Agent skill

Claude Code Settings Audit

by vinta in vinta/hal-9000

Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work.

MITAuto-check passedAgent Workflows

Install Claude Code Settings Audit

skills CLI
$ npx skills add vinta/hal-9000 --skill audit-claude-settings -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinta/hal-9000 audit-claude-settings --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-claude-settings .claude/skills/audit-claude-settings && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-claude-settings
GitHub stars
138
Token cost
~1.4k tokens
SKILL.md length
738 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work.

  • Works in 5 steps: Fetch ground truth → Collect the user's real config → Cross-reference → …
  • Checking whether your settings.json uses current keys and avoids deprecated ones
  • SKILL.md covers 1. Fetch ground truth, 2. Collect the user's real…, 3. Cross-reference and 4. Report, plus 2 more sections
  • Calls curl, git and python3; reaches code.claude.com and json.schemastore.org

What it does

This skill fetches three raw documentation pages from code.claude.com (settings, the settings reference and environment variables) with curl into a scratch folder and treats them as the only acceptable source for the scan. It searches the settings index and the variables table for the full key lists, reads the full entry of every key you set for defaults, deprecations and precedence, and reads the settings page for scope rules.

It then collects your real configuration from every settings scope that exists, including user, project, local and managed files, runs git diff on a dotfiles repo when that is the source of truth, and reads CLAUDE.md files, rules and auto-memory for workflow signals such as plugins, hooks, aliases, permission style and model choice. After two exhaustive cross-reference passes it delivers a ranked report in which each suggestion is tied to a named fact about you, and it applies the changes you pick. Allowed tools are limited to those curl calls, python3 -m json.tool, strings and reading under ~/.claude.

When your agent uses it

  • Checking whether your settings.json uses current keys and avoids deprecated ones
  • Finding Claude Code settings or env vars that would suit your workflow
  • Reviewing permission and hook configuration against the latest docs

Example prompts

  • “Audit my Claude Code settings against the latest docs and rank what I should change.”
  • “Check whether any env vars I set are deprecated or have better alternatives.”
  • “Compare my dotfiles copy of settings.json with the docs and apply the changes I pick.”

Requirements

  • Network access to code.claude.com
  • curl
  • Pre-approved tools (allowed-tools): Bash(curl -sfL https://code.claude.com/*), Bash(python3 -m json.tool:*), Bash(strings:*), Read(~/.claude/**)

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Fetch ground truth
  2. Collect the user's real config
  3. Cross-reference
  4. Report
  5. Apply

What it can do on your machine

Read from SKILL.md and the folder at commit 46dc048. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(curl -sfL https://code.claude.com/*)
    • Bash(python3 -m json.tool:*)
    • Bash(strings:*)
    • Read(~/.claude/**)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • code.claude.com
    • json.schemastore.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Claude Code Settings Audit loads about 1.4k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 738 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinta/hal-9000 at commit 46dc048, republished under its MIT licence (© vinta). 738 words, ~1,362 tokens.

Download SKILL.mdSave it as .claude/skills/audit-claude-settings/SKILL.md (or your agent's skills folder).
name
audit-claude-settings
description
Use when auditing Claude Code settings and env vars against the latest docs to suggest tailored changes
allowed-tools
Bash(curl -sfL https://code.claude.com/*), Bash(python3 -m json.tool:*), Bash(strings:*), Read(~/.claude/**)

Audit Claude Code Settings

Scan the three reference pages exhaustively, cross-reference them against the user's real config, deliver a ranked report, and apply what the user picks. Tie every suggestion to a named user fact — tailored, not generic.

1. Fetch ground truth

bash
curl -sfL https://code.claude.com/docs/en/settings.md -o <scratchpad>/cc-docs-settings.md
curl -sfL https://code.claude.com/docs/en/settings-reference.md -o <scratchpad>/cc-docs-settings-reference.md
curl -sfL https://code.claude.com/docs/en/env-vars.md -o <scratchpad>/cc-docs-env-vars.md

Every docs page has a raw markdown mirror at its URL plus .md. <scratchpad> is your session's scratchpad directory, or /tmp when the harness provides none. -f makes a missing page a failed command instead of a silently saved 404 body. These three files are the only acceptable source for the scan.

settings-reference.md holds every key: the table under its ## Settings index heading is one row per key with purpose, topic, and scope, and each key has a ### \key`entry below.env-vars.mdlists every variable as one table row under## Variables, and that row is its whole entry. Grep both for the full lists, then read the ###entry of every key the user sets in full — the entries carry the defaults, deprecations, and precedence the index table omits. Readsettings.md` whole for scope and precedence rules. The first line of each file points to https://code.claude.com/docs/llms.txt, the index of every docs page, for follow-ups such as permission rule syntax, hooks, and sandboxing.

