SkillAgentSearch skills...

config-audit

Run a full audit of the user's Claude Code configuration via the Agent Monitor Config Explorer API: counts per surface (user vs project), duplicate or overlapping skills and subagents, hooks that run shell commands, and which surfaces are read-only vs mutable.

Install / Use

npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill config-audit

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

85/100

Category

Operations

Supported Platforms

Claude Code

Our assessment of config-audit

config-audit scores 85/100 on our quality scale, 484th of 736 Operations skills we index.

Its SKILL.md is 3.9 KB long, well organised into 9 sections and no code examples: a solid amount of guidance for an agent.

With 1,015 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
26/30
Structure
13/20
Description
15/15
Adoption
13/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 12 days ago, so config-audit is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

config-audit compared with similar skills

All 4 of these similar skills score higher than config-audit; compare them before choosing.

SkillScoreStarsUpdatedFormat
config-audit (this skill)by hoangsonww851.0k12d agoSKILL.md
Agent-Reachby Panniantong10092.4k21d agoCLAUDE.md
headroomby headroomlabs-ai10074.5ktodayCLAUDE.md
Scraplingby D4Vinci10085.9ktodayMCP Server
crawl4aiby unclecode10084.8k1d agoMCP Server

Frequently asked questions

How do I install config-audit?
Run npx skills add hoangsonww/Claude-Code-Agent-Monitor --skill config-audit. The install tabs above show the steps for each supported agent.
Which AI agents does config-audit work with?
It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
Is config-audit safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is config-audit still maintained?
The repository was last updated 12 days ago, so config-audit is actively maintained.

name: config-audit description: > Run a full audit of the user's Claude Code configuration via the Agent Monitor Config Explorer API: counts per surface (user vs project), duplicate or overlapping skills and subagents, hooks that run shell commands, and which surfaces are read-only vs mutable. Reads /api/cc-config/overview, /skills, /agents, /commands, /hooks, and /settings. Use when reviewing your Claude Code setup for sprawl, duplication, or risk.

Config Audit

Produce a complete, data-backed audit of how the user's ~/.claude configuration has grown, what overlaps, and what is risky — all read through the Agent Monitor dashboard at http://localhost:4820.

Input

The user provides: $ARGUMENTS

This may be:

  • empty or "full" — audit every surface (default).
  • "skills" / "agents" / "commands" / "hooks" / "settings" — scope the audit to one surface only.
  • a project path passed as ?cwd= — to audit a project other than the dashboard server's own working directory.

Data Sources

| Endpoint | Returns | |----------|---------| | GET /api/cc-config/overview | roots + counts for every surface, split {user,project} where applicable (skills, agents, commands, outputStyles, plugins, mcpServers, hooks, memory, settingsFiles) | | GET /api/cc-config/skills | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } | | GET /api/cc-config/agents | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } | | GET /api/cc-config/commands | { items:[{ scope, name, file, size, mtime, frontmatter, preview }] } | | GET /api/cc-config/hooks | { items:[{ scope, file, exists, hooks:{ <Event>:[{matcher,type,command,timeout}] } }] } | | GET /api/cc-config/settings | { items:[{ scope, file, exists, data(redacted), raw_size }] } |

Report Sections

1. Surface inventory (user vs project)

From /overview counts, print a table: one row per surface with user, project, and total columns. Cover skills, agents, commands, output-styles, plugins (with enabled/disabled), marketplaces, MCP servers, hooks (user/project/project-local), memory, and settings files. Echo the resolved roots so the user knows which claudeHome/project was inspected.

2. Duplicate & overlapping skills + agents

Fetch /skills and /agents. Detect:

  • Name collisions across scope — same name at both user and project scope (project shadows user). List both file paths.
  • Near-duplicates — entries whose frontmatter.description / preview describe the same job. Group them and recommend keeping one.

3. Hooks that run shell commands

Flatten /hooks to (scope, file, Event, matcher, type, command, timeout). Flag every type: "command" entry. Within those, escalate ones that contain network egress (curl, wget, http, nc) or run unbounded with no timeout. Print the raw command so the user can review it.

4. Read-only vs mutable surfaces

State which surfaces the Config Explorer can mutate (skills, agents, commands, output-styles, user/project CLAUDE.md, and per-project auto-memory files via PUT/DELETE /api/cc-config/file) versus those that are read-only by design (plugins, MCP servers, settings.json and its in-file hooks — written concurrently by the running CLI). Direct cleanup suggestions only at mutable surfaces; for read-only ones, name the source file to edit by hand.

Output

  • A one-line verdict first: CLEAN / SPRAWL DETECTED / RISKY HOOKS.
  • Section 1 as a Markdown table (Surface | User | Project | Total).
  • Section 2 as grouped lists with file paths.
  • Section 3 as a table (Scope | Event | Matcher | Command | Risk).
  • Sizes in KB; any cost in USD to 4 decimals; use ▲/▼ for scope deltas.
  • Cite only fields the API returned — never fabricate counts or commands.
  • If the dashboard is unreachable at http://localhost:4820, say so and tell the user to start it with npm start from the repo root.

Related Skills

View on GitHub
GitHub Stars1.0k
CategoryOperations
Updated12d ago
Forks238

Languages

JavaScript

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions