MCP Server Builder
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
Scans project-local Claude Code settings files, finds permission patterns worth promoting to global config, then cleans up what global now covers.
$ npx skills add malob/nix-config --skill audit-permissions -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install malob/nix-config audit-permissions --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/malob/nix-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/configs/claude/plugins/cc-maintenance/skills/audit-permissions .claude/skills/audit-permissions && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-permissions" agent skill from https://github.com/malob/nix-config/tree/master/configs/claude/plugins/cc-maintenance/skills/audit-permissions into .claude/skills/audit-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-permissions", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/malob/nix-config/tree/master/configs/claude/plugins/cc-maintenance/skills/audit-permissionsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add malob/nix-config --skill audit-permissions -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install malob/nix-config audit-permissions --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malob/nix-config.git skills-src && mkdir -p .agents/skills && cp -r skills-src/configs/claude/plugins/cc-maintenance/skills/audit-permissions .agents/skills/audit-permissions && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-permissions" agent skill from https://github.com/malob/nix-config/tree/master/configs/claude/plugins/cc-maintenance/skills/audit-permissions into .agents/skills/audit-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-permissions", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malob/nix-config --skill audit-permissions -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install malob/nix-config audit-permissions --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malob/nix-config.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/configs/claude/plugins/cc-maintenance/skills/audit-permissions .cursor/skills/audit-permissions && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-permissions" agent skill from https://github.com/malob/nix-config/tree/master/configs/claude/plugins/cc-maintenance/skills/audit-permissions into .cursor/skills/audit-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-permissions", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/malob/nix-config.git --path configs/claude/plugins/cc-maintenance/skills/audit-permissions--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add malob/nix-config --skill audit-permissions -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install malob/nix-config audit-permissions --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malob/nix-config.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/configs/claude/plugins/cc-maintenance/skills/audit-permissions .gemini/skills/audit-permissions && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-permissions" agent skill from https://github.com/malob/nix-config/tree/master/configs/claude/plugins/cc-maintenance/skills/audit-permissions into .gemini/skills/audit-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-permissions", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install malob/nix-config audit-permissionsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add malob/nix-config --skill audit-permissions -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/malob/nix-config.git skills-src && mkdir -p .github/skills && cp -r skills-src/configs/claude/plugins/cc-maintenance/skills/audit-permissions .github/skills/audit-permissions && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-permissions" agent skill from https://github.com/malob/nix-config/tree/master/configs/claude/plugins/cc-maintenance/skills/audit-permissions into .github/skills/audit-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-permissions", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add malob/nix-config --skill audit-permissions -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install malob/nix-config audit-permissions --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/malob/nix-config.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/configs/claude/plugins/cc-maintenance/skills/audit-permissions .opencode/skills/audit-permissions && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-permissions" agent skill from https://github.com/malob/nix-config/tree/master/configs/claude/plugins/cc-maintenance/skills/audit-permissions into .opencode/skills/audit-permissions/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-permissions", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-permissionsScans project-local Claude Code settings files, finds permission patterns worth promoting to global config, then cleans up what global now covers.
This skill runs as three sequential tasks: promoting candidate permissions to global config with the user's explicit decision on each one, an automated cleanup script that removes local permissions now redundant with those promotions, and a judgment-call phase covering security hygiene, policy conflicts, and one-off cruft.
Before touching anything it checks whether the global settings file is a symlink so edits land on the real target, loads the user's saved maintenance preferences if present, and reads the global CLAUDE.md for tool-preference policies it can check later conflicts against. A bundled discovery-and-extraction pipeline gathers the raw permission data before any categorization happens.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9cca0f4. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(*/audit-permissions/scripts/*)Bash(readlink *)Read(~/.claude/settings.json)Edit(~/.claude/settings.json)Write(~/.claude/settings.json)Read(**/.claude/settings.local.json)Edit(**/.claude/settings.local.json)Write(**/.claude/settings.local.json)Read(~/.claude/cc-maintenance.local.md)Edit(~/.claude/cc-maintenance.local.md)…and 2 more on the same allowed-tools line.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python and Shell), which the agent can run.
Shell commands in SKILL.md call:
ghgitnixcargogonpmdenobrewxcodebuildFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, git and npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Code Permissions Auditor loads about 4.1k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 1,324 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from malob/nix-config at commit 9cca0f4, republished under its MIT licence (© malob). 1,324 words, ~4,102 tokens.
.claude/skills/audit-permissions/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Scan project-local Claude Code settings files, aggregate permission patterns, and recommend promotions to global configuration.
This audit runs in three phases, each as a separate task. Use TaskCreate at the start to create all three tasks, then work through them sequentially with user input via AskUserQuestion.
readlink -f ~/.claude/settings.jsonIf the global settings file is a symlink, note the real path. All writes to ~/.claude/settings.json must edit the symlink target, not create a new file that replaces the symlink.
