Every superpowers-prefixed skill call in ship-feature, init-project, tour, deploy, audit-delta, plugin-advisor and lib/analyze-before-plan now names the vendored skill directly. finishing-a-development-branch is described as the upstream skill this config does not vendor (gitflow finish is the integration path). CLAUDE.global.md Skill routing maps the four non-vendored skills the vendored text still references. settings.json loses the plugin key and its marketplace block; README, USAGE, plugin-advisor and the profile skill describe superpowers as vendored skills, always on, zero plugin cost. CHANGELOG entry with a known residual.
501 lines
24 KiB
JSON
501 lines
24 KiB
JSON
{
|
|
"cleanupPeriodDays": 7,
|
|
"attribution": {
|
|
"commit": "",
|
|
"pr": "",
|
|
"sessionUrl": false
|
|
},
|
|
"env": {
|
|
"ENABLE_STOP_REVIEW": "0"
|
|
},
|
|
"permissions": {
|
|
"allow": [
|
|
"Bash(git status)",
|
|
"Bash(git log*)",
|
|
"Bash(git diff*)",
|
|
"Bash(git branch*)",
|
|
"Bash(git fetch*)",
|
|
"Bash(git pull*)",
|
|
"Bash(git add *)",
|
|
"Bash(git commit*)",
|
|
"Bash(git checkout *)",
|
|
"Bash(git switch *)",
|
|
"Bash(git stash)",
|
|
"Bash(git stash push*)",
|
|
"Bash(git stash list*)",
|
|
"Bash(git stash show*)",
|
|
"Bash(git tag*)",
|
|
"Bash(git show*)",
|
|
"Bash(ls *)",
|
|
"Bash(ls)",
|
|
"Bash(find *)",
|
|
"Bash(cat *)",
|
|
"Bash(head *)",
|
|
"Bash(tail *)",
|
|
"Bash(grep *)",
|
|
"Bash(rg *)",
|
|
"Bash(fd *)",
|
|
"Bash(wc *)",
|
|
"Bash(echo *)",
|
|
"Bash(pwd)",
|
|
"Bash(which *)",
|
|
"Bash(type *)",
|
|
"Bash(whoami)",
|
|
"Bash(uname *)",
|
|
"Bash(mkdir -p *)",
|
|
"Bash(touch *)",
|
|
"Bash(jq *)",
|
|
"Bash(yq *)",
|
|
"Bash(awk *)",
|
|
"Bash(sort *)",
|
|
"Bash(uniq *)",
|
|
"Bash(tr *)",
|
|
"Bash(cut *)",
|
|
"Bash(diff *)",
|
|
"Bash(rtk grep *)",
|
|
"Bash(*/rtk grep *)",
|
|
"Bash(rtk ls)",
|
|
"Bash(rtk ls *)",
|
|
"Bash(*/rtk ls)",
|
|
"Bash(*/rtk ls *)",
|
|
"Bash(rtk cat *)",
|
|
"Bash(*/rtk cat *)",
|
|
"Bash(rtk head *)",
|
|
"Bash(*/rtk head *)",
|
|
"Bash(rtk tail *)",
|
|
"Bash(*/rtk tail *)",
|
|
"Bash(rtk wc *)",
|
|
"Bash(*/rtk wc *)",
|
|
"Bash(rtk diff *)",
|
|
"Bash(*/rtk diff *)",
|
|
"Bash(rtk git status)",
|
|
"Bash(*/rtk git status)",
|
|
"Bash(rtk git log*)",
|
|
"Bash(*/rtk git log*)",
|
|
"Bash(rtk git diff*)",
|
|
"Bash(*/rtk git diff*)",
|
|
"Bash(rtk git show*)",
|
|
"Bash(*/rtk git show*)",
|
|
"Bash(rtk git branch*)",
|
|
"Bash(*/rtk git branch*)",
|
|
"Read(**/*.md)",
|
|
"Read(**/*.txt)",
|
|
"Read(**/*.json)",
|
|
"Read(**/*.yaml)",
|
|
"Read(**/*.yml)",
|
|
"Read(**/*.toml)",
|
|
"Read(**/*.lock)",
|
|
"Read(**/*.gitignore)",
|
|
"Read(**/*.dockerignore)",
|
|
"Read(**/.claudeignore)",
|
|
"Read(**/Makefile)",
|
|
