Agent skill

Claude Code Permissions Auditor

by malob in malob/nix-config

Scans project-local Claude Code settings files, finds permission patterns worth promoting to global config, then cleans up what global now covers.

MITAuto-check passedAgent Workflows

Install Claude Code Permissions Auditor

skills CLI
$ npx skills add malob/nix-config --skill audit-permissions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install malob/nix-config audit-permissions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/malob/nix-config.git skills-src && mkdir -p .claude/skills && cp -r skills-src/configs/claude/plugins/cc-maintenance/skills/audit-permissions .claude/skills/audit-permissions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-permissions
GitHub stars
463
Token cost
~4.1k tokens
SKILL.md length
1,324 words
Files
4 (incl. scripts)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Scans project-local Claude Code settings files, finds permission patterns worth promoting to global config, then cleans up what global now covers.

  • Works in 3 steps: Promote to Global → Automated Redundancy Cleanup → Judgment Calls
  • Reviewing which project-local Claude Code permissions should become global
  • SKILL.md covers Workflow Overview, Initial Setup, Phase 1: Promote to Global and Phase 2: Automated Redundancy…, plus 5 more sections
  • Runs Python and Shell scripts from its folder; calls gh, git and nix

What it does

This skill runs as three sequential tasks: promoting candidate permissions to global config with the user's explicit decision on each one, an automated cleanup script that removes local permissions now redundant with those promotions, and a judgment-call phase covering security hygiene, policy conflicts, and one-off cruft.

Before touching anything it checks whether the global settings file is a symlink so edits land on the real target, loads the user's saved maintenance preferences if present, and reads the global CLAUDE.md for tool-preference policies it can check later conflicts against. A bundled discovery-and-extraction pipeline gathers the raw permission data before any categorization happens.

When your agent uses it

  • Reviewing which project-local Claude Code permissions should become global
  • Cleaning up redundant local permissions after a promotion
  • Auditing Claude Code settings for policy conflicts or stale entries

Example prompts

  • “Audit my Claude Code permissions and suggest what to promote to global.”
  • “Clean up redundant local permissions now that I've updated global settings.”
  • “Find permission patterns repeated across my projects.”

Requirements

  • Pre-approved tools (allowed-tools): Bash(*/audit-permissions/scripts/*), Bash(readlink *), Read(~/.claude/settings.json), Edit(~/.claude/settings.json), Write(~/.claude/settings.json), Read(**/.claude/settings.local.json), Edit(**/.claude/settings.local.json), Write(**/.claude/settings.local.json), Read(~/.claude/cc-maintenance.local.md), Edit(~/.claude/cc-maintenance.local.md), Write(~/.claude/cc-maintenance.local.md), Read(~/.claude/CLAUDE.md)

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Promote to Global
  2. Automated Redundancy Cleanup
  3. Judgment Calls

What it can do on your machine

Read from SKILL.md and the folder at commit 9cca0f4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(*/audit-permissions/scripts/*)
    • Bash(readlink *)
    • Read(~/.claude/settings.json)
    • Edit(~/.claude/settings.json)
    • Write(~/.claude/settings.json)
    • Read(**/.claude/settings.local.json)
    • Edit(**/.claude/settings.local.json)
    • Write(**/.claude/settings.local.json)
    • Read(~/.claude/cc-maintenance.local.md)
    • Edit(~/.claude/cc-maintenance.local.md)

    …and 2 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • git
    • nix
    • cargo
    • go
    • npm
    • deno
    • brew
    • xcodebuild

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Claude Code Permissions Auditor loads about 4.1k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 1,324 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from malob/nix-config at commit 9cca0f4, republished under its MIT licence (© malob). 1,324 words, ~4,102 tokens.

