Using Agent Skills
addyosmani/agent-skills
Meta-skill for choosing which workflow skill fits the task at hand, plus always-on habits: surface assumptions, stop on confusion, push back, keep it simple and stay in scope.
Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work.
$ npx skills add vinta/hal-9000 --skill audit-claude-settings -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinta/hal-9000 audit-claude-settings --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/audit-claude-settings .claude/skills/audit-claude-settings && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "audit-claude-settings" agent skill from https://github.com/vinta/hal-9000/tree/main/skills/audit-claude-settings into .claude/skills/audit-claude-settings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-claude-settings", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinta/hal-9000/tree/main/skills/audit-claude-settingsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinta/hal-9000 --skill audit-claude-settings -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinta/hal-9000 audit-claude-settings --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/audit-claude-settings .agents/skills/audit-claude-settings && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "audit-claude-settings" agent skill from https://github.com/vinta/hal-9000/tree/main/skills/audit-claude-settings into .agents/skills/audit-claude-settings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-claude-settings", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinta/hal-9000 --skill audit-claude-settings -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinta/hal-9000 audit-claude-settings --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/audit-claude-settings .cursor/skills/audit-claude-settings && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "audit-claude-settings" agent skill from https://github.com/vinta/hal-9000/tree/main/skills/audit-claude-settings into .cursor/skills/audit-claude-settings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-claude-settings", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinta/hal-9000.git --path skills/audit-claude-settings--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinta/hal-9000 --skill audit-claude-settings -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinta/hal-9000 audit-claude-settings --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/audit-claude-settings .gemini/skills/audit-claude-settings && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "audit-claude-settings" agent skill from https://github.com/vinta/hal-9000/tree/main/skills/audit-claude-settings into .gemini/skills/audit-claude-settings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-claude-settings", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinta/hal-9000 audit-claude-settingsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinta/hal-9000 --skill audit-claude-settings -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/audit-claude-settings .github/skills/audit-claude-settings && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "audit-claude-settings" agent skill from https://github.com/vinta/hal-9000/tree/main/skills/audit-claude-settings into .github/skills/audit-claude-settings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-claude-settings", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinta/hal-9000 --skill audit-claude-settings -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinta/hal-9000 audit-claude-settings --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinta/hal-9000.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/audit-claude-settings .opencode/skills/audit-claude-settings && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "audit-claude-settings" agent skill from https://github.com/vinta/hal-9000/tree/main/skills/audit-claude-settings into .opencode/skills/audit-claude-settings/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "audit-claude-settings", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
audit-claude-settingsAudits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work.
This skill fetches three raw documentation pages from code.claude.com (settings, the settings reference and environment variables) with curl into a scratch folder and treats them as the only acceptable source for the scan. It searches the settings index and the variables table for the full key lists, reads the full entry of every key you set for defaults, deprecations and precedence, and reads the settings page for scope rules.
It then collects your real configuration from every settings scope that exists, including user, project, local and managed files, runs git diff on a dotfiles repo when that is the source of truth, and reads CLAUDE.md files, rules and auto-memory for workflow signals such as plugins, hooks, aliases, permission style and model choice. After two exhaustive cross-reference passes it delivers a ranked report in which each suggestion is tied to a named fact about you, and it applies the changes you pick. Allowed tools are limited to those curl calls, python3 -m json.tool, strings and reading under ~/.claude.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 46dc048. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash(curl -sfL https://code.claude.com/*)Bash(python3 -m json.tool:*)Bash(strings:*)Read(~/.claude/**)From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlgitpython3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
code.claude.comjson.schemastore.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Claude Code Settings Audit loads about 1.4k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 738 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinta/hal-9000 at commit 46dc048, republished under its MIT licence (© vinta). 738 words, ~1,362 tokens.
