jlaws

J Config Audit — Security skill for Claude Code

Security community

Security audit of Claude, Codex, Gemini, and shared agent configuration for secrets, over-broad permissions, and prompt-injection vectors.

How to install J Config Audit

Installs to ~/.claude/commands/jlaws-dotfiles-j-config-audit.md

Terminal
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/jlaws/dotfiles/HEAD/.claude/commands/j-config-audit.md -o ~/.claude/commands/jlaws-dotfiles-j-config-audit.md

Restart Claude Code, or start a new session, for it to be picked up.

What J Config Audit does


name: j-config-audit description: "Security audit of Claude, Codex, Gemini, and shared agent configuration for secrets, over-broad permissions, and prompt-injection vectors. Use when reviewing agent config after changing settings, hooks, or permissions. Do NOT use for application code security (use /j-audit)." argument-hint: "" model: sonnet effort: xhigh

Invoke the `config-security-audit` skill via the Skill tool before doing anything else. Ru

Alternatives in Security

  • Security Guidance — Hook that warns about command injection, XSS, and unsafe patterns 14k ★
  • Security Guardian — Comprehensive security analysis for RTK CLI tool, focusing on command injection, shell escaping, hook security 11.9k ★
  • Token Scan — Meme coin and token security scan — checks for rug pull vectors (hidden mint, honeypot, fee manipulation, LP l 3.8k ★

Full documentation available on GitHub

View Source Repository