HarmonicSecurity

Claudit Sec — Security skill for Claude Code

Security community

Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions.

How to install Claudit Sec

This entry records only its repository, not the path inside it, so there is no exact command to give. Open HarmonicSecurity/claudit-sec and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Claudit Sec does

Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions.

Alternatives in Security

README

🛡️ CLAUDIT-SEC

**Security audit tool for Claude Desktop on macOS and Windows — including CoWork, extensions, plugins, MCP servers, connectors, and scheduled tasks.**

One command. Full visibility. Read-only.

⚠️ **Windows support is a work in progress.** We're aware of a few kinks and bugs and wanted to get something out sooner rather than later. Community feedback and contributions are welcome.

CLAUDIT terminal output

🤔 Why

Claude Desktop introduces a new class of endpoint risk: AI agents with autonomous execution, persistent scheduled tasks, MCP server integrations, browser-control extensions, and OAuth-authenticated connectors to external services. Most of this configuration lives in JSON files scattered across multiple directories with no centralised visibility.

CLAUDIT gives you that visibility in a single command.

📝 **A note on "Code":** Claude Desktop includes a built-in agent coding feature called **Code** (visible in the app's sidebar). This is **not** the same as **Claude Code**, the standalone terminal CLI. CLAUDIT primarily audits Claude Desktop and its CoWork features. It does include a basic check of the Claude Code settings file (`~/.claude/settings.json` on macOS, `%USERPROFILE%\.claude\settings.json` on Windows), but the focus is squarely on the Desktop app.

📋 What It Audits

Area What's Checked
🖥️ Desktop Settings keepAwakeEnabled, sidebar/menuBar preferences
🤖 CoWork Settings Scheduled tasks, web search, browser use, dispatch (mobile→desktop), network mode, egress policy, enabled plugins, marketplaces
🏢 Workspaces Multi-workspace detection, account names, session counts, org indicators (DXT-managed, org-plugins, dispatch-bridge)
🔌 MCP Servers Server names, commands, arguments, environment variable keys
🧩 Extensions (DXT) Installed extensions, signature status