"Read(**/Dockerfile*)",
|
|
"Read(**/docker-compose*)"
|
|
],
|
|
"deny": [
|
|
"Bash(rm -rf *)",
|
|
"Bash(rm -rf /*)",
|
|
"Bash(rm -r *)",
|
|
"Bash(rm -fr *)",
|
|
"Bash(rmdir *)",
|
|
"Bash(git push --force)",
|
|
"Bash(git push --force *)",
|
|
"Bash(git push -f*)",
|
|
"Bash(git push * +*)",
|
|
"Bash(git reset --hard*)",
|
|
"Bash(git clean -fd*)",
|
|
"Bash(sudo rm*)",
|
|
"Bash(sudo chmod*)",
|
|
"Bash(sudo chown*)",
|
|
"Bash(sudo dd*)",
|
|
"Bash(su *)",
|
|
"Bash(chmod 777 *)",
|
|
"Bash(chmod -R 777 *)",
|
|
"Bash(ssh *)",
|
|
"Bash(scp *)",
|
|
"Bash(nc *)",
|
|
"Bash(netcat *)",
|
|
"Bash(crontab *)",
|
|
"Bash(systemctl *)",
|
|
"Bash(service *)",
|
|
"Bash(npm install -g *)",
|
|
"Read(**/.env)",
|
|
"Read(**/.env.*)",
|
|
"Read(**/secrets/**)",
|
|
"Read(**/*.pem)",
|
|
"Read(**/*.key)",
|
|
"Read(**/*.p12)",
|
|
"Read(**/*.pfx)",
|
|
"Read(**/id_rsa*)",
|
|
"Read(**/id_ed25519*)",
|
|
"Read(**/.ssh/**)",
|
|
"Read(**/credentials)",
|
|
"Read(**/credentials.json)",
|
|
"Read(**/.aws/credentials)",
|
|
"Read(**/.azure/**)",
|
|
"Edit(**/.env)",
|
|
"Edit(**/.env.*)",
|
|
"Edit(**/secrets/**)",
|
|
"Edit(**/*.pem)",
|
|
"Edit(**/*.key)",
|
|
"Edit(**/*.p12)",
|
|
"Edit(**/*.pfx)",
|
|
"Edit(**/id_rsa*)",
|
|
"Edit(**/id_ed25519*)",
|
|
"Edit(**/.ssh/**)",
|
|
"Edit(**/credentials)",
|
|
"Edit(**/credentials.json)",
|
|
"Edit(**/.aws/credentials)",
|
|
"Edit(**/.azure/**)",
|
|
"Edit(**/*.lock)",
|
|
"Edit(**/package-lock.json)",
|
|
"Edit(**/pnpm-lock.yaml)",
|
|
"Edit(**/go.sum)",
|
|
"Edit(**/node_modules/**)",
|
|
"Bash(eval *)",
|
|
"Bash(exec *)",
|
|
"Bash(find * -delete*)",
|
|
"Bash(find * -exec rm*)",
|
|
"Bash(find * -execdir rm*)",
|
|
"Bash(find * -exec *)",
|
|
"Bash(find * -execdir *)",
|
|
"Bash(perl -e *)",
|
|
"Bash(ruby -e *)",
|
|
"Bash(cat .env)",
|
|
"Bash(cat .env.*)",
|
|
"Bash(cat */.env)",
|
|
"Bash(cat */.env.*)",
|
|
"Bash(cat */secrets/*)",
|
|
"Bash(cat */*.pem)",
|
|
"Bash(cat */*.key)",
|
|
"Bash(cat */id_rsa*)",
|
|
"Bash(cat */id_ed25519*)",
|
|
"Bash(cat */.aws/credentials)",
|
|
"Bash(head .env)",
|
|
"Bash(head .env.*)",
|
|
"Bash(tail .env)",
|
|
"Bash(tail .env.*)",
|
|
"Bash(less .env)",
|
|
"Bash(less .env.*)",
|
|
"Bash(more .env)",
|
|
"Bash(more .env.*)",
|
|
"Bash(grep * .env)",
|
|
"Bash(grep * .env.*)",
|
|
"Bash(sed * .env*)",
|
|
"Bash(awk * .env*)",
|
|
"Bash(cut * .env*)",
|
|
"Bash(tr * .env*)",
|
|
"Bash(sort * .env*)",
|
|
"Bash(uniq * .env*)",
|
|
"Bash(diff * .env*)",
|
|
"Bash(od * .env*)",
|
|
"Bash(xxd * .env*)",
|
|
"Bash(strings * .env*)",
|
|
"Bash(env)",
|
|
"Bash(printenv)",
|
|
"Bash(printenv *)",
|
|
"Bash(export *)",
|
|
"Bash(cp .env*)",
|
|
"Bash(cp **/.env*)",
|
|
"Bash(cp **/secrets/*)",
|
|
