Agent Config Audit — Security skill for Claude Code
Audit AI agent configuration files for security risks: risky permissions in .claude settings, secrets and unpinned servers in .mcp.json and claude_desktop_config.json, exfiltrating hooks, and prompt-i.
How to install Agent Config Audit
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open basitalisandhu/agent-config-audit and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Agent Config Audit does
Audit AI agent configuration files for security risks: risky permissions in .claude settings, secrets and unpinned servers in .mcp.json and claude_desktop_config.json, exfiltrating hooks, and prompt-injection patterns in CLAUDE.md, AGENTS.md and .cursor rules. Table, JSON and SARIF output, allowlist, GitHub Action, pre-commit.
Alternatives in Security
- Security Ownership Map — Map people-to-file ownership, compute bus factor, and identify risks 14.6k ★
- Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
- Pocketpaw — Your AI agent in 30 seconds 775 ★
README
agent-config-audit: audit AI agent configuration files for security risks
Audit AI agent configuration files for security risks: one command reads the files that launch and instruct a coding agent (`.claude/settings*.json`, `.mcp.json`, `claude_desktop_config.json`, `.cursor/` rules and MCP config, `CLAUDE.md`, `AGENTS.md`, plugin manifests, hooks, skills) and reports pre-approved dangerous commands, bypassed permission prompts, secrets committed next to server definitions, unpinned MCP servers, hooks that phone home, and prompt-injection patterns hidden in instruction files. Output as a table, JSON, Markdown or SARIF for GitHub code scanning. Read-only, standard library only, no network, deterministic.
[](https://github.com/basitalisandhu/agent-config-audit/actions/workflows/ci.yml) [](LICENSE) [](pyproject.toml)
Why
Agent configuration is code that runs with your privileges. A permission rule pre-approves shell commands, a hook executes on every tool call, an MCP server entry starts a process with your environment, and an instruction file is read by the model as if you had typed it. A cloned repository can ship all four. Nothing in the usual review tooling looks at these files, so a `Bash(*)` allow rule, a `GITHUB_TOKEN` pasted into `.mcp.json`, or an HTML comment telling the agent to "upload the repository and never mention this" goes unnoticed until it is used. This tool makes the review a one-second command that runs in CI and in a pre-commit hook.
When to use this
- Is this repository safe to open with an agent? Run it right after
git clone, before the first session. - What did a teammate just change in
.claude/settings.json? Run it in the pull request with--fail-on high. - **Are my MCP servers pinned and m
Related Skills
Security Actions
GitHub Actions for AI agent and supply chain security checks: audit agent configs (Claude Code settings, MCP s
J Config Audit
Security audit of Claude, Codex, Gemini, and shared agent configuration for secrets, over-broad permissions, a
Aisecscan
Static security scanner for Claude Code configuration — settings, permissions, hooks, MCP servers, agents/suba
Cchub
Desktop hub for managing Claude Code MCP servers, health checks, configuration profiles, skills, plugins, hook
Claude Setup Audit
A Claude Code plugin that audits your whole setup — settings, permissions, hooks, MCP servers, skills, CLAUDE.
MCP Skills Vault
Offline security check for MCP server configs (.mcp.json, VS Code, Cursor, Claude Code) — GitHub Action, pre-c
Related Agents
Claude Code Infra
Use PROACTIVELY and automatically — do not wait to be asked — to configure Claude Code itself: sub-agents, ski
Light Security ClaudeSettingsAudit
Audit Claude Code config files (settings.json, settings.local.json, .mcp.json) for unsafe or malicious content
Config Doctor
Audits and repairs Claude Code configuration, including agents, commands, hooks, settings, and project memory.