~ / rigs / wintermeyer / heinzel

wintermeyer/heinzel

A ruleset that turns AI coding assistants (e.g. Claude Code) into disciplined Linux, FreeBSD & macOS sysadmins. Manages servers via SSH and localhost with safety guardrails, checklists, and team support. Named after the Heinzelmännchen — he

↗ GitHub ★ 96 MIT updated today project Claude Code
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~5.7k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit wintermeyer/heinzel/.claude ./rig-heinzel  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit wintermeyer/heinzel/.claude/skills/heinzel-email .claude/skills/heinzel-email
$ npx degit wintermeyer/heinzel/.claude/skills/heinzel-fleet-audit .claude/skills/heinzel-fleet-audit
$ npx degit wintermeyer/heinzel/.claude/skills/heinzel-housekeeping .claude/skills/heinzel-housekeeping
$ npx degit wintermeyer/heinzel/.claude/skills/heinzel-macos-cleanup .claude/skills/heinzel-macos-cleanup
$ npx degit wintermeyer/heinzel/.claude/skills/heinzel-security .claude/skills/heinzel-security

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(halt)",
      "Bash(halt *)",
      "Bash(poweroff)",
      "Bash(poweroff *)",
      "Bash(mkfs*)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$CLAUDE_PROJECT_DIR/.claude/hooks/guard-taboos.sh\""
          }
        ]
      }
    ]
  }
}

Skills (5)

Hooks (3)

eventmatcherruns
SessionStartstartupbash "$CLAUDE_PROJECT_DIR/.claude/hooks/check-updates.sh"
SessionStart*mkdir -p -m 700 "$HOME/.cache/heinzel"
PreToolUseBashbash "$CLAUDE_PROJECT_DIR/.claude/hooks/guard-taboos.sh"

Permissions

deny (5)
Bash(halt)
Bash(halt *)
Bash(poweroff)
Bash(poweroff *)
Bash(mkfs*)
ask (0)
—
allow (0)
—

Similar rigs

copied ✓