Load user preferences from ~/.claude/cc-maintenance.local.md (if it exists). See User Preferences section below. Apply any configured defaults (risk tolerance, auto-cleanup preference).
Read global CLAUDE.md from ~/.claude/CLAUDE.md to identify tool preference policies for Phase 3 policy conflict detection.
Run the discovery and extraction pipeline:
scripts/discover-settings.sh | xargs scripts/extract-permissions.pyRead the actual global settings from ~/.claude/settings.json — compare against the real allow list, not just the static examples in this skill.
Create tasks for the three phases:
TaskCreate: "Review and promote permissions to global config"
TaskCreate: "Automated redundancy cleanup"
TaskCreate: "Judgment calls: security, policy, and cruft"Goal: Identify permissions worth adding to global config and get user approval.
Show a summary table of promotion candidates:
## Promotion Candidates
### Strong Recommendations (safe patterns, multiple projects)
| Permission | Projects | Suggested Global Pattern |
| ---------- | -------- | ------------------------ |
| ... | ... | ... |
### Moderate Recommendations (review carefully)
| Permission | Projects | Notes |
| ---------- | -------- | ----- |
| ... | ... | ... |
### Cross-Project File Patterns
[If any Read/Write/Edit permissions reference paths outside their project directory
and appear in multiple projects, flag them here. Example: multiple projects have
`Write(~/.config/some-tool/config.json)` - might indicate a shared config worth
adding globally.]Use AskUserQuestion to let the user decide:
Question: "Which permissions should I add to global settings?"
Options:
- "Add all strong recommendations"
- "Add strong + moderate recommendations"
- "Let me pick specific ones" (then list individually)
- "Skip - don't add any"If user approves additions:
~/.claude/settings.json (or symlink target)Bash(cmd *) not Bash(cmd:*)Goal: Remove local permissions now covered by global config. This is mechanical — the script identifies exact matches; user just sanity-checks the list.
Run the cleanup script in dry-run mode:
scripts/discover-settings.sh | scripts/cleanup-redundant.pyShow what would be removed:
## Redundant Permissions
| File | Permissions to Remove | Remaining |
| --------- | --------------------- | --------- |
| project-a | 5 (ls _, grep _, ...) | 12 |
| project-b | 3 (gh api \*, ...) | 8 |
| ... | ... | ... |
**Total:** X permissions across Y filesThe script also normalizes any remaining colon-syntax (Bash(cmd:*)) to space-syntax (Bash(cmd *)) when applying.
If auto_cleanup_redundant: true in user preferences, skip the question and apply directly (still show the summary). Otherwise:
Question: "Should I remove these redundant permissions from local files?"
Options:
- "Yes, clean them up"
- "Show me the full list first"
- "Skip cleanup"If user approves:
scripts/discover-settings.sh | scripts/cleanup-redundant.py --applyMark Phase 2 task as completed.
Goal: Everything that requires real user judgment — security risks, policy conflicts, stale cruft, and cleanup opportunities. Present all categories together.
Flag permissions that match these patterns:
High Risk (recommend removal):
Bash(curl *), Bash(wget *) — network exfiltration riskBash(rm *) — can delete any fileBash(source *) — executes arbitrary scriptsBash(eval *) — arbitrary code executionModerate Risk (review):
Bash(git reset *), Bash(git checkout *) — can discard workBash(pkill *), Bash(kill *) — process terminationBash(python *), Bash(python3 *), Bash(node *) — arbitrary code (flag if user hasn't consciously chosen this)Adjust what counts as "moderate" vs "high" based on the user's risk_tolerance preference if set.
Read the user's global ~/.claude/CLAUDE.md for stated tool preferences. Flag local permissions that conflict with those policies.
How to detect: Look for patterns like "prefer X over Y", "use X instead of Y", "avoid Y". Then scan all local permissions for uses of the deprecated tool. For example:
If CLAUDE.md says "prefer tool X over built-in Y", flag all
Ypermissions across local settings as policy conflicts.
Present these as informational — the user may have valid reasons for specific overrides.
Bash(prettier --write /full/path/to/file.md))Bash(done), Bash(for file in *.rs))Bash(cmd:*)) that weren't caught by the cleanup script (e.g., ones without a global equivalent)Read, Write, or Edit permissions for paths outside the projectWrite(~/.config/*) as security concernsmcp__server__*) — convenient but auto-permits any future tools added to that server without reviewAfter cleanup, identify settings files where:
Offer to delete these empty files entirely — they serve no purpose.
