agent-config-audit
Audit AI agent configuration files for security risks.
What it is
Audit AI agent configuration files for security risks: one command reads the files that launch and instruct a coding agent (.claude/settings*.json, .mcp.json, claude_desktop_config.json, .cursor/ rules and MCP config, CLAUDE.md, AGENTS.md, plugin manifests, hooks, skills) and reports pre-approved dangerous commands, bypassed permission prompts, secrets committed next to server definitions, unpinned MCP servers, hooks that phone home, and prompt-injection patterns hidden in instruction files. Output as a table, JSON, Markdown or SARIF for GitHub code scanning. Read-only, standard library only, no network, deterministic.
Install
pipx install git+https://github.com/basitalisandhu/agent-config-audit
cd your-project
agent-config-audit # table on stdout, exit 0
agent-config-audit --fail-on high # exit 1 when a high or critical finding exists
agent-config-audit --format sarif --output agent-config-audit.sarif
agent-config-audit --include-home # also ~/.claude, ~/.cursor, the Claude Desktop config
From the README; see the full README for every option.
Links
Releases
Topics: agent-security, ai-agents, ai-security, claude-code, cli, configuration-audit, cursor, devsecops, github-actions, hacktoberfest, llm-security, mcp, pre-commit, prompt-injection, python, sarif, secrets-detection, security-automation, security-tools