.claude/skills/audit-claude-settings/SKILL.md (or your agent's skills folder).Scan the three reference pages exhaustively, cross-reference them against the user's real config, deliver a ranked report, and apply what the user picks. Tie every suggestion to a named user fact — tailored, not generic.
curl -sfL https://code.claude.com/docs/en/settings.md -o <scratchpad>/cc-docs-settings.md
curl -sfL https://code.claude.com/docs/en/settings-reference.md -o <scratchpad>/cc-docs-settings-reference.md
curl -sfL https://code.claude.com/docs/en/env-vars.md -o <scratchpad>/cc-docs-env-vars.mdEvery docs page has a raw markdown mirror at its URL plus .md. <scratchpad> is your session's scratchpad directory, or /tmp when the harness provides none. -f makes a missing page a failed command instead of a silently saved 404 body. These three files are the only acceptable source for the scan.
settings-reference.md holds every key: the table under its ## Settings index heading is one row per key with purpose, topic, and scope, and each key has a ### \key`entry below.env-vars.mdlists every variable as one table row under## Variables, and that row is its whole entry. Grep both for the full lists, then read the ###entry of every key the user sets in full — the entries carry the defaults, deprecations, and precedence the index table omits. Readsettings.md` whole for scope and precedence rules. The first line of each file points to https://code.claude.com/docs/llms.txt, the index of every docs page, for follow-ups such as permission rule syntax, hooks, and sandboxing.
Read every settings scope that exists: ~/.claude/settings.json, .claude/settings.json, .claude/settings.local.json, and the OS's managed settings file if present. When a dotfiles repo is the source of truth, read the repo copy and run git diff on it — uncommitted drift matters in step 5.
Read ~/.claude/CLAUDE.md, the project CLAUDE.md, rules files, and auto-memory. These carry the workflow signals that make suggestions tailored: plugins, hooks, shell aliases, permission style, model choice, terminal, background-agent habits.
Done when you hold one list of every key and env var the user sets, plus a short profile of how they work.
Two passes, both exhaustive:
Open with problems in the current config, ranked by impact. Then grouped suggestions: security, workflow, small ideas. Close with leave-alone items — attractive switches that break something the user relies on (example: the blanket telemetry kills also disable Remote Control, cross-session messages, and auto-updates).
Each item carries the key, what it does in one line, and the user fact that makes it relevant.
Offer the picks with AskUserQuestion, multiSelect, grouped like the report. When the settings file already has uncommitted changes, commit those first as their own commit.
Apply the picks and validate with python3 -m json.tool after edits — invalid JSON makes Claude Code skip the whole file. Say which picks land later, per the "When edits take effect" section of settings.md.
rubyCrimsionPath). The raw .md mirror is the ground truth; fetch it with curl and read it yourself.skillOverrides sat on the skills page before the settings page listed it. Grep all three files, then check llms.txt pages, before you call a key dead.strings -a "$(which claude)" | grep -o -E '.{300}<name>.{300}'. Zero hits means dead; hits mean live code reads it, and the surrounding minified code tells you what it actually does — read it before proposing any change. Observed both failure modes: a docs-only audit flagged skipAutoPermissionPrompt dead while a migration in the binary still read it, and CLAUDE_CODE_SUBPROCESS_ENV_SCRUB=1 turned out to force every session to start in default (manual) permission mode, silently overriding defaultMode: "auto" with no warning shown.$schema line (https://json.schemastore.org/claude-code-settings.json) gives editors validation, but the published schema lags new CLI releases. A schema warning on a recently documented key is not proof of a dead key.© vinta, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/audit-claude-settings of vinta/hal-9000.
Open the folder on GitHubat commit 46dc048
Claude Code Settings Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Claude Code Settings Audit this skillvinta/hal-9000 | 138 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Using Agent Skillsaddyosmani/agent-skills | 103k | 4 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Claude ReflectBayramAnnakov/claude-reflect | 1.7k | 2 repos | ~627 | Automated safety check: Pass | MIT | |
| Neat-Freak Knowledge CloseoutKKKKhazix/khazix-skills | 21k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Writing For Agentsbestofjs/bestofjs | 3.1k | 18 repos | ~2.7k | Automated safety check: Pass | MIT | |
| Task Observerrebelytics/one-skill-to-rule-them-all | 3.2k | 1 repos | ~12k | Automated safety check: Pass | CC-BY-4.0 |
addyosmani/agent-skills
Meta-skill for choosing which workflow skill fits the task at hand, plus always-on habits: surface assumptions, stop on confusion, push back, keep it simple and stay in scope.
