~ / rigs / yktsnet / dotfiles-public

yktsnet/dotfiles-public

A two-phase development lifecycle for AI-agent collaboration: spec-driven bootstrap, guarantee-driven maintenance — on Nix.

↗ GitHub ★ 1 MIT updated today personal setup Claude Code
share on X
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
CONTEXT TAX · EVERY TURN
~2.1k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
4/5
Blocks destructive commands · Protects secrets · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ npx degit yktsnet/dotfiles-public/.claude ./rig-dotfiles-public  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit yktsnet/dotfiles-public/.claude/skills/consolidate-rules .claude/skills/consolidate-rules
$ npx degit yktsnet/dotfiles-public/.claude/skills/guarantee-audit .claude/skills/guarantee-audit
$ npx degit yktsnet/dotfiles-public/.claude/skills/jp-writing .claude/skills/jp-writing
$ npx degit yktsnet/dotfiles-public/.claude/skills/local-issue .claude/skills/local-issue
$ npx degit yktsnet/dotfiles-public/.claude/skills/mermaid-diagram .claude/skills/mermaid-diagram
$ npx degit yktsnet/dotfiles-public/.claude/skills/module-dev .claude/skills/module-dev
$ npx degit yktsnet/dotfiles-public/.claude/skills/mvp-docs .claude/skills/mvp-docs
$ npx degit yktsnet/dotfiles-public/.claude/skills/nix-tool-install .claude/skills/nix-tool-install
$ npx degit yktsnet/dotfiles-public/.claude/skills/pr-workflow .claude/skills/pr-workflow
$ npx degit yktsnet/dotfiles-public/.claude/skills/readme-i18n .claude/skills/readme-i18n
$ npx degit yktsnet/dotfiles-public/.claude/skills/repo-about .claude/skills/repo-about
$ npx degit yktsnet/dotfiles-public/.claude/skills/repo-publish .claude/skills/repo-publish
$ npx degit yktsnet/dotfiles-public/.claude/skills/repo-readme .claude/skills/repo-readme
$ npx degit yktsnet/dotfiles-public/.claude/skills/repo-standardize .claude/skills/repo-standardize
$ npx degit yktsnet/dotfiles-public/.claude/skills/session-nudge .claude/skills/session-nudge
$ npx degit yktsnet/dotfiles-public/.claude/skills/skill-dev .claude/skills/skill-dev
$ npx degit yktsnet/dotfiles-public/.claude/skills/sops-secrets .claude/skills/sops-secrets
$ curl -fsSL --create-dirs -o .claude/agents/issue-verifier.md https://raw.githubusercontent.com/yktsnet/dotfiles-public/main/.claude/agents/issue-verifier.md
$ curl -fsSL --create-dirs -o .claude/agents/jp-proofreader.md https://raw.githubusercontent.com/yktsnet/dotfiles-public/main/.claude/agents/jp-proofreader.md
$ curl -fsSL --create-dirs -o .claude/agents/screen-operator.md https://raw.githubusercontent.com/yktsnet/dotfiles-public/main/.claude/agents/screen-operator.md

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "permissions": {
    "deny": [
      "Bash(ssh *)",
      "Bash(nixos-rebuild *)",
      "Bash(darwin-rebuild *)",
      "Bash(home-manager switch *)",
      "Bash(nh *)",
      "Bash(nix flake update *)",
      "Edit(flake.lock)",
      "Edit(secrets-agents/**)",
      "Read(secrets-agents/**)"
    ]
  },
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-non-nix-install.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-live-claude-config-edit.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/route-browser-to-crit.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/no-branch-in-checkout.sh"
          }
        ]
      },
      {
        "matcher": "Edit|Write|Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/gate-memory-write.sh"
          }
        ]
      },
      {
        "matcher": "Write|Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-new-skill-md.sh"
          }
        ]
      },
      {
        "matcher": "Edit|Write",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-live-claude-config-edit.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-project-scoped-memory.sh"
          },
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/backup-secret-json.sh"
          }
        ]
      }
    ]
  }
}

Skills (17)

Subagents (3)

issue-verifier
model: claude-opus-5-5
実行者のブランチを、Issue ファイルだけを基準に確かめる。確認の項目・保証節・対象と範囲を自分で動かして判定し、合否と証拠を返す。pr-workflow の手順7のあとに実行者が呼ぶ。
jp-proofreader
model: claude-sonnet-5-5
日本語の Markdown 文書の表現だけを校正する。書き手とは別のコンテキストで規範を当てるための役。Stop フックが会話の外で自動的に回すので、会話からは呼ばない。Issue / PR の本文とコード中のコメントは対象外。
screen-operator
model: claude-sonnet-5-5
立ち上がっている画面をヘッドレスのブラウザで操作し、渡された道順のとおりに進めて、各手順で見えたものと画面写真を返す。合否は判定しない。pr-workflow で、画面に出る変更を user に見せる前に実行者が呼ぶ。

Hooks (13)

eventmatcherruns
PreToolUseBash$CLAUDE_PROJECT_DIR/.claude/hooks/block-non-nix-install.sh
PreToolUseBash$CLAUDE_PROJECT_DIR/.claude/hooks/block-live-claude-config-edit.sh
PreToolUseBash$CLAUDE_PROJECT_DIR/.claude/hooks/route-browser-to-crit.sh
PreToolUseBash$CLAUDE_PROJECT_DIR/.claude/hooks/no-branch-in-checkout.sh
PreToolUseEdit|Write|Bash$CLAUDE_PROJECT_DIR/.claude/hooks/gate-memory-write.sh
PreToolUseWrite|Bash$CLAUDE_PROJECT_DIR/.claude/hooks/block-new-skill-md.sh
PreToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/block-live-claude-config-edit.sh
PreToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/block-project-scoped-memory.sh
PreToolUseEdit|Write$CLAUDE_PROJECT_DIR/.claude/hooks/backup-secret-json.sh
PostToolUseEdit|Write|NotebookEdit$CLAUDE_PROJECT_DIR/.claude/hooks/static-check.sh
SessionStart*$CLAUDE_PROJECT_DIR/.claude/hooks/opus-scope-and-concision.sh
Stop*$CLAUDE_PROJECT_DIR/.claude/hooks/jp-proofread-stop.sh
UserPromptSubmit*$CLAUDE_PROJECT_DIR/.claude/hooks/jp-proofread-notice.sh

Permissions

deny (9)
Bash(ssh *)
Bash(nixos-rebuild *)
Bash(darwin-rebuild *)
Bash(home-manager switch *)
Bash(nh *)
Bash(nix flake update *)
Edit(flake.lock)
Edit(secrets-agents/**)
Read(secrets-agents/**)
ask (0)
—
allow (5)
Bash(nix flake check *)
Bash(nix flake check)
Bash(nix fmt *)
Bash(nix eval *)
Bash(zsh -n *)

Similar rigs

copied ✓