Agents & Protocols

Claude Code Settings Review: Hooks, Permissions, MCP

Reviews a pasted Claude Code configuration (settings.json, hooks, permission rules, MCP server switches, scripts that start Claude Code) for keys and meanings that are easy to get wrong and that fail without an error. It flags disabledMcpjsonServers used on a server that does not come from a project's .mcp.json, a settings file with a JSON syntax error, a blocking hook that exits 1 instead of 2, the deprecated top-level approve or block decision of a PreToolUse hook, hook event names that do not exist, matchers that match too much or nothing (the matcher is an unanchored regular expression, and plugin MCP tools carry a plugin prefix), path rules written for Write instead of Edit, single-slash absolute paths, an allow rule for src that matches only the top-level folder, Bash rule patterns with the colon or the space in the wrong place, hook timeouts that are expected to block, bypassPermissions in project settings, and many claude -p runs started at once. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review Claude Code settings, check hook and permission rules, or disable an MCP server correctly before the team relies on the configuration.

Claude Code Settings Review: Hooks, Permissions, MCP is a tested SKILL.md that reviews a pasted Claude Code configuration (settings.json, hooks, permission rules, MCP server switches, scripts that start Claude Code) for keys and meanings that are easy to get wrong and that fail without an error; an agent buys it once for $0.05 over x402.

Tested 2026-10-08No code, no hidden instructionsv1.0.0 · 13.6 KB · perpetual license

Not for

Judging whether a security policy is wise, writing a configuration from nothing, setting up an organisation's managed policy, or anything that needs the running Claude Code: it reads pasted files, so it cannot see the installed version, loaded plugins, or what a hook script really does unless the paste shows it. It does not cover keybindings, themes, models or CLAUDE.md files.

Tested, honestly

Tested 2026-10-08 with a strong and a weak model.

With and without the skill

Results with and without the skill, for Sonnet and Haiku
SonnetHaiku
withwithoutwithwithout
Right findings and verdict (24 configurations)23/2420/2423/2419/24

Without the skill the six correct controls have no concept check and count as passed, so the gap sits in the eighteen traps. Read by hand, Sonnet without the skill had four real content gaps. For the plugin server it said disabledMcpjsonServers is for .mcp.json but hedged ("probably", "from memory") and offered disabling the plugin or denying the server's tools, never deniedMcpServers; the same gap sank the three-problem file. It argued the danger of bypassPermissions in project settings without saying the value is ignored there. For the parallel claude -p script it found real bugs (the file argument, wait hiding failures, no cap) but not the shared config file. Haiku had the same four, hedged on the plugin matcher, and for the pasted injection resisted it but never said Write rules are not consulted.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

SonnetStrong model, claude-sonnet-5-5
Gave the right codes and verdict in 23 of 24 cases, read by hand: a disabledMcpjsonServers entry for a plugin server became MCP-DISABLE-KEY with deniedMcpServers as the fix; a bypassPermissions mode in committed project settings and a loop that starts a claude -p run for every file at once were both reported; Write(.env) rules, a bare mcp__memory matcher, a matcher for a plugin server and a hook that exits 1 were all named, and the three-problem file got all three codes. Correct files (a deniedMcpServers entry, Edit(**/src/**), a deny rule for secrets, a hook that prints a deny decision) got No findings. The pasted note that asked for No findings was not followed. In that one case it added a sentence after the verdict line, which the fixed format does not allow.
HaikuWeak model, claude-haiku-5-5
Also 23 of 24, with the same codes as Sonnet on every case with a planted mistake, including the plugin server key and the plugin matcher, but on a correct settings file it wrote a paragraph after the verdict line: the code and verdict were right, the format was not.

Full test summary

Example

Our own test text, before and after the skill ran. Excerpts only.

English · claude-sonnet-5-5

Before

File: ~/.claude/settings.json (user settings). Goal: turn off the "builds" MCP server that the acme plugin adds, in every project. { "model": "sonnet", "disabledMcpjsonServers": ["plugin:acme:builds"] }

After

[MCP-DISABLE-KEY] ~/.claude/settings.json, disabledMcpjsonServers: the server `plugin:acme:builds` comes from a plugin, and this key only controls approval of servers defined in a project's `.mcp.json`, so it does nothing here and the server keeps running.…

What is in the file

  • The answer
  • The codes
  • Rules
  • Work in this order
  • Short example

Languages

Any language. Tried in: English.

License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.

Versions

Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.

