CMD" | grep -qE 'git[[:space:]]+push.*(main|master)'; then echo 'BLOCKED: Use feature branches, not direct push to main' >&2; exit 2; fi

Slash commands (4)

/trailofbits/config/fix-issue/merge-dependabot/review-pr

Permissions

deny (31)
Bash(rm -rf *)
Bash(rm -fr *)
Bash(sudo *)
Bash(mkfs *)
Bash(dd *)
Bash(wget *|bash*)
Bash(wget *| bash*)
Bash(git push --force*)
Bash(git push *--force*)
Bash(git reset --hard*)
Edit(~/.bashrc)
Edit(~/.zshrc)
Edit(~/.ssh/**)
Read(~/.ssh/**)
Read(~/.gnupg/**)
Read(~/.aws/**)
Read(~/.azure/**)
Read(~/.config/gh/**)
Read(~/.git-credentials)
Read(~/.docker/config.json)
Read(~/.kube/**)
Read(~/.npmrc)
Read(~/.npm/**)
Read(~/.pypirc)
Read(~/.gem/credentials)
Read(~/Library/Keychains/**)
Read(~/Library/Application Support/**/metamask*/**)
Read(~/Library/Application Support/**/electrum*/**)
Read(~/Library/Application Support/**/exodus*/**)
Read(~/Library/Application Support/**/phantom*/**)
Read(~/Library/Application Support/**/solflare*/**)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