2. Collect the user's real config

Read every settings scope that exists: ~/.claude/settings.json, .claude/settings.json, .claude/settings.local.json, and the OS's managed settings file if present. When a dotfiles repo is the source of truth, read the repo copy and run git diff on it — uncommitted drift matters in step 5.

Read ~/.claude/CLAUDE.md, the project CLAUDE.md, rules files, and auto-memory. These carry the workflow signals that make suggestions tailored: plugins, hooks, shell aliases, permission style, model choice, terminal, background-agent habits.

Done when you hold one list of every key and env var the user sets, plus a short profile of how they work.

3. Cross-reference

Two passes, both exhaustive:

  • Validate (set → docs). Check every user key against all three files. Absent from all three → dead-key candidate; confirm against the binary (see Gotchas) before proposing removal. Named a legacy alias → propose the migration. Default or semantics changed → flag it. No key skipped.
  • Discover (docs → unset). Walk every documented key and variable once. Keep a candidate only when a specific user fact argues for it, and name that fact in the item.

4. Report

Open with problems in the current config, ranked by impact. Then grouped suggestions: security, workflow, small ideas. Close with leave-alone items — attractive switches that break something the user relies on (example: the blanket telemetry kills also disable Remote Control, cross-session messages, and auto-updates).

Each item carries the key, what it does in one line, and the user fact that makes it relevant.

Show full SKILL.md (294 more words)Show less

5. Apply

Offer the picks with AskUserQuestion, multiSelect, grouped like the report. When the settings file already has uncommitted changes, commit those first as their own commit.

Apply the picks and validate with python3 -m json.tool after edits — invalid JSON makes Claude Code skip the whole file. Say which picks land later, per the "When edits take effect" section of settings.md.

Gotchas

  • WebFetch answers through a small summarizer model. On a "list everything" prompt against a long page it truncates, and on a "continue the list" prompt it fabricates plausible keys (observed: rubyCrimsionPath). The raw .md mirror is the ground truth; fetch it with curl and read it yourself.
  • Undocumented is not the same as dead. A key can live on a different docs page — skillOverrides sat on the skills page before the settings page listed it. Grep all three files, then check llms.txt pages, before you call a key dead.
  • The installed CLI binary has the final say on undocumented keys and env vars: strings -a "$(which claude)" | grep -o -E '.{300}<name>.{300}'. Zero hits means dead; hits mean live code reads it, and the surrounding minified code tells you what it actually does — read it before proposing any change. Observed both failure modes: a docs-only audit flagged skipAutoPermissionPrompt dead while a migration in the binary still read it, and CLAUDE_CODE_SUBPROCESS_ENV_SCRUB=1 turned out to force every session to start in default (manual) permission mode, silently overriding defaultMode: "auto" with no warning shown.
  • The $schema line (https://json.schemastore.org/claude-code-settings.json) gives editors validation, but the published schema lags new CLI releases. A schema warning on a recently documented key is not proof of a dead key.
  • Docs churn fast. Results from a previous audit go stale; fetch fresh files every run, and treat remembered page content as expired.

© vinta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/audit-claude-settings of vinta/hal-9000.

Open the folder on GitHubat commit 46dc048

Compare with similar skills

Claude Code Settings Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Claude Code Settings Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Claude Code Settings Audit this skillvinta/hal-9000138—~1.4kAutomated safety check: PassMIT
Using Agent Skillsaddyosmani/agent-skills103k4 repos~2.4kAutomated safety check: PassMIT
Claude ReflectBayramAnnakov/claude-reflect1.7k2 repos~627Automated safety check: PassMIT
Neat-Freak Knowledge CloseoutKKKKhazix/khazix-skills21k—~1.9kAutomated safety check: PassMIT
Writing For Agentsbestofjs/bestofjs3.1k18 repos~2.7kAutomated safety check: PassMIT
Task Observerrebelytics/one-skill-to-rule-them-all3.2k1 repos~12kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Using Agent Skills

    addyosmani/agent-skills

    Meta-skill for choosing which workflow skill fits the task at hand, plus always-on habits: surface assumptions, stop on confusion, push back, keep it simple and stay in scope.

    103k GitHub starsUsed in 4 repos~2.4k tokens
    Agent WorkflowsAuto-check passed
  • Claude Reflect

    BayramAnnakov/claude-reflect

    Self-learning system that captures corrections during sessions and reminds users to run /reflect to update CLAUDE.md.