## Judgment Calls
### Security Hygiene
#### High Risk — Recommend Removal
| Permission | Project | Risk |
| -------------- | --------- | ----------------- |
| `Bash(curl *)` | project-x | Data exfiltration |
#### Moderate Risk — Review
| Permission | Project | Risk |
| ---------- | ------- | ---- |
| ... | ... | ... |
### Policy Conflicts
| Permission | Projects | Policy |
| --------------- | -------- | --------------------------- |
| `WebFetch(url)` | 3 | CLAUDE.md: prefer Firecrawl |
### One-Off Cruft
| Permission | Project |
| -------------------------------------------------- | --------- |
| `Bash(prettier --write /path/to/specific/file.md)` | project-y |
### External File Access
| Permission | Projects | Notes |
| ------------------------------ | ---------- | ------------------------------- |
| `Write(~/.config/tool/config)` | 3 projects | Shared config — consider global |
| `Edit(/etc/hosts)` | 1 project | System file — review necessity |
### MCP Tool Permissions
| Permission | Projects | Notes |
| -------------------------- | -------- | ------------------------------------------- |
| `mcp__slack__post_message` | 2 | Side effect: sends messages externally |
| `mcp__puppeteer__*` | 1 | Server wildcard — auto-permits future tools |
### Empty Settings Files
| File | Reason |
| ----------------------------------------- | ------------------------------------------ |
| `~/project-z/.claude/settings.local.json` | All permissions removed, no other settings |Use AskUserQuestion:
Question: "How should I handle the judgment call items?"
Options:
- "Remove all flagged items"
- "Remove high risk + cruft only"
- "Let me review each category"
- "Skip — keep everything"If user wants to review categories, ask about each separately.
Edit each affected settings.local.json to remove approved items. Delete empty settings files if approved.
Mark Phase 3 task as completed.
After all phases complete, offer to create or update ~/.claude/cc-maintenance.local.md with session learnings. Include:
Location: ~/.claude/cc-maintenance.local.md
Read at audit start. If missing, proceed with defaults. At session end, offer to create/update.
Format: YAML frontmatter for structured preferences + markdown body for freeform notes.
---
# All preferences are optional
risk_tolerance: moderate # conservative | moderate | aggressive
auto_cleanup_redundant: true
---
## Tool Preferences
- Prefer Exa/Firecrawl over built-in WebSearch/WebFetch
## Risk Notes
- sqlite3 and op item get considered moderate risk
- uv run python treated as arbitrary code execution
## Notes
- Always keep python3 permissions in the data-science project
- Don't consolidate Firecrawl tools into a server wildcard
## Session History
### 2026-02-09
- Promoted 13 permissions to global
- Removed ~220 cruft permissions from Assistant projectBehavior:
risk_tolerance adjusts what gets flagged as moderate vs high in Phase 3auto_cleanup_redundant skips the confirmation prompt in Phase 2 (still shows summary)All scripts are in scripts/ relative to this skill directory.
scripts/discover-settings.sh — Finds all .claude/settings.local.json files across ~ using fd with sensible exclusions (Library, node_modules, .git, etc.). Max depth of 5 for performance.scripts/extract-permissions.py — Aggregates permissions from multiple settings files. Outputs JSON with each permission, occurrence count, and list of projects using it. Sorted by count descending.scripts/cleanup-redundant.py — Removes permissions from local files that are covered by global config. Handles cross-syntax matching (colon-syntax vs space-syntax). Normalizes remaining permissions to space-syntax on write. Dry-run by default; use --apply to modify files.Usage examples:
# Extract and aggregate all permissions
scripts/discover-settings.sh | xargs scripts/extract-permissions.py
# Preview redundant permission cleanup (dry-run, default)
scripts/discover-settings.sh | scripts/cleanup-redundant.py
# Actually remove redundant permissions
scripts/discover-settings.sh | scripts/cleanup-redundant.py --applyUse space-syntax for all permissions: Bash(cmd *) not Bash(cmd:*).
Patterns worth promoting. These operate on local project code or perform read-only operations. Compare against the actual global config, not just this static list — these are examples of the kinds of patterns to look for.
Git Commands (read-only):
git branch *, git diff *, git log *, git show *, git status *
File Inspection (read-only):
cat *, head *, tail *, ls *, find *, grep *, du *
Build and Check Commands:
cargo build *, cargo test *, cargo check *, go build *, go test *,
npm run build *, npm run test *, deno check *, deno lint *, xcodebuild *
System Utilities:
open *, pbcopy, pbpaste, lsof *, ps *
Nix Commands:
nix build *, nix-build *, nix develop *, nix eval *, nix flake *,
nix path-info *, nix-prefetch-url *, nh darwin build *
Homebrew (read-only):
brew info *, brew search *
GitHub CLI:
gh api *, gh issue list *, gh issue view *, gh pr list *, gh pr view *,
gh pr diff *, gh pr checks *, gh search *, gh run list *, gh run view *
Wildcards:
* --help *, * --version
When promoting, generalize cautiously — only for safe patterns:
| Local Pattern | Global Pattern | Notes |
|---|---|---|
Bash(npm run build) | Bash(npm run build *) | Safe — runs project scripts |
Bash(cargo test --release) | Bash(cargo test *) | Safe — tests local code |
Bash(nix build .#package) | Bash(nix build *) | Safe — sandboxed builds |
Bash(python3 script.py) | Keep specific or skip | Risky — arbitrary code |
WebFetch(domain:github.com) | Keep as-is | Domain patterns don't change |
When adding to ~/.claude/settings.json:
Bash(cmd *) not Bash(cmd:*)© malob, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (scripts) in configs/claude/plugins/cc-maintenance/skills/audit-permissions of malob/nix-config.
