trupo-zz/claude-code-setup-sample
Sample Claude Code config pack for a fictional app: CLAUDE.md, permissions, a guard hook with tests, 3 skills. AI-assisted. MIT.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details
Copy this rig
# review before running: this installs third-party code $ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github $ claude mcp add fetch -- uvx mcp-server-fetch $ npx degit trupo-zz/claude-code-setup-sample/.claude ./rig-claude-code-setup-sample # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add github -e GITHUB_PERSONAL_ACCESS_<redacted> -- npx -y @modelcontextprotocol/server-github $ claude mcp add fetch -- uvx mcp-server-fetch
$ npx degit trupo-zz/claude-code-setup-sample/.claude/skills/pr-summary .claude/skills/pr-summary $ npx degit trupo-zz/claude-code-setup-sample/.claude/skills/repo-onboarding .claude/skills/repo-onboarding $ npx degit trupo-zz/claude-code-setup-sample/.claude/skills/run-tests .claude/skills/run-tests
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(./.env.*)",
"Read(./**/.env)",
"Read(./**/.env.*)",
"Read(./secrets/**)",
"Bash(rm -rf:*)",
"Bash(rm -r:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git reset --hard:*)"
]
},
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write|MultiEdit|Bash|PowerShell",
"hooks": [
{
"type": "command",
"command": "if [ -f \"$CLAUDE_PROJECT_DIR/.claude/hooks/block-secrets-edit.js\" ]; then node \"$CLAUDE_PROJECT_DIR/.claude/hooks/block-secrets-edit.js\"; rc=$?; if [ $rc -eq 0 ] || [ $rc -eq 2 ]; then exit $rc; fi; echo 'block-secrets-edit hook crashed (ex"
}
]
}
]
}
} MCP servers (2)
| server | source | est. tokens |
|---|---|---|
| GitHub MCP · "github" env: GITHUB_PERSONAL_ACCESS_TOKEN | npm | 18.0k |
| Fetch | pypi | 450 |
Skills (3)
Hooks (1)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Edit|Write|MultiEdit|Bash|PowerShell | if [ -f "$CLAUDE_PROJECT_DIR/.claude/hooks/block-secrets-edit.js" ]; then node "$CLAUDE_PROJECT_DIR/.claude/hooks/block-secrets-edit.js"; rc=$?; if [ $rc -eq 0 ] || [ $rc -eq 2 ]; then exit $rc; fi; echo 'block-secrets-edit hook crashed (ex |
Permissions
deny (10)
Read(./.env)
Read(./.env.*)
Read(./**/.env)
Read(./**/.env.*)
Read(./secrets/**)
Bash(rm -rf:*)
Bash(rm -r:*)
Bash(git push --force:*)
Bash(git push -f:*)
Bash(git reset --hard:*)
ask (0)
—
allow (8)
Bash(git status:*)
Bash(git diff:*)
Bash(git log:*)
Bash(git branch:*)
Bash(git show:*)
Bash(npm test)
Bash(npm run lint)
Bash(npm run build)
Similar rigs
YoungXAI/Dotfiles
Cross-platform (macOS/Linux) dev environment bootstrap: Zsh + Zinit + P10k, Kitty, VSCode/Cursor, Claude Code, 80+ packages — one command setup. | 跨平台开发环境一键部署系统:Shell、编辑器、终端、AI 工具链全套配置,模块化、幂等、无需 root。
YOLO Cowboy 31.1k tok ·
kunko-ai-labs/agent-assurance
Declare what your AI agent may do. Verify it on every edit, PR and release — MCP configs, Claude Code permissions, tool definitions. Deterministic, OWASP-mapped, signed evidence.
YOLO Cowboy 28.5k tok ·
lee-to/ai-workspace
AI Workspace - Give your AI agents memory that spans across projects.
Pragmatist 19.5k tok ·
heyong4725/claude-setup
Claude Code professional setup for Rust development
Pragmatist 19.1k tok ·