Download SKILL.mdSave it as .claude/skills/audit-permissions/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
audit-permissions
description
This skill should be used when the user asks to "audit claude permissions", "audit permissions", "review local claude settings", "promote permissions to global", "clean up claude settings", "find permission patterns", or wants to identify project-local Claude Code permissions that should be added to global configuration.
allowed-tools
Bash(*/audit-permissions/scripts/*), Bash(readlink *), Read(~/.claude/settings.json), Edit(~/.claude/settings.json), Write(~/.claude/settings.json), Read(**/.claude/settings.local.json), Edit(**/.claude/settings.local.json), Write(**/.claude/settings.local.json), Read(~/.claude/cc-maintenance.local.md), Edit(~/.claude/cc-maintenance.local.md), Write(~/.claude/cc-maintenance.local.md), Read(~/.claude/CLAUDE.md)

Audit Claude Permissions

Scan project-local Claude Code settings files, aggregate permission patterns, and recommend promotions to global configuration.

Workflow Overview

This audit runs in three phases, each as a separate task. Use TaskCreate at the start to create all three tasks, then work through them sequentially with user input via AskUserQuestion.

  • Phase 1: Promote to Global — Requires user judgment. Present candidates, get decisions, apply to global config.
  • Phase 2: Automated Redundancy Cleanup — Script-driven. After Phase 1 promotions, run cleanup script to remove local permissions now covered by global. Present for sanity-checking, then apply.
  • Phase 3: Judgment Calls — Everything requiring user input: security hygiene, policy conflicts, one-off cruft, empty file deletion, moderate-risk items.

Initial Setup

  1. Check for symlinked global settings:
bash
readlink -f ~/.claude/settings.json

If the global settings file is a symlink, note the real path. All writes to ~/.claude/settings.json must edit the symlink target, not create a new file that replaces the symlink.

  1. Load user preferences from ~/.claude/cc-maintenance.local.md (if it exists). See User Preferences section below. Apply any configured defaults (risk tolerance, auto-cleanup preference).

  2. Read global CLAUDE.md from ~/.claude/CLAUDE.md to identify tool preference policies for Phase 3 policy conflict detection.

  3. Run the discovery and extraction pipeline:

bash
scripts/discover-settings.sh | xargs scripts/extract-permissions.py
  1. Read the actual global settings from ~/.claude/settings.json — compare against the real allow list, not just the static examples in this skill.

  2. Create tasks for the three phases:

TaskCreate: "Review and promote permissions to global config"
TaskCreate: "Automated redundancy cleanup"
TaskCreate: "Judgment calls: security, policy, and cruft"
  1. Analyze the data and categorize permissions (see Categorization Rules below).

Phase 1: Promote to Global

Goal: Identify permissions worth adding to global config and get user approval.

Present Findings

Show a summary table of promotion candidates:

markdown
## Promotion Candidates

### Strong Recommendations (safe patterns, multiple projects)

| Permission | Projects | Suggested Global Pattern |
| ---------- | -------- | ------------------------ |
| ...        | ...      | ...                      |

### Moderate Recommendations (review carefully)

| Permission | Projects | Notes |
| ---------- | -------- | ----- |
| ...        | ...      | ...   |

### Cross-Project File Patterns

[If any Read/Write/Edit permissions reference paths outside their project directory
and appear in multiple projects, flag them here. Example: multiple projects have
`Write(~/.config/some-tool/config.json)` - might indicate a shared config worth
adding globally.]
Get User Decision

Use AskUserQuestion to let the user decide:

Question: "Which permissions should I add to global settings?"
Options:
- "Add all strong recommendations"
- "Add strong + moderate recommendations"
- "Let me pick specific ones" (then list individually)
- "Skip - don't add any"
Apply Changes

If user approves additions:

  1. Add selected permissions to ~/.claude/settings.json (or symlink target)
  2. Respect existing logical groupings (git, nix, gh, etc.)
  3. Sort alphabetically within groups
  4. Use space-syntax: Bash(cmd *) not Bash(cmd:*)
  5. Mark Phase 1 task as completed

Phase 2: Automated Redundancy Cleanup

Goal: Remove local permissions now covered by global config. This is mechanical — the script identifies exact matches; user just sanity-checks the list.

Preview Cleanup

Run the cleanup script in dry-run mode:

bash
scripts/discover-settings.sh | scripts/cleanup-redundant.py
Present Findings

Show what would be removed:

markdown
## Redundant Permissions

| File      | Permissions to Remove | Remaining |
| --------- | --------------------- | --------- |
| project-a | 5 (ls _, grep _, ...) | 12        |
| project-b | 3 (gh api \*, ...)    | 8         |
| ...       | ...                   | ...       |

**Total:** X permissions across Y files

The script also normalizes any remaining colon-syntax (Bash(cmd:*)) to space-syntax (Bash(cmd *)) when applying.