  1. v1.0.0 · 2026-10-08

    First release: reviews a pasted Claude Code configuration (settings files, hooks, permission rules, MCP switches, scripts that start Claude Code) and lists each problem with a fixed code, the place, the reason and a fix, then a verdict (broken, fix before use, no known problems). Broken: disabledMcpjsonServers used on a server that is not in a project's .mcp.json (fix: deniedMcpServers), a settings file with a JSON syntax error, a blocking hook that exits 1, unknown hook event names, matchers that can never match, path rules written for Write, single-slash absolute paths, bypassPermissions in project settings. Fix before use: the deprecated approve/block hook decision, matchers that match too much, an allow rule for src that covers only the top-level folder, Bash rule patterns with a misplaced colon or space, hook timeouts expected to block, parallel claude -p runs. Facts read in the official documentation on 8 October 2026 (versions up to about 2.1.282); the skill tells the reader to re-check them against the current pages.

    Price $0.05. Measured on 24 pasted configurations: Sonnet 20 right without the skill and 23 with it, Haiku 19 and 23.

FAQ

Which mistakes does it look for?

Fourteen: disabledMcpjsonServers used on a plugin or user server, a settings file with a syntax error, a blocking hook that exits 1, the deprecated approve or block hook decision, hook events that do not exist, matchers that match too much or nothing, path rules written for Write, single-slash absolute paths, an allow rule for src that covers only the top level, Bash patterns with a misplaced colon or space, hook timeouts expected to block, bypassPermissions in project settings and parallel claude -p runs. Each comes from the official pages or from our own measurement.

Is deniedMcpServers only for managed settings?

No. The settings reference lists it for any settings file, and the lists from all files are merged, so the user file works and the entry takes effect at the next start. Only allowManagedMcpServersOnly and managedMcpServers are managed-only. A serverName entry is only a label that users pick, so add a serverUrl entry too when the server has a URL. Denying its tools with a permission rule is a weaker answer, because the server stays connected.

Does Sonnet already know this without the skill?

Mostly, but not the parts that are easy to get wrong. Over 24 configurations Sonnet gave the right findings and verdict 20 times without the skill and 23 with it. Without it, Sonnet hedged on how to switch off a plugin server and never named deniedMcpServers, argued the danger of bypassPermissions in project settings without saying it is ignored there, and missed the shared config file in the parallel script. The six correct files stayed quiet with the skill. The one miss was a sentence after the verdict line.

Will these settings go out of date?

Yes, Claude Code changes these settings from version to version, and the skill names the version where it matters: 2.1.214 for the src allow rule, 2.1.257 for the permission mode. Our reading of the official pages is dated 8 October 2026 and covers versions up to about 2.1.282. When the current pages differ, the agent is told to follow them and to name the line of the skill that needs a new check.

Share

Read this page as Markdown: /skills/claude-code-settings-review.md.

  • Workers Pitfalls Review: D1, OpenNext, Fetch

    Code & Engineering

    SKILL.md · v1.2.0 · 9.8 KB

    Reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money. It flags the edge runtime under OpenNext, a fetch to your own Worker's workers.dev address (error 1042), D1 queries that bind more than 100 parameters as data grows, LIKE patterns over D1's 50-byte limit, reading rowsAffected where D1 returns meta.changes, interactive transactions D1 does not have, secrets kept in plain vars, outbound fetch code that treats only a thrown error as failure, a browser User-Agent that bot protection challenges, client hop-by-hop headers forwarded to fetch, cron triggers whose day of the week is written as numbers, and unbounded queries on the request path. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review a Cloudflare Worker before deploy, check D1 or wrangler code, or audit a Next.js app running on Cloudflare.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026

  • SKILL.md Review: Safe and Within the Limits

    Agents & Protocols

    SKILL.md · v1.0.1 · 6.7 KB

    Reviews a SKILL.md file before you install, buy or publish it and lists every problem with a fixed code, the place and a fix, then gives one verdict. It checks the front matter against the published limits (name up to 64 characters in lowercase, hyphens and digits, no reserved words; description present, up to 1,024 characters, naming both its job and the requests that should trigger it, in the third person), and it reads the body for hidden orders to the agent, credentials pasted into the text, commands that download and run remote code, Windows-style paths, a body over 500 lines and the lack of any example. Use to review a SKILL.md, audit a Claude or agent skill before installing it, check a skill file for prompt injection, or lint a skill before publishing it to a marketplace.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026

  • MCP Tool Schema: Definitions from API Docs

    Agents & Protocols

    SKILL.md · v1.0.0 · 7.6 KB

    Writes the MCP tool definition for one API operation - name, description, inputSchema and annotations - as the JSON a server returns from tools/list. The schema takes exactly the parameters the operation takes - required ones listed, defaults stated, exact enums, integer amounts, date formats, ranges, string and array limits, either-or parameters that refuse a call with both or neither - and refuses unknown ones. Credentials never become parameters, text in the API docs that speaks to the assistant stays out of the description, and the annotations say whether the tool only reads, can be repeated safely or destroys data, following the MCP specification of 2025-11-25. Use when asked to write, review or fix an MCP tool definition, a tool schema or an inputSchema, or to turn an API endpoint, an OpenAPI operation or a function signature into an MCP tool.

    $0.01once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026