~ / rigs / vinta / hal-9000

vinta/hal-9000

Opinionated AI coding agent and dev environment automation for macOS

↗ GitHub ★ 138 mit updated 5d ago personal setup Claude CodeCodex Claude plugin
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~4.2k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
5/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add --transport http openaiDeveloperDocs https://developers.openai.com/mcp
$ npx degit vinta/hal-9000/.claude ./rig-hal-9000  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add --transport http openaiDeveloperDocs https://developers.openai.com/mcp
$ npx degit vinta/hal-9000/.claude/skills/publish-plugins .claude/skills/publish-plugins
$ npx degit vinta/hal-9000/.claude/skills/update-playbooks .claude/skills/update-playbooks
$ npx degit vinta/hal-9000/skills/audit-claude-settings .claude/skills/audit-claude-settings
$ npx degit vinta/hal-9000/skills/best-practices .claude/skills/best-practices
$ npx degit vinta/hal-9000/skills/blindspot .claude/skills/blindspot
$ npx degit vinta/hal-9000/skills/commit .claude/skills/commit
$ npx degit vinta/hal-9000/skills/difference .claude/skills/difference
$ npx degit vinta/hal-9000/skills/fuck-over-engineering .claude/skills/fuck-over-engineering
$ npx degit vinta/hal-9000/skills/pr .claude/skills/pr
$ npx degit vinta/hal-9000/skills/refactor-agents-md .claude/skills/refactor-agents-md
$ npx degit vinta/hal-9000/skills/refactor-claude-md .claude/skills/refactor-claude-md
$ npx degit vinta/hal-9000/skills/refactor-memory .claude/skills/refactor-memory
$ npx degit vinta/hal-9000/skills/refactor-skill .claude/skills/refactor-skill
$ npx degit vinta/hal-9000/skills/simple-english .claude/skills/simple-english
$ npx degit vinta/hal-9000/skills/write-like-me .claude/skills/write-like-me

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Read(~/.aws/**)",
      "Read(~/.config/**)",
      "Read(~/.docker/**)",
      "Read(~/.dropbox/**)",
      "Read(~/.gnupg/**)",
      "Read(~/.gsutil/**)",
      "Read(~/.kube/**)",
      "Read(~/.npmrc)",
      "Read(~/.orbstack/**)",
      "Read(~/.pypirc)",
      "Read(~/.ssh/**)",
      "Read(~/*_history)",
      "Read(~/Library/**)",
      "Edit(~/Library/**)",
      "Read(~/Dropbox/**)",
      "Edit(~/Dropbox/**)",
      "Read(//etc/**)",
      "Edit(//etc/**)",
      "Bash(git -c *)",
      "Bash(git --config-env*)",
      "Bash(git --git-dir*)",
      "Bash(git remote add *)",
      "Bash(git remote set-url *)",
      "Bash(git config remote.*)",
      "Bash(git config * remote.*)",
      "Bash(gh repo delete *)",
      "Bash(su *)",
      "Bash(sudo *)",
      "Bash(passwd *)",
      "Bash(env *)",
      "Bash(printenv *)",
      "Bash(history *)",
      "Bash(fc *)",
      "Bash(eval *)",
      "Bash(exec *)",
      "Bash(rsync *)",
      "Bash(sftp *)",
      "Bash(telnet *)",
      "Bash(socat *)",
      "Bash(nc *)",
      "Bash(ncat *)",
      "Bash(netcat *)",
      "Bash(nmap *)",
      "Bash(chflags *)",
      "Bash(xattr *)",
      "Bash(diskutil *)",
      "Bash(mkfs *)",
      "Bash(security *)",
      "Bash(defaults *)",
      "Bash(launchctl *)",
      "Bash(osascript *)",
      "Bash(dscl *)",
      "Bash(networksetup *)",
      "Bash(scutil *)",
      "Bash(systemsetup *)",
      "Bash(pmset *)",
      "Bash(crontab *)"
    ],
    "ask": [
      "Bash(open *)",
      "Bash(chmod *)",
      "Bash(chown *)",
      "Bash(kill *)",
      "Bash(killall *)",
      "Bash(pkill *)",
      "Bash(curl *-d *)",
      "Bash(curl *--data*)",
      "Bash(curl *--json *)",
      "Bash(curl *-F *)",
      "Bash(curl *--form *)",
      "Bash(curl *-T *)",
      "Bash(curl *--upload-file *)",
      "Bash(curl *-H *)",
      "Bash(curl *--header *)",
      "Bash(git push *)",
      "Bash(gh repo create *)",
      "Bash(gh repo rename *)",
      "Bash(gh *--admin*)",
      "Bash(gh api *-X *)",
      "Bash(gh api *--method *)",
      "Bash(brew install *)",
      "Bash(pip install *)",
      "Bash(uv pip install *)",
      "Bash(uv tool install *)",
      "Bash(uv add *)",
      "Bash(npm install *)",
      "Bash(npm i *)",
      "Bash(yarn add *)",
      "Bash(pnpm add *)",
      "Bash(bun add *)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "python3 ~/.claude/hooks/guard-bash-paths.py"
          },
          {
            "type": "command",
            "command": "python3 ~/.claude/hooks/guard-network-egress.py"
          }
        ]
      }
    ]
  }
}