Get User Decision

If auto_cleanup_redundant: true in user preferences, skip the question and apply directly (still show the summary). Otherwise:

Question: "Should I remove these redundant permissions from local files?"
Options:
- "Yes, clean them up"
- "Show me the full list first"
- "Skip cleanup"
Apply Changes

If user approves:

bash
scripts/discover-settings.sh | scripts/cleanup-redundant.py --apply

Mark Phase 2 task as completed.


Phase 3: Judgment Calls

Goal: Everything that requires real user judgment — security risks, policy conflicts, stale cruft, and cleanup opportunities. Present all categories together.

Category A: Security Hygiene

Flag permissions that match these patterns:

High Risk (recommend removal):

  • Bash(curl *), Bash(wget *) — network exfiltration risk
  • Bash(rm *) — can delete any file
  • Bash(source *) — executes arbitrary scripts
  • Bash(eval *) — arbitrary code execution

Moderate Risk (review):

  • Bash(git reset *), Bash(git checkout *) — can discard work
  • Bash(pkill *), Bash(kill *) — process termination
  • Bash(python *), Bash(python3 *), Bash(node *) — arbitrary code (flag if user hasn't consciously chosen this)

Adjust what counts as "moderate" vs "high" based on the user's risk_tolerance preference if set.

Category B: Policy Conflicts

Read the user's global ~/.claude/CLAUDE.md for stated tool preferences. Flag local permissions that conflict with those policies.

How to detect: Look for patterns like "prefer X over Y", "use X instead of Y", "avoid Y". Then scan all local permissions for uses of the deprecated tool. For example:

If CLAUDE.md says "prefer tool X over built-in Y", flag all Y permissions across local settings as policy conflicts.

Present these as informational — the user may have valid reasons for specific overrides.

Category C: One-Off Cruft
  • Hardcoded file paths (e.g., Bash(prettier --write /full/path/to/file.md))
  • Incomplete shell constructs (Bash(done), Bash(for file in *.rs))
  • Very specific commands with no wildcards that look like debugging artifacts
  • Duplicate entries
  • Legacy colon-syntax permissions (Bash(cmd:*)) that weren't caught by the cleanup script (e.g., ones without a global equivalent)
Category D: Cross-Project File Access
  • Read, Write, or Edit permissions for paths outside the project
  • Flag if the same external path appears in multiple projects (potential global candidate)
  • Flag broad patterns like Write(~/.config/*) as security concerns
Category F: MCP Tool Permissions
  • Flag MCP tools with write/send/delete capabilities (message sending, data deletion, post creation) — these have side effects beyond the local environment
  • Flag server-wide wildcards (mcp__server__*) — convenient but auto-permits any future tools added to that server without review
  • Suggest consolidation: if all or most tools from a server are individually listed, suggest replacing with the server wildcard (with a note about the trade-off)
Category E: Empty File Deletion

After cleanup, identify settings files where:

  • All permissions have been removed (empty allow list or no allow list)
  • No other settings exist (no hooks, enabledPlugins, etc.)

Offer to delete these empty files entirely — they serve no purpose.

Present Findings
markdown
## Judgment Calls

### Security Hygiene

#### High Risk — Recommend Removal

| Permission     | Project   | Risk              |
| -------------- | --------- | ----------------- |
| `Bash(curl *)` | project-x | Data exfiltration |

#### Moderate Risk — Review

| Permission | Project | Risk |
| ---------- | ------- | ---- |
| ...        | ...     | ...  |

### Policy Conflicts

| Permission      | Projects | Policy                      |
| --------------- | -------- | --------------------------- |
| `WebFetch(url)` | 3        | CLAUDE.md: prefer Firecrawl |

### One-Off Cruft

| Permission                                         | Project   |
| -------------------------------------------------- | --------- |
| `Bash(prettier --write /path/to/specific/file.md)` | project-y |

