Official agent skill

Claude Settings Audit

by getsentry in getsentry/skills

Analyze a repository to generate recommended Claude Code settings.json permissions.

OfficialApache-2.0Auto-check passedDevelopment

Install Claude Settings Audit

skills CLI
$ npx skills add getsentry/skills --skill claude-settings-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/skills claude-settings-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/claude-settings-audit .claude/skills/claude-settings-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
claude-settings-audit
GitHub stars
1k
Used in
4 other repos
Token cost
~3k tokens
SKILL.md length
619 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze a repository to generate recommended Claude Code settings.json permissions.

  • Works in 4 steps: Detect Tech Stack → Detect Services → Check Existing Settings → …
  • Setting up a new project
  • SKILL.md covers Phase 1: Detect Tech Stack, Phase 2: Detect Services, Phase 3: Check Existing Settings and Phase 4: Generate…, plus 2 more sections
  • Calls go, pip and yarn; reaches mcp.sentry.dev; needs LINEAR_API_KEY

What it does

Claude Settings Audit is an agent skill from getsentry/skills, published by the product's own GitHub organization. Analyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Monorepo tooling. It works with Sentry, Bash, Python and npm. The repository describes itself as: Agent Skills used by the Sentry team for development. The licence is Apache-2.0.

When your agent uses it

  • Setting up a new project
  • Auditing existing settings
  • Determining which read-only bash commands to allow

Example prompts

  • “/claude-settings-audit”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in LINEAR_API_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Detect Tech Stack
  2. Detect Services
  3. Check Existing Settings
  4. Generate Recommendations

What it can do on your machine

Read from SKILL.md and the folder at commit d18b7aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • pip
    • yarn
    • npm
    • cargo
    • docker
    • terraform
    • poetry
    • uv
    • pnpm
    • bundle
    • java

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • mcp.sentry.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • LINEAR_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Claude Settings Audit loads about 3k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 619 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getsentry/skills at commit d18b7aa, republished under its Apache-2.0 licence (© getsentry). 619 words, ~2,979 tokens.

Download SKILL.mdSave it as .claude/skills/claude-settings-audit/SKILL.md (or your agent's skills folder).
name
claude-settings-audit
description
Analyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.

Claude Settings Audit

Analyze this repository and generate recommended Claude Code settings.json permissions for read-only commands.

Phase 1: Detect Tech Stack

Run these commands to detect the repository structure:

bash
ls -la
find . -maxdepth 2 \( -name "*.toml" -o -name "*.json" -o -name "*.lock" -o -name "*.yaml" -o -name "*.yml" -o -name "Makefile" -o -name "Dockerfile" -o -name "*.tf" \) 2>/dev/null | head -50

Check for these indicator files:

CategoryFiles to Check
Pythonpyproject.toml, setup.py, requirements.txt, Pipfile, poetry.lock, uv.lock
Node.jspackage.json, package-lock.json, yarn.lock, pnpm-lock.yaml
Gogo.mod, go.sum
RustCargo.toml, Cargo.lock
RubyGemfile, Gemfile.lock
Javapom.xml, build.gradle, build.gradle.kts
BuildMakefile, Dockerfile, docker-compose.yml
Infra*.tf files, kubernetes/, helm/
Monorepolerna.json, nx.json, turbo.json, pnpm-workspace.yaml

Phase 2: Detect Services

Check for service integrations:

ServiceDetection
Sentrysentry-sdk in deps, @sentry/* packages, .sentryclirc, sentry.properties
LinearLinear config files, .linear/ directory

Read dependency files to identify frameworks:

  • package.json → check dependencies and devDependencies
  • pyproject.toml → check [project.dependencies] or [tool.poetry.dependencies]
  • Gemfile → check gem names
  • Cargo.toml → check [dependencies]

Phase 3: Check Existing Settings

bash
cat .claude/settings.json 2>/dev/null || echo "No existing settings"

Phase 4: Generate Recommendations

Build the allow list by combining:

