zaffnet/whetstone
My macOS setup as a chezmoi repo, a Copier template for Python projects, and the skills and hooks I use with Claude Code, Codex, and Cursor.
ARCHETYPE
Fort Knox
Deny lists, pre-tool hooks, sandboxing. Nothing touches prod without a signature.
GUARDRAILS
4/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · Sandbox or ask-first rules · details
Copy this rig
# review before running: this installs third-party code
$ npx degit zaffnet/whetstone/home/dot_claude ./rig-whetstone # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit zaffnet/whetstone/skills/a-philosophy-of-software-design .claude/skills/a-philosophy-of-software-design $ npx degit zaffnet/whetstone/skills/address-pr-comments-sequential .claude/skills/address-pr-comments-sequential $ npx degit zaffnet/whetstone/skills/clean-architecture .claude/skills/clean-architecture $ npx degit zaffnet/whetstone/skills/clean-code .claude/skills/clean-code $ npx degit zaffnet/whetstone/skills/deep-pr-review .claude/skills/deep-pr-review $ npx degit zaffnet/whetstone/skills/designing-data-intensive-applications .claude/skills/designing-data-intensive-applications $ npx degit zaffnet/whetstone/skills/domain-driven-design .claude/skills/domain-driven-design $ npx degit zaffnet/whetstone/skills/implementing-domain-driven-design .claude/skills/implementing-domain-driven-design $ npx degit zaffnet/whetstone/skills/prose-honesty .claude/skills/prose-honesty $ npx degit zaffnet/whetstone/skills/simplify-english .claude/skills/simplify-english $ npx degit zaffnet/whetstone/skills/sync-machine-config-to-repo .claude/skills/sync-machine-config-to-repo $ npx degit zaffnet/whetstone/skills/teach-me .claude/skills/teach-me $ npx degit zaffnet/whetstone/skills/writing-whip .claude/skills/writing-whip
$ curl -fsSL --create-dirs -o .claude/agents/code-honesty-auditor.md https://raw.githubusercontent.com/zaffnet/whetstone/main/template/project/.claude/agents/code-honesty-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/prose-honesty-auditor.md https://raw.githubusercontent.com/zaffnet/whetstone/main/template/project/.claude/agents/prose-honesty-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/async-safety-reviewer.md https://raw.githubusercontent.com/zaffnet/whetstone/main/agents/async-safety-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/code-honesty-auditor.md https://raw.githubusercontent.com/zaffnet/whetstone/main/agents/code-honesty-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/consumer-agnostic-client-reviewer.md https://raw.githubusercontent.com/zaffnet/whetstone/main/agents/consumer-agnostic-client-reviewer.md $ curl -fsSL --create-dirs -o .claude/agents/deceptive-test-hunter.md https://raw.githubusercontent.com/zaffnet/whetstone/main/agents/deceptive-test-hunter.md $ curl -fsSL --create-dirs -o .claude/agents/prose-honesty-auditor.md https://raw.githubusercontent.com/zaffnet/whetstone/main/agents/prose-honesty-auditor.md $ curl -fsSL --create-dirs -o .claude/agents/variant-extensibility-reviewer.md https://raw.githubusercontent.com/zaffnet/whetstone/main/agents/variant-extensibility-reviewer.md
Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash|Grep",
"hooks": [
{
"type": "command",
"command": "graphify hook-guard search"
}
]
},
{
"matcher": "Read|Glob",
"hooks": [
{
"type": "command",
"command": "graphify hook-guard read"
}
]
},
{
"matcher": "*",
"hooks": [
{
"type": "command",
"command": "~/.config/iterm2/cc-status"
}
]
}
]
}
} Skills (13)
a-philosophy-of-software-designaddress-pr-comments-sequentialclean-architectureclean-codedeep-pr-reviewdesigning-data-intensive-applicationsdomain-driven-designimplementing-domain-driven-designprose-honestysimplify-englishsync-machine-config-to-repoteach-mewriting-whip
Subagents (8)
| code-honesty-auditor | — |