"Bash(mv .env*)",
|
|
"Bash(mv **/.env*)",
|
|
"Bash(mv **/secrets/*)",
|
|
"Bash(git add .env*)",
|
|
"Bash(git add **/.env*)",
|
|
"Bash(cp **/id_rsa*)",
|
|
"Bash(cp **/id_ed25519*)",
|
|
"Bash(cp **/.ssh/*)",
|
|
"Bash(source /dev/stdin)",
|
|
"Bash(xargs * .env*)",
|
|
"Bash(tar * .env*)",
|
|
"Bash(zip * .env*)",
|
|
"Bash(base64 .env*)",
|
|
"Bash(rtk cat *.env*)",
|
|
"Bash(*/rtk cat *.env*)",
|
|
"Bash(rtk grep * .env*)",
|
|
"Bash(*/rtk grep * .env*)",
|
|
"Bash(rtk head *.env*)",
|
|
"Bash(*/rtk head *.env*)",
|
|
"Bash(rtk tail *.env*)",
|
|
"Bash(*/rtk tail *.env*)",
|
|
"Bash(lftp)",
|
|
"Bash(lftp *)",
|
|
"Bash(lftpget *)",
|
|
"Bash(ncftp*)",
|
|
"Bash(sftp *)",
|
|
"Bash(ftp *)",
|
|
"Bash(sitecopy *)",
|
|
"Bash(curl -T *)",
|
|
"Bash(curl * -T *)",
|
|
"Bash(curl * --upload-file *)",
|
|
"Bash(rsync --delete*)",
|
|
"Bash(rsync * --delete*)",
|
|
"Bash(rsync * --del *)",
|
|
"Bash(rsync * --del)",
|
|
"Bash(chmod -R *)",
|
|
"Bash(chown -R *)",
|
|
"Bash(chgrp -R *)",
|
|
"Bash(chmod --recursive *)",
|
|
"Bash(chown --recursive *)",
|
|
"Bash(sudo)",
|
|
"Bash(sudo *)",
|
|
"Bash(doas *)",
|
|
"Bash(pkexec *)",
|
|
"Bash(dd *)",
|
|
"Bash(shred *)",
|
|
"Bash(wipefs *)",
|
|
"Bash(mkfs*)",
|
|
"Bash(fdisk *)",
|
|
"Bash(sfdisk *)",
|
|
"Bash(sgdisk *)",
|
|
"Bash(parted *)",
|
|
"Bash(docker system prune*)",
|
|
"Bash(docker volume rm *)",
|
|
"Bash(docker volume prune*)",
|
|
"Bash(docker compose down -v*)",
|
|
"Bash(docker compose down --volumes*)",
|
|
"Bash(docker compose down * -v*)",
|
|
"Bash(docker compose down * --volumes*)",
|
|
"Bash(docker run --privileged*)",
|
|
"Bash(docker run * --privileged*)",
|
|
"Bash(docker * /var/run/docker.sock*)",
|
|
"Bash(docker run -v /:*)",
|
|
"Bash(docker run * -v /:*)",
|
|
"Bash(git push --delete *)",
|
|
"Bash(git push * --delete *)",
|
|
"Bash(git push --mirror*)",
|
|
"Bash(git push * --mirror*)",
|
|
"Bash(git push * :*)",
|
|
"Bash(git push --force-with-lease*)",
|
|
"Bash(git push * --force-with-lease*)",
|
|
"Bash(git branch -D *)",
|
|
"Bash(git branch --delete --force *)",
|
|
"Bash(git branch -d *)",
|
|
"Bash(git branch --delete *)",
|
|
"Bash(git branch -dr *)",
|
|
"Bash(git branch -rd *)",
|
|
"Bash(git branch -m main*)",
|
|
"Bash(git branch -m develop*)",
|
|
"Bash(git branch -M main*)",
|
|
"Bash(git branch -M develop*)",
|
|
"Bash(git filter-branch*)",
|
|
"Bash(git filter-repo*)",
|
|
"Bash(git reflog expire*)",
|
|
"Bash(git reflog delete*)",
|
|
"Bash(git gc --prune*)",
|
|
"Bash(git update-ref -d *)",
|
|
"Bash(git stash clear)",
|
|
"Bash(git stash drop*)",
|
|
"Bash(git clean -f*)",
|
|
"Bash(git clean -x*)",
|
|
"Bash(git commit --no-verify*)",
|
|
"Bash(git commit * --no-verify*)",
|
|