BayramAnnakov/claude-reflect
Self-learning system that captures corrections during sessions and reminds users to run /reflect to update CLAUDE.md.
KKKKhazix/khazix-skills
Brings project docs, agent rule files, authorized memory and leftover workspace files back in line with what the code and runtime actually do at the end of a work session.
bestofjs/bestofjs
Writing documents for agents. An agent skill from bestofjs/bestofjs.
rebelytics/one-skill-to-rule-them-all
Monitors task execution for skill improvement opportunities.
microsoft/SkillOpt
Runs an on-demand or nightly sleep cycle that reviews past Claude Code sessions and proposes validated updates to CLAUDE.md and skills.
vinta/hal-9000
Finds which plugins in the repository changed, bumps only the ones not already bumped since origin/main, and checks that each plugin's two manifests stay in sync.
vinta/hal-9000
Commits everything in the working tree as one logical change per commit, splitting files by hunk, with bodies that say what was wrong before and never an invented reason.
vinta/hal-9000
A skill your agent uses when the user explicitly asks to push the current branch and open a PR, rewrite an open PR's body from its commits, or wait for CI and merge it
vinta/hal-9000
Keeps Ansible install tasks in line with upstream docs by fixing version, install-method and link drift one tool at a time, with a commit for each.
vinta/hal-9000
Rewrites docs, READMEs, issues, comments or UI text in plain Global English that translates well and still sounds native, keeping every fact intact.
vinta/hal-9000
A skill your agent uses when about to choose, configure, or refine a tool, library, config format, API pattern, or project setup, or before proposing a design of your own — research current…
Categories
Audits your Claude Code settings and environment variables against the current official docs and returns a ranked list of changes tied to how you actually work. com (settings, the settings reference and environment variables) with curl into a scratch folder and treats them as the only acceptable source for the scan. It searches the settings index and the variables table for the full key lists, reads the full entry of every key you set for defaults, deprecations and precedence, and reads the settings page for scope rules.
Claude Code Settings Audit fits situations like: checking whether your settings.json uses current keys and avoids deprecated ones; finding Claude Code settings or env vars that would suit your workflow; reviewing permission and hook configuration against the latest docs.
Run `npx skills add vinta/hal-9000 --skill audit-claude-settings -a claude-code`. Or copy the skill folder (skills/audit-claude-settings in vinta/hal-9000) into .claude/skills/audit-claude-settings in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinta/hal-9000 --skill audit-claude-settings -a codex`. Or copy the skill folder (skills/audit-claude-settings in vinta/hal-9000) into .agents/skills/audit-claude-settings in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinta/hal-9000 --skill audit-claude-settings -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-claude-settings, .gemini/skills/audit-claude-settings, .github/skills/audit-claude-settings and .opencode/skills/audit-claude-settings in your project.
Going by SKILL.md and its folder, Claude Code Settings Audit needs the command-line tools its instructions call (curl, git and python3). Our summary lists: Network access to code.claude.com; curl. Its frontmatter pre-approves these tools: Bash(curl -sfL https://code.claude.com/*), Bash(python3 -m json.tool:*), Bash(strings:*), Read(~/.claude/**).
SKILL.md names 2 domains. In commands or code: code.claude.com and json.schemastore.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Claude Code Settings Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Claude Code Settings Audit: Using Agent Skills (addyosmani/agent-skills, 103k stars), Claude Reflect (BayramAnnakov/claude-reflect, 1.7k stars), Neat-Freak Knowledge Closeout (KKKKhazix/khazix-skills, 21k stars) and Writing For Agents (bestofjs/bestofjs, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinta (a GitHub user) maintains it in vinta/hal-9000, which has 138 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 8, 2026.
Source: vinta/hal-9000 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.