y-miyazaki/config
A repository of initial settings around the editor
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code $ claude mcp add context7 -- npx -y @upstash/context7-mcp@4.1.1 $ claude mcp add fetch -- uvx --with 'mcp>=1.28,<2' mcp-server-fetch==2026.8.18 $ claude mcp add codebase-memory-mcp -- codebase-memory-mcp $ npx degit y-miyazaki/config/.claude ./rig-config # inspect, then merge into .claude/
MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ claude mcp add context7 -- npx -y @upstash/context7-mcp@4.1.1 $ claude mcp add fetch -- uvx --with 'mcp>=1.28,<2' mcp-server-fetch==2026.8.18 $ claude mcp add codebase-memory-mcp -- codebase-memory-mcp
$ npx degit y-miyazaki/config/.agents/skills/agent-skills-review .claude/skills/agent-skills-review $ npx degit y-miyazaki/config/.agents/skills/ci-sweeper .claude/skills/ci-sweeper $ npx degit y-miyazaki/config/.agents/skills/docs-creator .claude/skills/docs-creator $ npx degit y-miyazaki/config/.agents/skills/docs-updater .claude/skills/docs-updater $ npx degit y-miyazaki/config/.agents/skills/github-actions-review .claude/skills/github-actions-review $ npx degit y-miyazaki/config/.agents/skills/github-actions-validation .claude/skills/github-actions-validation $ npx degit y-miyazaki/config/.agents/skills/github-issue-autofix .claude/skills/github-issue-autofix $ npx degit y-miyazaki/config/.agents/skills/github-issue-triage .claude/skills/github-issue-triage $ npx degit y-miyazaki/config/.agents/skills/github-pr-body .claude/skills/github-pr-body $ npx degit y-miyazaki/config/.agents/skills/github-pr-revise .claude/skills/github-pr-revise $ npx degit y-miyazaki/config/.agents/skills/go-review .claude/skills/go-review $ npx degit y-miyazaki/config/.agents/skills/go-validation .claude/skills/go-validation $ npx degit y-miyazaki/config/.agents/skills/instructions-review .claude/skills/instructions-review $ npx degit y-miyazaki/config/.agents/skills/loop-verifier .claude/skills/loop-verifier $ npx degit y-miyazaki/config/.agents/skills/markdown-validation .claude/skills/markdown-validation $ npx degit y-miyazaki/config/.agents/skills/refactor .claude/skills/refactor $ npx degit y-miyazaki/config/.agents/skills/shell-script-review .claude/skills/shell-script-review $ npx degit y-miyazaki/config/.agents/skills/shell-script-validation .claude/skills/shell-script-validation $ npx degit y-miyazaki/config/.agents/skills/tech-debt .claude/skills/tech-debt $ npx degit y-miyazaki/config/.apm/packages/terraform/.apm/skills/terraform-review .claude/skills/terraform-review $ npx degit y-miyazaki/config/.apm/packages/terraform/.apm/skills/terraform-validation .claude/skills/terraform-validation
$ curl -fsSL --create-dirs -o .claude/agents/test-engineer.md https://raw.githubusercontent.com/y-miyazaki/config/main/.claude/agents/test-engineer.md Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"permissions": {
"deny": [
"Bash(actionlint *)",
"Bash(apm *)",
"Bash(bundle install *)",
"Bash(cargo install *)",
"Bash(composer install *)",
"Bash(curl *)",
"Bash(ghalint *)",
"Bash(golangci-lint *)",
"Bash(gofmt *)",
"Bash(go get *)",
"Bash(go mod download *)",
"Bash(markdown-link-check *)",
"Bash(markdownlint-cli2 *)",
"Bash(mix deps.get *)",
"Bash(npm install *)",
"Bash(pip install *)",
"Bash(pnpm install *)",
"Bash(poetry install *)",
"Bash(rm -rf *)",
"Bash(shellcheck *)",