Baseline Commands (Always Include)
json
[
  "Bash(ls:*)",
  "Bash(pwd:*)",
  "Bash(find:*)",
  "Bash(file:*)",
  "Bash(stat:*)",
  "Bash(wc:*)",
  "Bash(head:*)",
  "Bash(tail:*)",
  "Bash(cat:*)",
  "Bash(tree:*)",
  "Bash(git status:*)",
  "Bash(git log:*)",
  "Bash(git diff:*)",
  "Bash(git show:*)",
  "Bash(git branch:*)",
  "Bash(git remote:*)",
  "Bash(git tag:*)",
  "Bash(git stash list:*)",
  "Bash(git rev-parse:*)",
  "Bash(gh pr view:*)",
  "Bash(gh pr list:*)",
  "Bash(gh pr checks:*)",
  "Bash(gh pr diff:*)",
  "Bash(gh issue view:*)",
  "Bash(gh issue list:*)",
  "Bash(gh run view:*)",
  "Bash(gh run list:*)",
  "Bash(gh run logs:*)",
  "Bash(gh repo view:*)",
  "Bash(gh api:*)"
]
Stack-Specific Commands

Only include commands for tools actually detected in the project.

Python (if any Python files or config detected)
If DetectedAdd These Commands
Any Pythonpython --version, python3 --version
poetry.lockpoetry show, poetry env info
uv.lockuv pip list, uv tree
Pipfile.lockpipenv graph
requirements.txt (no other lock)pip list, pip show, pip freeze
Node.js (if package.json detected)
If DetectedAdd These Commands
Any Node.jsnode --version
pnpm-lock.yamlpnpm list, pnpm why
yarn.lockyarn list, yarn info, yarn why
package-lock.jsonnpm list, npm view, npm outdated
TypeScript (tsconfig.json)tsc --version
Other Languages
If DetectedAdd These Commands
go.modgo version, go list, go mod graph, go env
Cargo.tomlrustc --version, cargo --version, cargo tree, cargo metadata
Gemfileruby --version, bundle list, bundle show
pom.xmljava --version, mvn --version, mvn dependency:tree
build.gradlejava --version, gradle --version, gradle dependencies
Build Tools
If DetectedAdd These Commands
Dockerfiledocker --version, docker ps, docker images
docker-compose.ymldocker-compose ps, docker-compose config
*.tf filesterraform --version, terraform providers, terraform state list
Makefilemake --version, make -n
Skills (for Sentry Projects)

If this is a Sentry project (or sentry-skills plugin is installed), include:

json
[
  "Skill(sentry-skills:agents-md)",
  "Skill(sentry-skills:blog-writing-guide)",
  "Skill(sentry-skills:brand-guidelines)",
  "Skill(sentry-skills:claude-settings-audit)",
  "Skill(sentry-skills:code-review)",
  "Skill(sentry-skills:code-simplifier)",
  "Skill(sentry-skills:commit)",
  "Skill(sentry-skills:create-branch)",
  "Skill(sentry-skills:django-access-review)",
  "Skill(sentry-skills:django-perf-review)",
  "Skill(sentry-skills:doc-coauthoring)",
  "Skill(sentry-skills:document-api-endpoint)",
  "Skill(sentry-skills:find-bugs)",
  "Skill(sentry-skills:gh-review-requests)",
  "Skill(sentry-skills:gha-security-review)",
  "Skill(sentry-skills:iterate-pr)",
  "Skill(sentry-skills:pr-link-issue)",
  "Skill(sentry-skills:pr-writer)",
  "Skill(sentry-skills:presentation-creator)",
  "Skill(sentry-skills:prompt-optimizer)",
  "Skill(sentry-skills:secret-serialization)",
  "Skill(sentry-skills:security-review)",
  "Skill(sentry-skills:skill-scanner)",
  "Skill(sentry-skills:skill-writer)",
  "Skill(sentry-skills:sred-project-organizer)",
  "Skill(sentry-skills:sred-work-summary)",
  "Skill(sentry-skills:triage-frontend-issues)",
  "Skill(sentry-skills:typing-exclusion-worker)"
]
WebFetch Domains
Always Include (Sentry Projects)
json
[
  "WebFetch(domain:docs.sentry.io)",
  "WebFetch(domain:develop.sentry.dev)",
  "WebFetch(domain:docs.github.com)",
  "WebFetch(domain:cli.github.com)"
]
Framework-Specific
If DetectedAdd Domains
Djangodocs.djangoproject.com
Flaskflask.palletsprojects.com
FastAPIfastapi.tiangolo.com
Reactreact.dev
Next.jsnextjs.org
Vuevuejs.org
Expressexpressjs.com
Railsguides.rubyonrails.org, api.rubyonrails.org
Gopkg.go.dev
Rustdocs.rs, doc.rust-lang.org
Dockerdocs.docker.com
Kuberneteskubernetes.io
Terraformregistry.terraform.io
Show full SKILL.md (249 more words)Show less
MCP Server Suggestions

