One of the main rules in software engineering is to always have a backup.
Many of us improve our Claude workflow every day. We create and edit skills and hooks, update CLAUDE.md and so on. I recommend creating a private repository and committing your ~/.claude folder.
This is useful in several cases:
- It protects you if something happens to your .claude folder
- You keep previous versions of your skills and CLAUDE.md
- You see in git what has changed. This makes it much easier to track the changes that Claude makes to CLAUDE.md by itself (it often writes there something different from what you asked)
Make sure to add these to your .gitignore. The .credentials.json file, settings.json if it contains tokens, and also plugins, history.jsonl, paste-cache, file-history and the projects folder, because they hold tokens and session transcripts with work code.
Here’s an example of my .gitignore below (feel free to use it as a starting point):
# Back up only what you author in ~/.claude. Everything else stays out by default:
# credentials, session transcripts, caches, installed plugins.
# Keep your own files in another folder here? Add a !/<folder>/ line for it.
/*
!/.gitignore
!/README.md
!/CLAUDE.md
!/rules/
!/skills/
!/commands/
!/agents/
!/hooks/
!/output-styles/
!/keybindings.json
!/statusline*
# Hook registration, permissions and the status line live here.
# Uncomment only after every token in its env block moved to a real environment variable.
# !/settings.json
# Auto-memory: keep only memory/ from each project, never the session transcripts
!/projects/
/projects/*/*
!/projects/*/memory/
# Synced by the Claude apps, not authored here
/skills/synced/
# Safety net inside allowed folders
.env*
*.pem
*.key
node_modules/
__pycache__/
My blog: olegdubovoi.com
Top comments (2)
The whitelist pattern is definitely the way to go here.
A quick pre-commit hook scanning for secret patterns inside custom skills and hooks saved me more than once. Even when settings.json stays ignored, it is easy during late-night debugging to paste a test bearer token into a curl wrapper inside ~/.claude/skills and push it to the remote repo.
The diff on CLAUDE.md is also where you spot instruction bloat early. Agents love turning a single failed tool call into three paragraphs of permanent negative constraints that chew through prompt tokens on every future run.
A pre-commit hook is a nice idea! I agree that it's easy to forget about something and accidentally commit it, and even .gitignore won't help in this situation. Thanks for your comment! :)