AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Config Audit

skill-hoangsonww-claude-code-agent-monitor-config-audit · by hoangsonww

>

No reviews yet
0 installs
21 views
0.0% view→install

Install

$ agentstack add skill-hoangsonww-claude-code-agent-monitor-config-audit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-hoangsonww-claude-code-agent-monitor-config-audit)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Config Audit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Config Audit

Produce a complete, data-backed audit of how the user's ~/.claude configuration has grown, what overlaps, and what is risky — all read through the Agent Monitor dashboard at http://localhost:4820.

Input

The user provides: $ARGUMENTS

This may be:

  • empty or "full" — audit every surface (default).
  • "skills" / "agents" / "commands" / "hooks" / "settings" — scope the audit to

one surface only.

  • a project path passed as ?cwd= — to audit a project other than the

dashboard server's own working directory.

Data Sources

| Endpoint | Returns | |----------|---------| | GET /api/cc-config/overview | roots + counts for every surface, split {user,project} where applicable (skills, agents, commands, outputStyles, plugins, mcpServers, hooks, memory, settingsFiles) | | GET /api/cc-config/skills | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } | | GET /api/cc-config/agents | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } | | GET /api/cc-config/commands | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } | | GET /api/cc-config/hooks | { items:[{ scope, file, exists, hooks:{ :[{matcher,type,command,timeout}] } }] } | | GET /api/cc-config/settings | { items:[{ scope, file, exists, data(redacted), raw_size }] } |

Report Sections

1. Surface inventory (user vs project)

From /overview counts, print a table: one row per surface with user, project, and total columns. Cover skills, agents, commands, output-styles, plugins (with enabled/disabled), marketplaces, MCP servers, hooks (user/project/project-local), memory, and settings files. Echo the resolved roots so the user knows which claudeHome/project was inspected.

2. Duplicate & overlapping skills + agents

Fetch /skills and /agents. Detect:

  • Name collisions across scope — same name at both user and project

scope (project shadows user). List both file paths.

  • Near-duplicates — entries whose frontmatter.description / preview

describe the same job. Group them and recommend keeping one.

3. Hooks that run shell commands

Flatten /hooks to (scope, file, Event, matcher, type, command, timeout). Flag every type: "command" entry. Within those, escalate ones that contain network egress (curl, wget, http, nc) or run unbounded with no timeout. Print the raw command so the user can review it.

4. Read-only vs mutable surfaces

State which surfaces the Config Explorer can mutate (skills, agents, commands, output-styles, user/project CLAUDE.md, and per-project auto-memory files via PUT/DELETE /api/cc-config/file) versus those that are read-only by design (plugins, MCP servers, settings.json and its in-file hooks — written concurrently by the running CLI). Direct cleanup suggestions only at mutable surfaces; for read-only ones, name the source file to edit by hand.

Output

  • A one-line verdict first: CLEAN / SPRAWL DETECTED / RISKY HOOKS.
  • Section 1 as a Markdown table (Surface | User | Project | Total).
  • Section 2 as grouped lists with file paths.
  • Section 3 as a table (Scope | Event | Matcher | Command | Risk).
  • Sizes in KB; any cost in USD to 4 decimals; use ▲/▼ for scope deltas.
  • Cite only fields the API returned — never fabricate counts or commands.
  • If the dashboard is unreachable at http://localhost:4820, say so and tell

the user to start it with npm start from the repo root.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.