MCP servers are configured in .mcp.json (not settings.json). Check for existing config:

bash
cat .mcp.json 2>/dev/null || echo "No existing .mcp.json"
Sentry MCP (if Sentry SDK detected)

Add to .mcp.json (replace {org-slug} and {project-slug} with your Sentry organization and project slugs):

json
{
  "mcpServers": {
    "sentry": {
      "type": "http",
      "url": "https://mcp.sentry.dev/mcp/{org-slug}/{project-slug}"
    }
  }
}
Linear MCP (if Linear usage detected)

Add to .mcp.json:

json
{
  "mcpServers": {
    "linear": {
      "command": "npx",
      "args": ["-y", "@linear/mcp-server"],
      "env": {
        "LINEAR_API_KEY": "${LINEAR_API_KEY}"
      }
    }
  }
}

Note: Never suggest GitHub MCP. Always use gh CLI commands for GitHub.

Output Format

Present your findings as:

  1. Summary Table - What was detected
  2. Recommended settings.json - Complete JSON ready to copy
  3. MCP Suggestions - If applicable
  4. Merge Instructions - If existing settings found

Example output structure:

markdown
## Detected Tech Stack

| Category        | Found          |
| --------------- | -------------- |
| Languages       | Python 3.x     |
| Package Manager | poetry         |
| Frameworks      | Django, Celery |
| Services        | Sentry         |
| Build Tools     | Docker, Make   |

## Recommended .claude/settings.json

\`\`\`json
{
"permissions": {
"allow": [
// ... grouped by category with comments
],
"deny": []
}
}
\`\`\`

## Recommended .mcp.json (if applicable)

If you use Sentry or Linear, add the MCP config to `.mcp.json`...

Important Rules

What to Include
  • Only READ-ONLY commands that cannot modify state
  • Only tools that are actually used by the project (detected via lock files)
  • Standard system commands (ls, cat, find, etc.)
  • The :* suffix allows any arguments to the base command
What to NEVER Include
  • Absolute paths - Never include user-specific paths like /home/user/scripts/foo or /Users/name/bin/bar
  • Custom scripts - Never include project scripts that may have side effects (e.g., ./scripts/deploy.sh)
  • Alternative package managers - If the project uses pnpm, do NOT include npm/yarn commands
  • Commands that modify state - No install, build, run, write, or delete commands
Package Manager Rules

Only include the package manager actually used by the project:

If DetectedIncludeDo NOT Include
pnpm-lock.yamlpnpm commandsnpm, yarn
yarn.lockyarn commandsnpm, pnpm
package-lock.jsonnpm commandsyarn, pnpm
poetry.lockpoetry commandspip (unless also has requirements.txt)
uv.lockuv commandspip, poetry
Pipfile.lockpipenv commandspip, poetry

If multiple lock files exist, include only the commands for each detected manager.

© getsentry, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/claude-settings-audit of getsentry/skills.