    1.7k GitHub starsUsed in 2 repos~627 tokens
    Agent WorkflowsAuto-check passed
  • Neat-Freak Knowledge Closeout

    KKKKhazix/khazix-skills

    Brings project docs, agent rule files, authorized memory and leftover workspace files back in line with what the code and runtime actually do at the end of a work session.

    21k GitHub stars~1.9k tokensUpdated 8 days ago
    Agent WorkflowsAuto-check passed
  • Writing For Agents

    bestofjs/bestofjs

    Writing documents for agents. An agent skill from bestofjs/bestofjs.

    3.1k GitHub starsUsed in 18 repos~2.7k tokens
    Agent WorkflowsAuto-check passed
  • Task Observer

    rebelytics/one-skill-to-rule-them-all

    Monitors task execution for skill improvement opportunities.

    3.2k GitHub starsUsed in 1 repo~12k tokens
    Agent WorkflowsAuto-check passed
  • SkillOpt Sleep Cycle

    microsoft/SkillOpt

    Official

    Runs an on-demand or nightly sleep cycle that reviews past Claude Code sessions and proposes validated updates to CLAUDE.md and skills.

    18k GitHub stars~2.3k tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed

More from vinta/hal-9000

All 15 skills in this repo
  • Finds which plugins in the repository changed, bumps only the ones not already bumped since origin/main, and checks that each plugin's two manifests stay in sync.

    138 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Logical Git Commits

    vinta/hal-9000

    Commits everything in the working tree as one logical change per commit, splitting files by hunk, with bodies that say what was wrong before and never an invented reason.

    138 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • PR

    vinta/hal-9000

    A skill your agent uses when the user explicitly asks to push the current branch and open a PR, rewrite an open PR's body from its commits, or wait for CI and merge it

    138 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Keeps Ansible install tasks in line with upstream docs by fixing version, install-method and link drift one tool at a time, with a commit for each.

    138 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Rewrites docs, READMEs, issues, comments or UI text in plain Global English that translates well and still sounds native, keeping every fact intact.

    138 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Best Practices

    vinta/hal-9000

    A skill your agent uses when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current…

    138 GitHub stars~553 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Claude Code Settings Audit

What does Claude Code Settings Audit do?

Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work. com (settings, the settings reference and environment variables) with curl into a scratch folder and treats them as the only acceptable source for the scan. It searches the settings index and the variables table for the full key lists, reads the full entry of every key you set for defaults, deprecations and precedence, and reads the settings page for scope rules.

When should I use Claude Code Settings Audit?

Claude Code Settings Audit fits situations like: checking whether your settings.json uses current keys and avoids deprecated ones; finding Claude Code settings or env vars that would suit your workflow; reviewing permission and hook configuration against the latest docs.

How do I install Claude Code Settings Audit in Claude Code?

Run `npx skills add vinta/hal-9000 --skill audit-claude-settings -a claude-code`. Or copy the skill folder (skills/audit-claude-settings in vinta/hal-9000) into .claude/skills/audit-claude-settings in your project. Claude Code loads it when a task matches its description.

How do I install Claude Code Settings Audit in Codex?

Run `npx skills add vinta/hal-9000 --skill audit-claude-settings -a codex`. Or copy the skill folder (skills/audit-claude-settings in vinta/hal-9000) into .agents/skills/audit-claude-settings in your project. Codex loads it when a task matches its description.

Can I use Claude Code Settings Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinta/hal-9000 --skill audit-claude-settings -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-claude-settings, .gemini/skills/audit-claude-settings, .github/skills/audit-claude-settings and .opencode/skills/audit-claude-settings in your project.

What does Claude Code Settings Audit need to run?

Going by SKILL.md and its folder, Claude Code Settings Audit needs the command-line tools its instructions call (curl, git and python3). Our summary lists: Network access to code.claude.com; curl. Its frontmatter pre-approves these tools: Bash(curl -sfL https://code.claude.com/*), Bash(python3 -m json.tool:*), Bash(strings:*), Read(~/.claude/**).

Does Claude Code Settings Audit access the network?

SKILL.md names 2 domains. In commands or code: code.claude.com and json.schemastore.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Claude Code Settings Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Claude Code Settings Audit use?

Claude Code Settings Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Claude Code Settings Audit use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Claude Code Settings Audit?

Skills that share tags, products or a category with Claude Code Settings Audit: Using Agent Skills (addyosmani/agent-skills, 103k stars), Claude Reflect (BayramAnnakov/claude-reflect, 1.7k stars), Neat-Freak Knowledge Closeout (KKKKhazix/khazix-skills, 21k stars) and Writing For Agents (bestofjs/bestofjs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Claude Code Settings Audit?

vinta (a GitHub user) maintains it in vinta/hal-9000, which has 138 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.

Source: vinta/hal-9000 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.