Claudit Sec — Security skill for Claude Code
Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions.
How to install Claudit Sec
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open HarmonicSecurity/claudit-sec and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Claudit Sec does
Security audit tool for Claude Desktop and Claude Code on macOS — single-command visibility into MCP servers, extensions, plugins, connectors, scheduled tasks, and permissions.
Alternatives in Security
- Trail Of Bits Claude-code-config — Opinionated production defaults from a top security firm: sandboxing, permissions, hooks, skills, MCP server c 1.6k ★
- Pocketpaw — Your AI agent in 30 seconds 775 ★
- Google MCP Security Servers — Security Operations and Threat Intelligence MCP servers 453 ★
README
🛡️ CLAUDIT-SEC
**Security audit tool for Claude Desktop on macOS and Windows — including CoWork, extensions, plugins, MCP servers, connectors, and scheduled tasks.**
One command. Full visibility. Read-only.
⚠️ **Windows support is a work in progress.** We're aware of a few kinks and bugs and wanted to get something out sooner rather than later. Community feedback and contributions are welcome.
🤔 Why
Claude Desktop introduces a new class of endpoint risk: AI agents with autonomous execution, persistent scheduled tasks, MCP server integrations, browser-control extensions, and OAuth-authenticated connectors to external services. Most of this configuration lives in JSON files scattered across multiple directories with no centralised visibility.
CLAUDIT gives you that visibility in a single command.
📝 **A note on "Code":** Claude Desktop includes a built-in agent coding feature called **Code** (visible in the app's sidebar). This is **not** the same as **Claude Code**, the standalone terminal CLI. CLAUDIT primarily audits Claude Desktop and its CoWork features. It does include a basic check of the Claude Code settings file (`~/.claude/settings.json` on macOS, `%USERPROFILE%\.claude\settings.json` on Windows), but the focus is squarely on the Desktop app.
📋 What It Audits
| Area | What's Checked |
|---|---|
| 🖥️ Desktop Settings | keepAwakeEnabled, sidebar/menuBar preferences |
| 🤖 CoWork Settings | Scheduled tasks, web search, browser use, dispatch (mobile→desktop), network mode, egress policy, enabled plugins, marketplaces |
| 🏢 Workspaces | Multi-workspace detection, account names, session counts, org indicators (DXT-managed, org-plugins, dispatch-bridge) |
| 🔌 MCP Servers | Server names, commands, arguments, environment variable keys |
| 🧩 Extensions (DXT) | Installed extensions, signature status |
Related Skills
Toolward
Security auditor for AI agent extensions — MCP servers, skills, plugins, connectors. Finds prompt injection, t
Agent Config Audit
Audit AI agent configuration files for security risks: risky permissions in .claude settings, secrets and unpi
Polyagent
Multi-provider AI agent bridge — an MCP server that lets Claude Desktop delegate tasks (security scans, code r
Cchub
Desktop hub for managing Claude Code MCP servers, health checks, configuration profiles, skills, plugins, hook
Aisecscan
Static security scanner for Claude Code configuration — settings, permissions, hooks, MCP servers, agents/suba
Claude Code Security Setup
A secure Claude Code setup from Trail of Bits that provides opinionated defaults, documentation, and workflows
Related Agents
Claude Code Infra
Use PROACTIVELY and automatically — do not wait to be asked — to configure Claude Code itself: sub-agents, ski
Computer Use Operator
Desktop automation specialist. Controls native macOS apps via Computer Use MCP. Handles Finder, System Setting
MCP Advisor
Portable MCP build + conformance advisor — how to build an MCP server (tools/resources/prompts, transports, OA