"Bash(shfmt *)",
"Bash(sudo *)",
"Bash(wget *)",
"Bash(yarn *)",
"Bash(zizmor *)",
"Read(**/credentials/**)",
"Read(**/*.crt)",
"Read(**/*.key)",
"Read(**/*.p12)",
"Read(**/*.pem)",
"Read(**/*.pfx)",
"Read(**/*.tfstate)",
"Read(**/*.tfstate.*)",
"Read(**/*.tfbackend)",
"Read(**/.env.*.local)",
"Read(**/.env.local)",
"Read(./.astro/**)",
"Read(./.env)",
"Read(./.env.*)",
"Read(./.next/**)",
"Read(./.nuxt/**)",
"Read(./.svelte-kit/**)",
"Read(./.yarn/**)",
"Read(./env/common/tmp/**)",
"Read(./secrets/**)",
"Read(./temp/**)",
"Read(./tmp/**)",
"Read(~/.aws/credentials)",
"Read(~/.azure/**)",
"Read(~/.config/gcloud/**)",
"Read(~/.docker/config.json)",
"Read(~/.helm/**)",
"Read(~/.kube/config)",
"Read(~/.ssh/id_*)",
"Read(~/.terraform.d/credentials.tfrc.json)",
"Write(**/credentials/**)",
"Write(**/*.crt)",
"Write(**/*.key)",
"Write(**/*.p12)",
"Write(**/*.pem)",
"Write(**/*.pfx)",
"Write(**/*.tfstate)",
"Write(**/*.tfstate.*)",
"Write(**/*.tfbackend)",
"Write(./.env)",
"Write(./.env.*)",
"Write(./secrets/**)",
"Write(~/**)"
],
"ask": [
"Bash(git branch -D *)",
"Bash(git checkout *)",
"Bash(git clean -f *)",
"Bash(git commit *)",
"Bash(git push *)",
"Bash(git rebase *)",
"Bash(git reset --hard *)",
"Bash(npm publish *)",
"Write(.claude/settings.json)",
"Write(.editorconfig)",
"Write(.eslintrc*)",
"Write(.github/workflows/**)",
"Write(.gitleaks.toml)",
"Write(.golangci.yaml)",
"Write(.prettierrc*)",
"Write(AGENTS.md)",
"Write(CLAUDE.md)",
"Write(docker-compose*.yml)",
"Write(Dockerfile)",
"Write(go.mod)",
"Write(jest.config.*)",
"Write(Makefile)",
"Write(mise.toml)",
"Write(package.json)",
"Write(renovate.json)",
"Write(terraform.*.tfvars)",
"Write(tsconfig.json)"
]
}
} MCP servers (4)
| server | source | est. tokens |
|---|---|---|
| Context7 | npm | 1.2k |
| mcp · "fetch" | pypi | 2.5k |
| github | local / custom | 2.5k |
| codebase-memory-mcp | binary | 2.5k |
Skills (21)
agent-skills-reviewci-sweeperdocs-creatordocs-updatergithub-actions-reviewgithub-actions-validationgithub-issue-autofixgithub-issue-triagegithub-pr-bodygithub-pr-revisego-reviewgo-validationinstructions-reviewloop-verifiermarkdown-validationrefactorshell-script-reviewshell-script-validationtech-debtterraform-reviewterraform-validation
Subagents (1)
| test-engineer | >- |
Hooks (9)
| event | matcher | runs |
|---|---|---|
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/common-hooks-claude/scripts/actionlint.sh" |
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/common-hooks-claude/scripts/ghalint.sh" |
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/common-hooks-claude/scripts/zizmor.sh" |
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/common-hooks-claude/scripts/gitleaks.sh" |
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/common-hooks-claude/scripts/markdown_link_check.sh" |
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/common-hooks-claude/scripts/markdownlint_cli2.sh" |
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/go-hooks-claude/scripts/golangci_lint.sh" |
| Stop | * | "${CLAUDE_PROJECT_DIR}/.claude/hooks/shell-script-hooks-claude/scripts/shellcheck.sh" |
| PostToolUse | Write | "${CLAUDE_PROJECT_DIR}/.claude/hooks/shell-script-hooks-claude/scripts/shfmt.sh" |
Cursor rules (9)
agent-skillsbatsgithub-actions-workflowgo-testgoinstructionsmarkdownshell-scriptterraform
Permissions
deny (68)
Bash(actionlint *)
Bash(apm *)