"Bash(git commit -n *)",
|
|
"Bash(git config core.hooksPath *)",
|
|
"Bash(git config --global core.hooksPath *)",
|
|
"Bash(git -c core.hooksPath=*)",
|
|
"Bash(xargs rm*)",
|
|
"Bash(* xargs rm*)",
|
|
"Bash(* xargs -0 rm*)",
|
|
"Bash(* | bash)",
|
|
"Bash(* | bash -*)",
|
|
"Bash(* | sh)",
|
|
"Bash(* | sh -*)",
|
|
"Bash(* | sudo *)",
|
|
"Bash(chattr *)",
|
|
"Bash(GIT_CONFIG_GLOBAL=*)",
|
|
"Bash(GIT_CONFIG_SYSTEM=*)",
|
|
"Bash(GIT_CONFIG=*)",
|
|
"Bash(env GIT_CONFIG*)",
|
|
"Bash(git config --unset core.hooksPath*)",
|
|
"Bash(git config --unset-all core.hooksPath*)",
|
|
"Bash(git config --local core.hooksPath *)",
|
|
"Bash(git config gitflow.*)",
|
|
"Bash(git config --global gitflow.*)",
|
|
"Bash(git config --local gitflow.*)"
|
|
],
|
|
"ask": [
|
|
"Bash(bash -c *)",
|
|
"Bash(mkfifo *)",
|
|
"Bash(git push *)",
|
|
"Bash(git push)",
|
|
"Bash(brew install *)",
|
|
"Bash(apt install *)",
|
|
"Bash(apt-get install *)",
|
|
"Bash(dnf install *)",
|
|
"Bash(pacman -S *)",
|
|
"WebSearch",
|
|
"WebFetch",
|
|
"Bash(git stash pop*)"
|
|
],
|
|
"defaultMode": "auto",
|
|
"disableBypassPermissionsMode": "disable",
|
|
"additionalDirectories": []
|
|
},
|
|
"model": "claude-fable-5-1[1m]",
|
|
"hooks": {
|
|
"SessionStart": [
|
|
{
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/session-start.sh"
|
|
},
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/unpushed-guard.sh",
|
|
"timeout": 5,
|
|
"statusMessage": "Checking unpushed work..."
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"PreToolUse": [
|
|
{
|
|
"matcher": "Bash",
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/rtk-rewrite.sh"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"Notification": [
|
|
{
|
|
"matcher": "permission_prompt|idle_prompt|agent_needs_input|elicitation_dialog|elicitation_url_dialog",
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/notify-attention.sh",
|
|
"timeout": 5,
|
|
"statusMessage": "Ringing terminal bell..."
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"Stop": [
|
|
{
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/notify-attention.sh",
|
|
"timeout": 5,
|
|
"statusMessage": "Ringing terminal bell..."
|
|
},
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/unpushed-guard.sh",
|
|
"timeout": 5,
|
|
"statusMessage": "Checking unpushed work..."
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"UserPromptSubmit": [
|
|
{
|
|
"hooks": [
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/design-toolchain-reminder.sh",
|
|
"timeout": 5,
|
|
"statusMessage": "Checking design signals..."
|
|
},
|
|
{
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/ctx7-reminder.sh",
|
|
"timeout": 5,
|
|
"statusMessage": "Checking fast-libs..."
