config-audit
Run a full audit of the user's Claude Code configuration via the Agent Monitor Config Explorer API: counts per surface (user vs project), duplicate or overlapping skills and subagents, hooks that run shell commands, and which surfaces are read-only vs mutable.
Install / Use
npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill config-auditInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
OperationsSupported Platforms
Our assessment of config-audit
config-audit scores 85/100 on our quality scale, 484th of 736 Operations skills we index.
Its SKILL.md is 3.9 KB long, well organised into 9 sections and no code examples: a solid amount of guidance for an agent.
With 1,015 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 12 days ago, so config-audit is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
config-audit compared with similar skills
All 4 of these similar skills score higher than config-audit; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| config-audit (this skill)by hoangsonww | 85 | 1.0k | 12d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 92.4k | 21d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.9k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.8k | 1d ago | MCP Server |
Frequently asked questions
- How do I install config-audit?
- Run
npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill config-audit. The install tabs above show the steps for each supported agent. - Which AI agents does config-audit work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is config-audit safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is config-audit still maintained?
- The repository was last updated 12 days ago, so config-audit is actively maintained.
Skill content
View source on GitHubname: config-audit description: > Run a full audit of the user's Claude Code configuration via the Agent Monitor Config Explorer API: counts per surface (user vs project), duplicate or overlapping skills and subagents, hooks that run shell commands, and which surfaces are read-only vs mutable. Reads /api/cc-config/overview, /skills, /agents, /commands, /hooks, and /settings. Use when reviewing your Claude Code setup for sprawl, duplication, or risk.
Config Audit
Produce a complete, data-backed audit of how the user's ~/.claude
configuration has grown, what overlaps, and what is risky — all read through
the Agent Monitor dashboard at http://localhost:4820.
Input
The user provides: $ARGUMENTS
This may be:
- empty or "full" — audit every surface (default).
- "skills" / "agents" / "commands" / "hooks" / "settings" — scope the audit to one surface only.
- a project path passed as
?cwd=— to audit a project other than the dashboard server's own working directory.
Data Sources
| Endpoint | Returns |
|----------|---------|
| GET /api/cc-config/overview | roots + counts for every surface, split {user,project} where applicable (skills, agents, commands, outputStyles, plugins, mcpServers, hooks, memory, settingsFiles) |
| GET /api/cc-config/skills | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } |
| GET /api/cc-config/agents | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } |
| GET /api/cc-config/commands | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } |
| GET /api/cc-config/hooks | { items:[{ scope, file, exists, hooks:{ <Event>:[{matcher,type,command,timeout}] } }] } |
| GET /api/cc-config/settings | { items:[{ scope, file, exists, data(redacted), raw_size }] } |
Report Sections
1. Surface inventory (user vs project)
From /overview counts, print a table: one row per surface with user,
project, and total columns. Cover skills, agents, commands, output-styles,
plugins (with enabled/disabled), marketplaces, MCP servers, hooks
(user/project/project-local), memory, and settings files. Echo the resolved
roots so the user knows which claudeHome/project was inspected.
2. Duplicate & overlapping skills + agents
Fetch /skills and /agents. Detect:
- Name collisions across scope — same
nameat both user and project scope (project shadows user). List bothfilepaths. - Near-duplicates — entries whose
frontmatter.description/previewdescribe the same job. Group them and recommend keeping one.
3. Hooks that run shell commands
Flatten /hooks to (scope, file, Event, matcher, type, command, timeout).
Flag every type: "command" entry. Within those, escalate ones that contain
network egress (curl, wget, http, nc) or run unbounded with no
timeout. Print the raw command so the user can review it.
4. Read-only vs mutable surfaces
State which surfaces the Config Explorer can mutate (skills, agents, commands,
output-styles, user/project CLAUDE.md, and per-project auto-memory files via
PUT/DELETE /api/cc-config/file) versus those that are read-only by design
(plugins, MCP servers, settings.json and its in-file hooks — written
concurrently by the running CLI). Direct cleanup suggestions only at mutable
surfaces; for read-only ones, name the source file to edit by hand.
Output
- A one-line verdict first: CLEAN / SPRAWL DETECTED / RISKY HOOKS.
- Section 1 as a Markdown table (
Surface | User | Project | Total). - Section 2 as grouped lists with
filepaths. - Section 3 as a table (
Scope | Event | Matcher | Command | Risk). - Sizes in KB; any cost in USD to 4 decimals; use ▲/▼ for scope deltas.
- Cite only fields the API returned — never fabricate counts or commands.
- If the dashboard is unreachable at
http://localhost:4820, say so and tell the user to start it withnpm startfrom the repo root.
Related Skills
Agent-Reach
92.4kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.9k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.8kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
