claude-settings-audit

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local read-only shell commands including ls, find, and cat to identify project frameworks and inspect existing configuration files like .claude/settings.json and .mcp.json. These operations are limited to the local environment and are essential for the skill's purpose of auditing repository settings.
  • [EXTERNAL_DOWNLOADS]: The skill recommends allowing network access to well-known and trusted documentation domains such as docs.sentry.io, docs.github.com, and official framework sites (e.g., react.dev, nextjs.org). These references are documented neutrally and target established technology providers.
  • [REMOTE_CODE_EXECUTION]: The skill includes a configuration template for the Linear MCP server that utilizes npx -y @linear/mcp-server. While npx involves remote code execution, this is provided as a recommendation for the user to manually add to their configuration for a well-known service and is not executed automatically by the skill during its audit phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 04:36 AM