Bash(bundle install *)
Bash(cargo install *)
Bash(composer install *)
Bash(curl *)
Bash(ghalint *)
Bash(golangci-lint *)
Bash(gofmt *)
Bash(go get *)
Bash(go mod download *)
Bash(markdown-link-check *)
Bash(markdownlint-cli2 *)
Bash(mix deps.get *)
Bash(npm install *)
Bash(pip install *)
Bash(pnpm install *)
Bash(poetry install *)
Bash(rm -rf *)
Bash(shellcheck *)
Bash(shfmt *)
Bash(sudo *)
Bash(wget *)
Bash(yarn *)
Bash(zizmor *)
Read(**/credentials/**)
Read(**/*.crt)
Read(**/*.key)
Read(**/*.p12)
Read(**/*.pem)
Read(**/*.pfx)
Read(**/*.tfstate)
Read(**/*.tfstate.*)
Read(**/*.tfbackend)
Read(**/.env.*.local)
Read(**/.env.local)
Read(./.astro/**)
Read(./.env)
Read(./.env.*)
Read(./.next/**)
Read(./.nuxt/**)
Read(./.svelte-kit/**)
Read(./.yarn/**)
Read(./env/common/tmp/**)
Read(./secrets/**)
Read(./temp/**)
Read(./tmp/**)
Read(~/.aws/credentials)
Read(~/.azure/**)
Read(~/.config/gcloud/**)
Read(~/.docker/config.json)
Read(~/.helm/**)
Read(~/.kube/config)
Read(~/.ssh/id_*)
Read(~/.terraform.d/credentials.tfrc.json)
Write(**/credentials/**)
Write(**/*.crt)
Write(**/*.key)
Write(**/*.p12)
Write(**/*.pem)
ask (27)
Bash(git branch -D *)
Bash(git checkout *)
Bash(git clean -f *)
Bash(git commit *)
Bash(git push *)
Bash(git rebase *)
Bash(git reset --hard *)
Bash(npm publish *)
Write(.claude/settings.json)
Write(.editorconfig)
Write(.eslintrc*)
Write(.github/workflows/**)
Write(.gitleaks.toml)
Write(.golangci.yaml)
Write(.prettierrc*)
Write(AGENTS.md)
Write(CLAUDE.md)
Write(docker-compose*.yml)
Write(Dockerfile)
Write(go.mod)
Write(jest.config.*)
Write(Makefile)
Write(mise.toml)
Write(package.json)
Write(renovate.json)
Write(terraform.*.tfvars)
Write(tsconfig.json)
allow (120)
Bash(awk *)
Bash(basename *)
Bash(bash *)
Bash(bats *)
Bash(cat *)
Bash(cd *)
Bash(cmp *)
Bash(command *)
Bash(cut *)
Bash(date *)
Bash(df *)
Bash(diff *)
Bash(dirname *)
Bash(du *)
Bash(echo *)
Bash(env *)
Bash(file *)
Bash(find *)
Bash(gh api *)
Bash(gh issue list)
Bash(gh pr list)
Bash(gh run *)
Bash(gh workflow list)
Bash(git add *)
Bash(git blame *)
Bash(git branch *)
Bash(git diff *)
Bash(git grep *)
Bash(git log *)
Bash(git remote -v *)
Bash(git remote show *)
Bash(git rev-parse *)
Bash(git show *)
Bash(git stash list *)
Bash(git stash show *)
Bash(git status)
Bash(go doc *)
Bash(go env *)
Bash(go list *)
Bash(go test *)
Bash(go tool *)
Bash(go version *)
Bash(grep *)
Bash(head *)
Bash(hostname *)
Bash(id *)
Bash(jq *)
Bash(lean-ctx *)
Bash(*lean-ctx-bin/bin/lean-ctx *)
Bash(npx *lean-ctx*)
Bash(less *)
Bash(ls *)
Bash(mockery *)
Bash(more *)
Bash(npm list *)
Bash(npm run *)
Bash(npm test *)
Bash(npm view *)
Bash(printenv *)
Bash(printf *)
Similar rigs
wasabeef/claude-code-cookbook
A collection of settings to make Claude Code more useful.
YOLO Cowboy 48.2k tok ·
Rene-Kuhm/claude-code-enterprise-config
Enterprise Claude Code configuration: 8 specialised agents, 20 invocable skills, 7 context rules, 6 commands, 8 automated hooks and 19 MCP server integrations, with an installer.
Fort Knox 75.1k tok ·
edbizarro/dotfiles
:skull: dotfiles! managed by GNU stow
Pragmatist 2.9k tok ·
jesseoue/universal-agent-config
One source of truth for AI coding agent configuration and model routing. Generates native configs for OpenCode, omp, Claude Code, Codex, Cursor, Aider, and Goose with OpenRouter, Cloudflare, Vercel, LiteLLM, and Portkey routing.
Minimalist 2.2k tok ·