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"statusLine": {
|
|
"type": "command",
|
|
"command": "bash ~/.claude/hooks/statusline.sh"
|
|
},
|
|
"enabledPlugins": {
|
|
"example-skills@anthropic-agent-skills": false,
|
|
"ui-ux-pro-max@ui-ux-pro-max-skill": true,
|
|
"security-guidance@claude-code-plugins": true,
|
|
"pr-review-toolkit@claude-code-plugins": false,
|
|
"brightdata-plugin@synced": false
|
|
},
|
|
"extraKnownMarketplaces": {
|
|
"claude-code-plugins": {
|
|
"source": {
|
|
"source": "github",
|
|
"repo": "anthropics/claude-code"
|
|
}
|
|
},
|
|
"ui-ux-pro-max-skill": {
|
|
"source": {
|
|
"source": "github",
|
|
"repo": "nextlevelbuilder/ui-ux-pro-max-skill"
|
|
}
|
|
},
|
|
"anthropic-agent-skills": {
|
|
"source": {
|
|
"source": "github",
|
|
"repo": "anthropics/skills"
|
|
}
|
|
}
|
|
},
|
|
"feedbackDrafts": "off",
|
|
"effortLevel": "xhigh",
|
|
"remoteControlAtStartup": true,
|
|
"inputNeededNotifEnabled": true,
|
|
"skipAutoPermissionPrompt": true,
|
|
"autoMode": {
|
|
"allow": [
|
|
"$defaults",
|
|
"Local dev containers: `docker exec`, `docker run`, `docker compose up`/`exec`/`logs`/`ps` against a container running on this workstation whose name does not carry `prod` or `production` (a local Supabase or Postgres such as `supabase_db_*`) is routine development, not a remote shell into a shared host. Running a SQL file or script that lives in the repo inside it (`psql -f`, migrations, verify scripts) and piping the output through `tail` or `grep` passes. Remote Shell Writes, Production Reads and Sensitive Remote Exec apply only to hosts named as sensitive in Environment or carrying `prod`. A literal `DROP`, `TRUNCATE` or `DELETE` without a predicate typed on the command line stays under Mass Delete.",
|
|
"Project-local node: `node <file>`, `npm run`, `pnpm` or `yarn` scripts, and `npx` or `pnpm exec` of a package declared in the project's manifest or lockfile, with effects inside the current working directory, pass like `awk` or `echo`. `node -e` that computes or edits inside the working directory passes; the soft block on inline interpreters that delete or write outside it still applies."
|
|
],
|
|
"soft_deny": [
|
|
"$defaults",
|
|
"Scope of intent: an instruction clears a SOFT BLOCK for the current turn only. An approval given in an earlier turn is not an approval now, and the same action repeated in a later turn has to be asked for again.",
|
|
"Writing outside the current working directory: `cp`, `mv`, `sed -i`, `rsync`, `tee`, or a shell redirection whose destination resolves outside the cwd. Several sibling projects live under `~/Documents/`, so the realistic failure is writing into the wrong one, where git recovers nothing. Clear only when the user named the destination in this turn.",
|
|
"`rsync` invoked with `--delete`. It removes files at the destination that are absent from the source, with no undo. Clear only against a destination the user named in this turn.",
|
|
"Sending SIGKILL (`kill -9`) or killing processes by name (`killall`, `pkill`). These reach processes outside this session, including the user's editors, shells, dtach sessions and background jobs, and the target is chosen by a pattern, so a typo kills the wrong thing. Clear only when the user named the process in this turn.",
|
|
"Editing more than one file in place in a single command: `sed -i` or `perl -pi` over a glob, or a loop over `git ls-files`. The damage is not loss, since git recovers it, but a diff spanning hundreds of files that nobody reads before committing. `sed -i` on a single named file passes. Clear only when the user asked for the sweep.",
|
|
"Moving or renaming a directory inside the repo (`mv src/api src/api_old`, or any `mv` of a tree). It breaks imports and paths silently, and the breakage surfaces far from the command. Clear only when the user asked for that move.",
|
|
"An inline interpreter or `xargs` that deletes, or that writes outside the current working directory: `python3 -c`, `python -c` or `node -e` calling `rmtree`, `remove`, `unlink` or `truncate`; `xargs` feeding `rm`, `mv` or `dd`. `find ... | xargs rm` is the case that matters, since it routes around the `find * -exec rm` deny rule. Reading, computing, and editing a file inside the working directory pass untouched.",
|
|
"Docker data destruction on this workstation: `docker rm -f` of a container, and `docker run` with a bind mount outside the current working directory or the session temp dir (volume drops, `system prune`, `compose down -v` and `--privileged` are static deny rules and cannot be cleared). Clear only when the user named the container or the mount in this turn.",
|
|
"Discarding uncommitted work: `git checkout -- <path>` or `git checkout .`, `git restore` without `--staged`, `git stash pop` onto a dirty tree, or overwriting a modified tracked file with `cp` or `mv`. Git recovers a committed state, not this. Clear only when the user asked to discard those exact changes in this turn.",
|
|
