Reviewing Runtime Configuration

Reviews Claude Code settings and hook definitions for security, permission scoping, and command safety. Use when reviewing changes to .claude/settings.json, .claude/settings.local.json, or hooks.json in a repository or plugin. Flags local settings appearing in a changeset, hardcoded secrets, filesystem-wide permissions, dangerous auto-approvals, and hook commands that exfiltrate data or route their input into a shell. Also use when asked to review hooks, audit permissions, or check what runs without a prompt. Normally reached through `reviewing-claude-config`, which runs an always-on secret scan and a finding filter first.

bitwarden ff3fc88 14.6 KB Updated

File contents

bitwarden/ai-plugins/tree/main/plugins/claude-config-validator/skills/reviewing-runtime-configuration commit ff3fc88302

Frequently asked questions

npx skillmds@latest add bitwarden/reviewing-runtime-configuration