MCP servers (1)

serversourceest. tokens
OpenAI Developer Docs · "openaiDeveloperDocs" remote · remote 1.0k

Skills (15)

Hooks (7)

eventmatcherruns
PostToolUseEditbin/hal sync 2>/dev/null || true
PostToolUseEditmake lint-python >&2 || exit 2
PostToolUseEditmake lint-ansible >&2 || exit 2
PostToolUseWritemake lint-python >&2 || exit 2
PostToolUseWritemake lint-ansible >&2 || exit 2
PreToolUseBashpython3 ~/.claude/hooks/guard-bash-paths.py
PreToolUseBashpython3 ~/.claude/hooks/guard-network-egress.py

Plugins (7)

cc-plugin-you-should-know@builtinhal-skills@hal-9000hal-output-styles@hal-9000hal-grammar-check@hal-9000hal-session-auto-rename@hal-9000hal-voice@hal-9000mattpocock-skills@mattpocock

Permissions

deny (57)
Read(~/.aws/**)
Read(~/.config/**)
Read(~/.docker/**)
Read(~/.dropbox/**)
Read(~/.gnupg/**)
Read(~/.gsutil/**)
Read(~/.kube/**)
Read(~/.npmrc)
Read(~/.orbstack/**)
Read(~/.pypirc)
Read(~/.ssh/**)
Read(~/*_history)
Read(~/Library/**)
Edit(~/Library/**)
Read(~/Dropbox/**)
Edit(~/Dropbox/**)
Read(//etc/**)
Edit(//etc/**)
Bash(git -c *)
Bash(git --config-env*)
Bash(git --git-dir*)
Bash(git remote add *)
Bash(git remote set-url *)
Bash(git config remote.*)
Bash(git config * remote.*)
Bash(gh repo delete *)
Bash(su *)
Bash(sudo *)
Bash(passwd *)
Bash(env *)
Bash(printenv *)
Bash(history *)
Bash(fc *)
Bash(eval *)
Bash(exec *)
Bash(rsync *)
Bash(sftp *)
Bash(telnet *)
Bash(socat *)
Bash(nc *)
Bash(ncat *)
Bash(netcat *)
Bash(nmap *)
Bash(chflags *)
Bash(xattr *)
Bash(diskutil *)
Bash(mkfs *)
Bash(security *)
Bash(defaults *)
Bash(launchctl *)
Bash(osascript *)
Bash(dscl *)
Bash(networksetup *)
Bash(scutil *)
Bash(systemsetup *)
Bash(pmset *)
Bash(crontab *)
ask (31)
Bash(open *)
Bash(chmod *)
Bash(chown *)
Bash(kill *)
Bash(killall *)
Bash(pkill *)
Bash(curl *-d *)
Bash(curl *--data*)
Bash(curl *--json *)
Bash(curl *-F *)
Bash(curl *--form *)
Bash(curl *-T *)
Bash(curl *--upload-file *)
Bash(curl *-H *)
Bash(curl *--header *)
Bash(git push *)
Bash(gh repo create *)
Bash(gh repo rename *)
Bash(gh *--admin*)
Bash(gh api *-X *)
Bash(gh api *--method *)
Bash(brew install *)
Bash(pip install *)
Bash(uv pip install *)
Bash(uv tool install *)
Bash(uv add *)
Bash(npm install *)
Bash(npm i *)
Bash(yarn add *)
Bash(pnpm add *)
Bash(bun add *)
allow (14)
Read(~/Projects/**)
Edit(~/Projects/**)
Bash(git branch *)
Bash(git stash *)
Bash(git add *)
Bash(git mv *)
Bash(git rm *)
Bash(git apply *)
Bash(git commit *)
Bash(git restore *)
Bash(gh repo view *)
Bash(find *)
Bash(mkdir *)
WebSearch

Similar rigs

copied ✓