"Undeclared node packages: `npx <pkg>`, `pnpm dlx` or `yarn dlx` of a package absent from the manifest and lockfile runs code fetched at call time; `npm install <name>` or `pnpm add <name>` adds a dependency the house rule requires naming first. Clear only when the user named the package in this turn.",
|
|
"Publishing to the 21st.dev public catalog: `21st publish`, `publish-theme`, `publish-template`, `publish-gradient`, `publish-ascii`, `submit` and `resubmit` push a component, theme or template from this machine onto a public listing under the user's account; `21st edit`, `delete`, `withdraw`, `remove-from-catalog` and `21st profile set|upload` change or remove what is already published there. Retrieval and generation (`search`, `logo`, `get`, `add`, `generate`, `iterate`) are ordinary design work and pass. Clear only when the user asked to publish or change that specific item in this turn."
|
|
],
|
|
"hard_deny": [
|
|
"$defaults",
|
|
"Secret exfiltration: reading a `.env`, an SSH key, a token or a credentials file, and then sending what it contained outside this machine. That covers an HTTP request body or header, a paste or gist service, a file upload, an email, and a commit or push to any repository. The static deny rules match the reading tools by pattern and cannot see the second half of the chain; read and send are separate steps and may sit several turns apart. No instruction clears this.",
|
|
"Production deployment: running a project's deploy script (`bin/deploy.sh` and its equivalents), any lftp, FTP, SFTP or rsync push to a hosting provider, and any action against a target whose name carries `prod` or `production` as a whole word or name segment. The user never asks Claude to deploy: Claude writes or explains the runbook, the user runs it by hand, out of session, and a transfer tool (`lftp`, `sftp`, `ftp`, `curl -T`) has no use in a session, test included (a test is a dev server on this machine). A green test suite, a finished feature, or a plan step that reads \"deploy\" is not an instruction to deploy. No in-session instruction clears this.",
|
|
"Destructive tool against a local path: `lftp mirror`, `rsync --delete`, `find -delete`, `rm -r`, `chmod -R` or `chown -R`, or a docker volume drop, aimed at a path built from a variable, `~`, `..` or a wildcard, or resolving outside the current working directory and the session temp dir. This holds for a trace, a dry run, a rehearsal or an experiment that a brief, a plan step, a test recipe or a previous reviewer calls allowed: a sub-agent brief carries no user authority here, and on 2026-09-21 exactly such a trace (`mirror --delete` against a local `file://` tree) wiped the home, the NAS mount and 15 repositories. Tracing what such a tool would do is done by reading it. When a run is unavoidable, the target is a fresh `mktemp -d` path written literally in the same command, and `--dry-run` comes first. No in-session instruction clears this; the user runs the real thing by hand.",
|
|
"Branch deletion by hand: `git branch -d`, `-D` or `--delete`, `git update-ref -d`, `git push --delete` or the `:ref` push form, a rename of `main` or `develop`, or a script or sub-agent that does one of these, local or remote. The only sanctioned path is `gitflow.sh finish` or `gitflow.sh delete <branch>`, which refuses `main`/`develop` outright and any branch not merged into develop or main, then removes the `origin/` copy once its own tip passes the same check; `git branch -d` proves nothing once the branch has an auto-pushed upstream, which every branch has since BDR-095. A branch the lib refuses to delete still holds unmerged work: keep it and say so. No brief, plan step or cleanup routine authorizes a hand deletion.",
|
|
"Routing around a guardrail: a command the deny rules or this classifier refused is not run again through a wrapper script, an alias, a heredoc, a Makefile target written for the purpose, an env file, another shell, `make`/`python -c` indirection or another agent. That is the same action one step removed. A refusal ends the attempt: report the exact command and the rule that stopped it, then wait for the user. This binds every sub-agent whatever its brief says: a brief that orders a refused form is wrong, report it, do not comply. The legitimate hermetic test run is `make test` (optionally `suite=<file>`); the export lives in the Makefile, never on the command line.",
|
|
"Disarming the guardrails: removing or weakening an entry in the `deny`, `soft_deny` or `hard_deny` lists of any settings.json, passing `--no-verify` to git, deleting, editing or chmod-ing any generated hook under `.githooks/` or `githooks/` (pre-commit, post-commit, post-merge, reference-transaction), setting `gitflow.protect` or `gitflow.autopush`, setting `disableAllHooks`, or switching `permissions.defaultMode` to `bypassPermissions`. Adding a restriction is fine; removing one is not. When a task is blocked by a guardrail, say so and stop, rather than widening the guardrail to get through. The user maintains these files by hand. No instruction clears this."
