claude-settings-audit
Analyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
npx skills add sickn33/agentic-awesome-skills --skill claude-settings-audit --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
# Claude Settings Audit Analyze this repository and generate recommended Claude Code `settings.json` permissions for read-only commands. ## When to Use - You are setting up or auditing Claude Code `settings.json` permissions for a repository. - You need to infer a safe read-only allow list from the repo's tech stack, tooling, and monorepo structure. - You want to review or replace an existing Claude permissions baseline with something evidence-based. ## Phase 1: Detect Tech Stack Run these commands to detect the repository structure: ```bash ls -la find . -maxdepth 2 \( -name "*.toml" -o -name "*.json" -o -name "*.lock" -o -name "*.yaml" -o -name "*.yml" -o -name "Makefile" -o -name "Dockerfile" -o -name "*.tf" \) 2>/dev/null | head -50 ``` Check for these indicator files: | Category | Files to Check | | ------------ | ------------------------------------------------------------------------------------- | | **Python** | `pyproject.toml`, `setup.py`, `requirements.txt`, `Pipfile`, `poetry.lock`, `uv.lock` | | **Node.js** | `package.json`, `package-lock.json`, `yarn.lock`, `pnpm-lock.yaml` | | **Go** | `go.mod`, `go.sum` | | **Rust** | `Cargo.toml`, `Cargo.lock` | | **Ruby** | `Gemfi
- When to Use
- Phase 1: Detect Tech Stack
- Phase 2: Detect Services
- Phase 3: Check Existing Settings
- Phase 4: Generate Recommendations
- Baseline Commands (Always Include)
- Stack-Specific Commands
- Skills (for Sentry Projects)
- WebFetch Domains
- MCP Server Suggestions
- Output Format
- Important Rules
- What to Include
- What to NEVER Include
ls -la cat .claude/settings.json 2>/dev/null || echo "No existing settings" cat .mcp.json 2>/dev/null || echo "No existing .mcp.json"
What does the claude-settings-audit skill do?
Analyze a repository to generate recommended Claude Code settings.json permissions. Use when setting up a new project, auditing existing settings, or determining which read-only bash commands to allow. Detects tech stack, build tools, and monorepo structure.
How do I install it?
Run `npx skills add sickn33/agentic-awesome-skills --skill claude-settings-audit --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From sickn33/agentic-awesome-skills, a repository with 44,414 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.