### External File Access

| Permission                     | Projects   | Notes                           |
| ------------------------------ | ---------- | ------------------------------- |
| `Write(~/.config/tool/config)` | 3 projects | Shared config — consider global |
| `Edit(/etc/hosts)`             | 1 project  | System file — review necessity  |

### MCP Tool Permissions

| Permission                 | Projects | Notes                                       |
| -------------------------- | -------- | ------------------------------------------- |
| `mcp__slack__post_message` | 2        | Side effect: sends messages externally      |
| `mcp__puppeteer__*`        | 1        | Server wildcard — auto-permits future tools |

### Empty Settings Files

| File                                      | Reason                                     |
| ----------------------------------------- | ------------------------------------------ |
| `~/project-z/.claude/settings.local.json` | All permissions removed, no other settings |
Get User Decision

Use AskUserQuestion:

Question: "How should I handle the judgment call items?"
Options:
- "Remove all flagged items"
- "Remove high risk + cruft only"
- "Let me review each category"
- "Skip — keep everything"

If user wants to review categories, ask about each separately.

Show full SKILL.md (532 more words)Show less
Apply Changes

Edit each affected settings.local.json to remove approved items. Delete empty settings files if approved.

Mark Phase 3 task as completed.


Session Wrap-Up

After all phases complete, offer to create or update ~/.claude/cc-maintenance.local.md with session learnings. Include:

  • Any risk tolerance preferences expressed during the session
  • Tool preference notes mentioned during review
  • Freeform notes from user decisions (overrides, exceptions, per-project rules — anything the user said that should carry forward to future audits)
  • Session history entry (date, summary of changes)

User Preferences

Location: ~/.claude/cc-maintenance.local.md

Read at audit start. If missing, proceed with defaults. At session end, offer to create/update.

Format: YAML frontmatter for structured preferences + markdown body for freeform notes.

yaml
---
# All preferences are optional
risk_tolerance: moderate # conservative | moderate | aggressive
auto_cleanup_redundant: true
---
## Tool Preferences
- Prefer Exa/Firecrawl over built-in WebSearch/WebFetch

## Risk Notes
- sqlite3 and op item get considered moderate risk
- uv run python treated as arbitrary code execution

## Notes
- Always keep python3 permissions in the data-science project
- Don't consolidate Firecrawl tools into a server wildcard

## Session History
### 2026-02-09
- Promoted 13 permissions to global
- Removed ~220 cruft permissions from Assistant project

Behavior:

  • risk_tolerance adjusts what gets flagged as moderate vs high in Phase 3
  • auto_cleanup_redundant skips the confirmation prompt in Phase 2 (still shows summary)
  • Tool Preferences section supplements CLAUDE.md policy detection
  • Notes section is a freeform catch-all for any user preferences that don't fit the structured sections — overrides, exceptions, per-project rules, anything the agent should remember across audits
  • Session History provides context for future audits

Scripts

All scripts are in scripts/ relative to this skill directory.

  • scripts/discover-settings.sh — Finds all .claude/settings.local.json files across ~ using fd with sensible exclusions (Library, node_modules, .git, etc.). Max depth of 5 for performance.
  • scripts/extract-permissions.py — Aggregates permissions from multiple settings files. Outputs JSON with each permission, occurrence count, and list of projects using it. Sorted by count descending.
  • scripts/cleanup-redundant.py — Removes permissions from local files that are covered by global config. Handles cross-syntax matching (colon-syntax vs space-syntax). Normalizes remaining permissions to space-syntax on write. Dry-run by default; use --apply to modify files.

Usage examples:

bash
# Extract and aggregate all permissions
scripts/discover-settings.sh | xargs scripts/extract-permissions.py

# Preview redundant permission cleanup (dry-run, default)
scripts/discover-settings.sh | scripts/cleanup-redundant.py

# Actually remove redundant permissions
scripts/discover-settings.sh | scripts/cleanup-redundant.py --apply

Categorization Rules

Formatting Rules

Use space-syntax for all permissions: Bash(cmd *) not Bash(cmd:*).

Reasonable Global Candidates

Patterns worth promoting. These operate on local project code or perform read-only operations. Compare against the actual global config, not just this static list — these are examples of the kinds of patterns to look for.

