I turned that into a framework: 3-layer architecture (hooks for hard rules, 200-line working memory, indexed long-term knowledge), a self-learning system that captures your corrections automatically, and 21 pre-installed skills.
The dangerous-command blocker hook was the latest addition — it hard-blocks rm, git reset --hard, sudo, curl|sh before execution. Not a suggestion, an actual exit code 2.
Happy to answer questions about the architecture or trade notes on CLAUDE.md workflows.