claude-settings-audit
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local read-only shell commands including
ls,find, andcatto identify project frameworks and inspect existing configuration files like.claude/settings.jsonand.mcp.json. These operations are limited to the local environment and are essential for the skill's purpose of auditing repository settings. - [EXTERNAL_DOWNLOADS]: The skill recommends allowing network access to well-known and trusted documentation domains such as
docs.sentry.io,docs.github.com, and official framework sites (e.g.,react.dev,nextjs.org). These references are documented neutrally and target established technology providers. - [REMOTE_CODE_EXECUTION]: The skill includes a configuration template for the Linear MCP server that utilizes
npx -y @linear/mcp-server. Whilenpxinvolves remote code execution, this is provided as a recommendation for the user to manually add to their configuration for a well-known service and is not executed automatically by the skill during its audit phase.
Audit Metadata