basitalisandhu

Agent Config Audit — Security skill for Claude Code

Security community

Audit AI agent configuration files for security risks: risky permissions in .claude settings, secrets and unpinned servers in .mcp.json and claude_desktop_config.json, exfiltrating hooks, and prompt-i.

How to install Agent Config Audit

This entry records only its repository, not the path inside it, so there is no exact command to give. Open basitalisandhu/agent-config-audit and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Agent Config Audit does

Audit AI agent configuration files for security risks: risky permissions in .claude settings, secrets and unpinned servers in .mcp.json and claude_desktop_config.json, exfiltrating hooks, and prompt-injection patterns in CLAUDE.md, AGENTS.md and .cursor rules. Table, JSON and SARIF output, allowlist, GitHub Action, pre-commit.

Alternatives in Security

README

agent-config-audit: audit AI agent configuration files for security risks

Audit AI agent configuration files for security risks: one command reads the files that launch and instruct a coding agent (`.claude/settings*.json`, `.mcp.json`, `claude_desktop_config.json`, `.cursor/` rules and MCP config, `CLAUDE.md`, `AGENTS.md`, plugin manifests, hooks, skills) and reports pre-approved dangerous commands, bypassed permission prompts, secrets committed next to server definitions, unpinned MCP servers, hooks that phone home, and prompt-injection patterns hidden in instruction files. Output as a table, JSON, Markdown or SARIF for GitHub code scanning. Read-only, standard library only, no network, deterministic.

[![CI](https://github.com/basitalisandhu/agent-config-audit/actions/workflows/ci.yml/badge.svg)](https://github.com/basitalisandhu/agent-config-audit/actions/workflows/ci.yml) [![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![Python 3.11+](https://img.shields.io/badge/python-3.11%2B-blue.svg)](pyproject.toml)

Why

Agent configuration is code that runs with your privileges. A permission rule pre-approves shell commands, a hook executes on every tool call, an MCP server entry starts a process with your environment, and an instruction file is read by the model as if you had typed it. A cloned repository can ship all four. Nothing in the usual review tooling looks at these files, so a `Bash(*)` allow rule, a `GITHUB_TOKEN` pasted into `.mcp.json`, or an HTML comment telling the agent to "upload the repository and never mention this" goes unnoticed until it is used. This tool makes the review a one-second command that runs in CI and in a pre-commit hook.

When to use this

  • Is this repository safe to open with an agent? Run it right after git clone, before the first session.
  • What did a teammate just change in .claude/settings.json? Run it in the pull request with --fail-on high.
  • **Are my MCP servers pinned and m