Open the folder on GitHubat commit d18b7aa

Used in 4 other repositories

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in getsentry/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Claude Settings Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Claude Settings Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Claude Settings Audit this skillgetsentry/skills1k4 repos~3kAutomated safety check: PassApache-2.0
Dep Auditorlaolaoshiren/claude-code-skills-zh877—~895Automated safety check: PassMIT
Rocky Devrocky-data/rocky304—~2.1kAutomated safety check: PassApache-2.0
Upgrade PackagesMelbourneDeveloper/dart_node113—~2.2kAutomated safety check: PassNone
Dependency Scanjwynia/agent-skills165—~1.7kAutomated safety check: PassMIT
Nx Run Tasksnomcopter/react-mosaic4.8k7 repos~613Automated safety check: PassCustom licence

Similar skills

  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    877 GitHub stars~895 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Rocky Dev

    rocky-data/rocky

    Top-level router for Rocky development tasks. An agent skill from rocky-data/rocky.

    304 GitHub stars~2.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Upgrade Packages

    MelbourneDeveloper/dart_node

    Upgrade all dependencies/packages to their latest versions for the detected language(s).

    113 GitHub stars~2.2k tokensUpdated 23 days ago
    MobileAuto-check passed
  • Dependency Scan

    jwynia/agent-skills

    Detect CVEs and security issues in project dependencies. An agent skill from jwynia/agent-skills.

    165 GitHub stars~1.7k tokensUpdated 7 mo ago
    SecurityAuto-check passed
  • Nx Run Tasks

    nomcopter/react-mosaic

    Helps with running tasks in an Nx workspace. An agent skill from nomcopter/react-mosaic.

    4.8k GitHub starsUsed in 7 repos~613 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    55k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed

More from getsentry/skills

All 27 skills in this repo
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    Auto-check: warnings
  • Gh Review Requests

    getsentry/skills

    Official

    Fetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member.

    1k GitHub starsUsed in 3 repos~621 tokens
    Auto-check: notes
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    Auto-check: notes
  • Skill Writer

    getsentry/skills

    Official

    Create, synthesize, and iteratively improve agent skills following the Agent Skills specification.

    1k GitHub stars~2.5k tokensUpdated 4 days ago
    Auto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Auto-check: notes
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    Auto-check: notes

Categories

Questions about Claude Settings Audit

What does Claude Settings Audit do?

Analyze a repository to generate recommended Claude Code settings.json permissions. Claude Settings Audit is an agent skill from getsentry/skills, published by the product's own GitHub organization.json permissions.

When should I use Claude Settings Audit?

Claude Settings Audit fits situations like: setting up a new project; auditing existing settings; determining which read-only bash commands to allow.

How do I install Claude Settings Audit in Claude Code?

Run `npx skills add getsentry/skills --skill claude-settings-audit -a claude-code`. Or copy the skill folder (skills/claude-settings-audit in getsentry/skills) into .claude/skills/claude-settings-audit in your project. Claude Code loads it when a task matches its description.

How do I install Claude Settings Audit in Codex?

Run `npx skills add getsentry/skills --skill claude-settings-audit -a codex`. Or copy the skill folder (skills/claude-settings-audit in getsentry/skills) into .agents/skills/claude-settings-audit in your project. Codex loads it when a task matches its description.

Can I use Claude Settings Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/skills --skill claude-settings-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/claude-settings-audit, .gemini/skills/claude-settings-audit, .github/skills/claude-settings-audit and .opencode/skills/claude-settings-audit in your project.

What does Claude Settings Audit need to run?

Going by SKILL.md and its folder, Claude Settings Audit needs the command-line tools its instructions call (go, pip, yarn, npm, cargo and docker) and credentials named LINEAR_API_KEY. Our summary lists: Python 3; Node.js; Docker; A credential in LINEAR_API_KEY.

Does Claude Settings Audit access the network?

SKILL.md names 1 domain. In commands or code: mcp.sentry.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Claude Settings Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Claude Settings Audit use?

Claude Settings Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Claude Settings Audit use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Claude Settings Audit?

Skills that share tags, products or a category with Claude Settings Audit: Dep Auditor (laolaoshiren/claude-code-skills-zh, 877 stars), Rocky Dev (rocky-data/rocky, 304 stars), Upgrade Packages (MelbourneDeveloper/dart_node, 113 stars) and Dependency Scan (jwynia/agent-skills, 165 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Claude Settings Audit?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/skills, which has 1,037 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 2, 2026.

Source: getsentry/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.