~ / rigs / trailofbits / claude-code-devcontainer

trailofbits/claude-code-devcontainer

Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.

↗ GitHub ★ 950 Apache-2.0 updated 1mo ago project Claude Code
share on X
ARCHETYPE
Minimalist
Lean instructions, few tools, tiny context tax. Lets the model think.
CONTEXT TAX · EVERY TURN
~0 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
1/5
No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit trailofbits/claude-code-devcontainer/.claude ./rig-claude-code-devcontainer  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(.devcontainer/**)"
    ]
  }
}

Permissions

deny (1)
Read(.devcontainer/**)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