Git Commands (read-only): git branch *, git diff *, git log *, git show *, git status *

File Inspection (read-only): cat *, head *, tail *, ls *, find *, grep *, du *

Build and Check Commands: cargo build *, cargo test *, cargo check *, go build *, go test *, npm run build *, npm run test *, deno check *, deno lint *, xcodebuild *

System Utilities: open *, pbcopy, pbpaste, lsof *, ps *

Nix Commands: nix build *, nix-build *, nix develop *, nix eval *, nix flake *, nix path-info *, nix-prefetch-url *, nh darwin build *

Homebrew (read-only): brew info *, brew search *

GitHub CLI: gh api *, gh issue list *, gh issue view *, gh pr list *, gh pr view *, gh pr diff *, gh pr checks *, gh search *, gh run list *, gh run view *

Wildcards: * --help *, * --version

Pattern Generalization

When promoting, generalize cautiously — only for safe patterns:

Local PatternGlobal PatternNotes
Bash(npm run build)Bash(npm run build *)Safe — runs project scripts
Bash(cargo test --release)Bash(cargo test *)Safe — tests local code
Bash(nix build .#package)Bash(nix build *)Safe — sandboxed builds
Bash(python3 script.py)Keep specific or skipRisky — arbitrary code
WebFetch(domain:github.com)Keep as-isDomain patterns don't change
Formatting Rules for Global Settings

When adding to ~/.claude/settings.json:

  • Respect existing logical groupings (git, file inspection, nix, brew, gh, system utilities, build tools, wildcards, Skills, MCP tools)
  • Within each group, sort alphabetically
  • Place new permissions in the appropriate group based on command prefix
  • Use space-syntax: Bash(cmd *) not Bash(cmd:*)

© malob, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts) in configs/claude/plugins/cc-maintenance/skills/audit-permissions of malob/nix-config.

  • SKILL.md
  • scripts/cleanup-redundant.py
  • scripts/discover-settings.sh
  • scripts/extract-permissions.py

Open the folder on GitHubat commit 9cca0f4

Compare with similar skills

Claude Code Permissions Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Claude Code Permissions Auditor compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Claude Code Permissions Auditor this skillmalob/nix-config463—~4.1kAutomated safety check: PassMIT
MCP Server Builderanthropics/skills180k64 repos~2.3kAutomated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k11 repos~4.1kAutomated safety check: NotesApache-2.0
Using Superpowersfarm-fe/farm5.6k35 repos~1.4kAutomated safety check: PassMIT
Executing Plans Inlineobra/superpowers296k2 repos~5.1kAutomated safety check: PassMIT
Claude Code Agent Developmentanthropics/claude-plugins-official38k8 repos~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • MCP Server Builder

    anthropics/skills

    Official

    Guides the design and implementation of Model Context Protocol servers in TypeScript or Python, from tool naming and error messages to evaluation.

    180k GitHub starsUsed in 64 repos~2.3k tokens
    Agent WorkflowsAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 11 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Using Superpowers

    farm-fe/farm

    A skill your agent uses when starting any conversation - establishes how to find and use skills, requiring Skill tool invocation before ANY response including clarifying questions

    5.6k GitHub starsUsed in 35 repos~1.4k tokens
    Agent WorkflowsAuto-check passed
  • Executing Plans Inline

    obra/superpowers

    Has the agent carry out an implementation plan itself, task by task in the current session, keeping a ledger, proving each step with a test and ending with one whole-branch review.

    296k GitHub starsUsed in 2 repos~5.1k tokens
    Agent WorkflowsAuto-check passed
  • Claude Code Agent Development

    anthropics/claude-plugins-official

    Official

    Explains how to write agents for Claude Code plugins: the markdown file with YAML frontmatter, trigger descriptions, model and color settings, and system prompt design.

    38k GitHub starsUsed in 8 repos~2.8k tokens
    Agent WorkflowsAuto-check passed
  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    795 GitHub starsUsed in 89 repos~8.2k tokens
    Agent WorkflowsAuto-check passed

More from malob/nix-config

  • Deep Research Team

    malob/nix-config

    Coordinates a team of researcher agents across several rounds, with a lead who triages findings, assigns follow-ups and cross-checks key claims.