| prose-honesty-auditor | — |
| async-safety-reviewer | Reviews changed Python for async-safety defects in an asyncio stack (FastAPI, asyncpg, httpx AsyncClient, SQLModel AsyncSession). Use after changing any .py file in the project's Python packages. Repo |
| code-honesty-auditor model: sonnet | Judges every sentence and clause of the comments, docstrings, and checker suppressions a diff adds against a high bar of usefulness to a later reader. Use before handing a turn back. Reports each part |
| consumer-agnostic-client-reviewer | Reviews client libraries (thin wrappers over upstream APIs) and their design docs for consumer coupling: assumptions about who calls them. Use after changing any client source or client design doc. Re |
| deceptive-test-hunter | Audits test changes for deceptive or redundant tests. Use after writing or changing any *_test.py file. Reports tests that only assert their own mock's canned value or that re-check what ruff, mypy, o |
| prose-honesty-auditor model: sonnet | Judges every sentence and clause of the prose a diff adds to markdown, text, and HTML files -- READMEs, design docs, ADRs -- against a high bar of usefulness to a later reader. Use before handing a tu |
| variant-extensibility-reviewer | Reviews a stack built around a registry of variants (job types, executors, plugins, discriminated unions) for whether a new variant can be added without core surgery. Use after changing any registry, |
Hooks (20)
| event | matcher | runs |
|---|---|---|
| PreToolUse | Bash|Grep | graphify hook-guard search |
| PreToolUse | Read|Glob | graphify hook-guard read |
| PreToolUse | * | ~/.config/iterm2/cc-status |
| PostToolUse | * | ~/.config/iterm2/cc-status |
| SessionStart | * | if [ -n "$CLAUDE_ENV_FILE" ] && [ -f "$CLAUDE_PROJECT_DIR/.venv/bin/activate" ]; then printf 'export VIRTUAL_ENV="%s/.venv"\nexport PATH="%s/.venv/bin:$PATH"\n' "$CLAUDE_PROJECT_DIR" "$CLAUDE_PROJECT_DIR" >> "$CLAUDE_ENV_FILE"; fi |
| SessionStart | * | ~/.config/iterm2/cc-status |
| Notification | permission_prompt | afplay /System/Library/Sounds/Glass.aiff |
| Notification | elicitation_dialog | afplay /System/Library/Sounds/Glass.aiff |
| Notification | idle_prompt | afplay /System/Library/Sounds/Glass.aiff |
| Notification | * | ~/.config/iterm2/cc-status |
| Stop | * | bash "$HOME/.agents/hooks/typecheck.sh" |
| Stop | * | afplay /System/Library/Sounds/Funk.aiff |
| Stop | * | ~/.config/iterm2/cc-status |
| StopFailure | * | afplay /System/Library/Sounds/Sosumi.aiff |
| StopFailure | * | ~/.config/iterm2/cc-status |
| PermissionRequest | * | ~/.config/iterm2/cc-status |
| SessionEnd | * | ~/.config/iterm2/cc-status |
| SubagentStop | * | ~/.config/iterm2/cc-status |
| UserPromptSubmit | * | ~/.config/iterm2/cc-status |
| Stop | * | bash "$CLAUDE_PROJECT_DIR/.claude/hooks/typecheck.sh" |
Plugins (6)
github@claude-plugins-officialpyright-lsp@claude-plugins-officialwhetstone-hooks@whetstonewhetstone-skills@whetstonewhetstone-reviewers@whetstoneevals@ai-evals-course
Similar rigs
claude-code-best/claude-code
原汁原昧 Claude Code 可运行,可构建, 可调试版; 生产级工程化, 企业级可靠性; 安全无毒, 内存泄露修复
Pragmatist 5.8k tok ·
Anyesh/skillprobe
Automated end-to-end testing for AI agent skills(agentskills.io). Launches Claude Code and Cursor as subprocesses, runs scenarios in real workspaces, and asserts what the model actually does.
Minimalist 54 tok ·
JuanJo24S/claude-develop-skills
Skills and a git-guard hook for Claude Code and OpenCode: branch and PR workflow, secrets out of the code, clean code. Docs in Spanish and English.
Minimalist 292 tok ·
techygarg/lattice
Install engineering discipline into any AI coding assistant. Composable skills for design, implementation, review, and team standards. Better process, not just better prompts.
Skill Collector 2.5k tok ·