Install
$ agentstack add skill-teddy563-mcwrench-audit-config ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Audit Config
Scan a Minecraft server's config files and produce a prioritised, actionable report.
Procedure
- Locate the config tree. Look for, at the server root and per-world folders:
server.properties, bukkit.yml, spigot.yml, paper-global.yml, paper-world-defaults.yml, */paper-world.yml, purpur.yml, velocity.toml, config/ plugin folders. Use Glob/Grep/Read. If only pasted text is available, audit that.
- Read each present file and check against the reference checklists:
references/paper-global-checklist.md— server-wide Paper settings + proxy forwarding.references/common-footguns.md— the high-frequency mistakes that crash or lag servers.
- Cross-file consistency (the part single-file linters miss):
online-modevs proxy forwarding: behind Velocity/Bungee the backend must run
online-mode=false AND have modern forwarding configured, or skins/UUIDs break.
- Never both
spigot.yml: bungeecord: trueandpaper-global.yml: proxies.velocity.enabled: true— the server won't start. view-distanceinserver.propertiesvsspigot.yml/paper-world.yml— the lower wins per-world; flag silent mismatches.proxies.velocity.secretpresent and not the literal default/empty;forwarding.secretmatches the proxy.
- Security pass:
- RCON: if
enable-rcon=true, confirm a strongrcon.passwordand that the port is
firewalled / loopback-bound — never publicly exposed. (Critical if exposed.)
online-mode=falsewithout a proxy in front = crackable server (high, unless intended).
- Performance pass: view-distance/simulation-distance sanity for the player count,
entity-activation-range present, mob spawn limits set, entity-per-chunk-save-limit caps for experience_orb/arrow/ender_pearl, hopper tuning. Defer deep tuning to the performance-tuning skill but flag obvious wins here.
- YAML hygiene: detect literal tab characters (YAML forbids tabs — a common silent
breakage), duplicate keys, and values that should be quoted.
- Plugin conflict pass: run
check-conflicts.mjsto flag mutually exclusive plugins (two
skyblock engines, two claim systems, ItemsAdder + Oraxen), missing deps (Vault without an economy, LibsDisguises without ProtocolLib), and proxy/Folia mismatches. Verify any hit with learn-plugin-docs before recommending a removal.
Reporting format
Group findings by severity and give each a one-line fix:
CRITICAL — will crash or lose data
- [file:key] problem → fix
HIGH — lag or security
- …
MEDIUM — quality / maintainability
LOW — style / nitpick
End with a short "Looks good" list of things that are already correct, so the user trusts the audit. If a referenced plugin's keys are unfamiliar, call the learn-plugin-docs skill before judging them — do not invent keys.
Helper scripts
- Seed the audit by scanning the tree:
``bash node "${CLAUDE_PLUGIN_ROOT}/skills/audit-config/scripts/scan-server-tree.mjs" # detects software, config files, worlds, plugins, key settings, and tab-character warnings # add --json for machine-readable output ``
- Find paper-world.yml overrides (you should only override keys you mean to):
``bash node "${CLAUDE_PLUGIN_ROOT}/skills/audit-config/scripts/diff-against-defaults.mjs" \ /paper-world.yml paper-world-defaults.yml ``
- Check plugin conflicts / missing deps (uses
references/conflict-rules.json+ the profile):
``bash node "${CLAUDE_PLUGIN_ROOT}/skills/audit-config/scripts/check-conflicts.mjs" # or --list "LuckPerms,EssentialsX,Vault" or --profile (add --json for machine output) ``
- Write the server profile so later answers stop re-asking version/host/stack:
``bash node "${CLAUDE_PLUGIN_ROOT}/skills/audit-config/scripts/scan-server-tree.mjs" --write-profile ` All are read-only on the scanned tree (only --write-profile writes, into mcwrench's _cache/`) and run on stock Node ≥18. Use them to orient, then read the flagged files.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Teddy563
- Source: Teddy563/mcwrench
- License: MIT
- Homepage: https://mcwrench.teddy.bar
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.