    463 GitHub starsUsed in 1 repo~5.8k tokens
    Auto-check passed
  • Nerd Font Icon Lookup

    malob/nix-config

    Works around Claude Code filtering private-use Unicode so agents can read and write Nerd Font icons in Starship, tmux and prompt configs.

    463 GitHub stars~697 tokensUpdated 4 days ago
    Auto-check passed
  • Homebrew Cask Creator

    malob/nix-config

    Coordinates specialist agents to create a Homebrew cask for a macOS app: pre-flight checks, download and inspection, a livecheck strategy and the remaining cask steps.

    463 GitHub stars~1.6k tokensUpdated 4 days ago
    Auto-check passed
  • Web Research Search Tips

    malob/nix-config

    Practical guidance for multi-source web research with Exa, the Firecrawl CLI and Reddit MCP tools: when to search, when to fetch and which tool to prefer.

    463 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed

Categories

Questions about Claude Code Permissions Auditor

What does Claude Code Permissions Auditor do?

Scans project-local Claude Code settings files, finds permission patterns worth promoting to global config, then cleans up what global now covers. This skill runs as three sequential tasks: promoting candidate permissions to global config with the user's explicit decision on each one, an automated cleanup script that removes local permissions now redundant with those promotions, and a judgment-call phase covering security hygiene, policy conflicts, and one-off cruft.

When should I use Claude Code Permissions Auditor?

Claude Code Permissions Auditor fits situations like: reviewing which project-local Claude Code permissions should become global; cleaning up redundant local permissions after a promotion; auditing Claude Code settings for policy conflicts or stale entries.

How do I install Claude Code Permissions Auditor in Claude Code?

Run `npx skills add malob/nix-config --skill audit-permissions -a claude-code`. Or copy the skill folder (configs/claude/plugins/cc-maintenance/skills/audit-permissions in malob/nix-config) into .claude/skills/audit-permissions in your project. Claude Code loads it when a task matches its description.

How do I install Claude Code Permissions Auditor in Codex?

Run `npx skills add malob/nix-config --skill audit-permissions -a codex`. Or copy the skill folder (configs/claude/plugins/cc-maintenance/skills/audit-permissions in malob/nix-config) into .agents/skills/audit-permissions in your project. Codex loads it when a task matches its description.

Can I use Claude Code Permissions Auditor in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add malob/nix-config --skill audit-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-permissions, .gemini/skills/audit-permissions, .github/skills/audit-permissions and .opencode/skills/audit-permissions in your project.

What does Claude Code Permissions Auditor need to run?

Going by SKILL.md and its folder, Claude Code Permissions Auditor needs Python and a shell for the scripts in its folder and the command-line tools its instructions call (gh, git, nix, cargo, go and npm). Its frontmatter pre-approves these tools: Bash(*/audit-permissions/scripts/*), Bash(readlink *), Read(~/.claude/settings.json), Edit(~/.claude/settings.json), Write(~/.claude/settings.json), Read(**/.claude/settings.local.json), Edit(**/.claude/settings.local.json), Write(**/.claude/settings.local.json), Read(~/.claude/cc-maintenance.local.md), Edit(~/.claude/cc-maintenance.local.md), Write(~/.claude/cc-maintenance.local.md), Read(~/.claude/CLAUDE.md).

Does Claude Code Permissions Auditor access the network?

SKILL.md contains no URLs. Its commands use gh, git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Claude Code Permissions Auditor safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Claude Code Permissions Auditor use?

Claude Code Permissions Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Claude Code Permissions Auditor use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Claude Code Permissions Auditor?

Skills that share tags, products or a category with Claude Code Permissions Auditor: MCP Server Builder (anthropics/skills, 180k stars), Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars), Using Superpowers (farm-fe/farm, 5.6k stars) and Executing Plans Inline (obra/superpowers, 296k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Claude Code Permissions Auditor?

malob (a GitHub user) maintains it in malob/nix-config, which has 463 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 4, 2026.

Source: malob/nix-config on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.