|
|
],
|
|
"environment": [
|
|
"$defaults",
|
|
"### Machine-specific (refines any \"None configured\" default above)",
|
|
"**Primary use of Claude Code**: software development on a personal Linux workstation. Single developer, no organization.",
|
|
"**Source control**: self-hosted Gitea at `git.bchanot.fr` (SSH on port 49220). Some checkouts under `/home/bchanot/Documents/` have no remote at all and are local-only.",
|
|
"**Repository visibility**: private. The Gitea instance is self-hosted and not publicly indexed, and a checkout with no remote is local-only. Treat every repo here as private unless its remote points at a public host.",
|
|
"**Trusted repo**: the checkout Claude Code is currently working in, under `/home/bchanot/Documents/`. No single repo is privileged over the others — read the current one, do not assume a previous session's project.",
|
|
"**Trusted internal domains**: `git.bchanot.fr` (self-hosted Gitea). It is the only internal service.",
|
|
"**Default / protected branches**: gitflow. `main` (prod) and `develop` (integration) are protected: a per-repo pre-commit hook refuses code commits on either (exempting `.claude/**` and merges) and Gitea enforces branch protection on both. Neither is ever deleted or renamed: a reference-transaction hook vetoes it at the ref layer, and a working branch is deleted only by `gitflow.sh finish` or `gitflow.sh delete` after an explicit merged-into-develop-or-main check, the `origin/` copy going with it under the same check on its tip. Work lands on `feature/*`, `bugfix/*`, `chore/*`, `release/*`, `hotfix/*`.",
|
|
"**Secrets management**: `~/.claude/.env` is the single source of truth and lives outside every git tree; repos reach it through a gitignored symlink. Only `.env.example`, holding placeholders, is ever tracked. A real secret inside a repo is a defect, not a configuration.",
|
|
"**Internal sharing / snippet hosting**: none. Public paste, gist and pastebin services are outside the trust boundary.",
|
|
"**CI/CD deploy targets**: no CI system. Deploys run out of band by the user, from a per-project runbook that Claude writes or explains (typically lftp/FTP to OVH mutualised hosting for web projects). Claude never runs a deploy or a transfer tool; nothing deploys automatically on a push or a merge.",
|
|
"**Internal package registry**: none. Public npm and PyPI.",
|
|
"**Host containment**: an ordinary developer workstation with open internet and no sandbox. Nothing is contained by the environment itself.",
|
|
"**Data-loss history**: on 2026-09-21 a sub-agent's `lftp mirror --delete` trace against a local `file://` path wiped the home, the NAS mount and 15 repositories in 90 seconds; nothing had been pushed for four days. The deny rules on transfer and mirror tools, the hard_deny on destructive tools against local paths, and the gitflow push hooks exist because of it.",
|
|
"**Push discipline**: every branch is pushed at creation and every commit at once by the gitflow post-commit and post-merge hooks, so the remote holds the work. A branch ahead of its upstream is a defect to fix now, not a state to keep.",
|
|
"**Sensitive remote targets**: any namespace, host, database or container whose name carries `prod` or `production` as a whole word or name segment.",
|
|
"**Sensitive data locations & audiences**: per-project `.env` files (gitignored) hold database, deploy and API credentials; some web projects store customer-submitted form data under a retention policy. Both are personal or client data — never send either to an external service."
|
|
]
|
|
}
|
|
}
|