Open the folder on GitHubat commit 9cca0f4
Claude Code Permissions Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Claude Code Permissions Auditor this skillmalob/nix-config | 463 | — | ~4.1k | Automated safety check: Pass | MIT | |
| MCP Server Builderanthropics/skills | 180k | 64 repos | ~2.3k | Automated safety check: Pass | Apache-2.0 | |
| Hook Development for Claude Code Pluginsanthropics/claude-plugins-official | 38k | 11 repos | ~4.1k | Automated safety check: Notes | Apache-2.0 | |
| Using Superpowersfarm-fe/farm | 5.6k | 35 repos | ~1.4k | Automated safety check: Pass | MIT | |
| Executing Plans Inlineobra/superpowers | 296k | 2 repos | ~5.1k | Automated safety check: Pass | MIT | |
| Claude Code Agent Developmentanthropics/claude-plugins-official | 38k | 8 repos | ~2.8k | Automated safety check: Pass | Apache-2.0 |
anthropics/skills
Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.
anthropics/claude-plugins-official
Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.
farm-fe/farm
A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions
obra/superpowers
Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.
anthropics/claude-plugins-official
Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.
Azure/azqr
Create new skills, modify and improve existing skills, and measure skill performance.
malob/nix-config
Coordinates a team of researcher agents across several rounds, with a lead who triages findings, assigns follow-ups and cross-checks key claims.
malob/nix-config
Works around Claude Code filtering private-use Unicode so agents can read and write Nerd Font icons in Starship, tmux and prompt configs.
malob/nix-config
Coordinates specialist agents to create a Homebrew cask for a macOS app: pre-flight checks, download and inspection, a livecheck strategy and the remaining cask steps.
malob/nix-config
Practical guidance for multi-source web research with Exa, the Firecrawl CLI and Reddit MCP tools: when to search, when to fetch and which tool to prefer.
Categories
Scans project-local Claude Code settings files, finds permission patterns worth promoting to global config, then cleans up what global now covers. This skill runs as three sequential tasks: promoting candidate permissions to global config with the user's explicit decision on each one, an automated cleanup script that removes local permissions now redundant with those promotions, and a judgment-call phase covering security hygiene, policy conflicts, and one-off cruft.
Claude Code Permissions Auditor fits situations like: reviewing which project-local Claude Code permissions should become global; cleaning up redundant local permissions after a promotion; auditing Claude Code settings for policy conflicts or stale entries.
Run `npx skills add malob/nix-config --skill audit-permissions -a claude-code`. Or copy the skill folder (configs/claude/plugins/cc-maintenance/skills/audit-permissions in malob/nix-config) into .claude/skills/audit-permissions in your project. Claude Code loads it when a task matches its description.
Run `npx skills add malob/nix-config --skill audit-permissions -a codex`. Or copy the skill folder (configs/claude/plugins/cc-maintenance/skills/audit-permissions in malob/nix-config) into .agents/skills/audit-permissions in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malob/nix-config --skill audit-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-permissions, .gemini/skills/audit-permissions, .github/skills/audit-permissions and .opencode/skills/audit-permissions in your project.
Going by SKILL.md and its folder, Claude Code Permissions Auditor needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (gh, git, nix, cargo, go and npm). Its frontmatter pre-approves these tools: Bash(*/audit-permissions/scripts/*), Bash(readlink *), Read(~/.claude/settings.json), Edit(~/.claude/settings.json), Write(~/.claude/settings.json), Read(**/.claude/settings.local.json), Edit(**/.claude/settings.local.json), Write(**/.claude/settings.local.json), Read(~/.claude/cc-maintenance.local.md), Edit(~/.claude/cc-maintenance.local.md), Write(~/.claude/cc-maintenance.local.md), Read(~/.claude/CLAUDE.md).
SKILL.md contains no URLs. Its commands use gh, git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Claude Code Permissions Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Claude Code Permissions Auditor: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 296k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
malob (a GitHub user) maintains it in malob/nix-config, which has 463 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 4, 2026.
Source: malob/nix-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.