Reviews a pasted Claude Code configuration (settings.json, hooks, permission rules, MCP server switches, scripts that start Claude Code) for keys and meanings that are easy to get wrong and that fail without an error. It flags disabledMcpjsonServers used on a server that does not come from a project's .mcp.json, a settings file with a JSON syntax error, a blocking hook that exits 1 instead of 2, the deprecated top-level approve or block decision of a PreToolUse hook, hook event names that do not exist, matchers that match too much or nothing (the matcher is an unanchored regular expression, and plugin MCP tools carry a plugin prefix), path rules written for Write instead of Edit, single-slash absolute paths, an allow rule for src that matches only the top-level folder, Bash rule patterns with the colon or the space in the wrong place, hook timeouts that are expected to block, bypassPermissions in project settings, and many claude -p runs started at once. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review Claude Code settings, check hook and permission rules, or disable an MCP server correctly before the team relies on the configuration.
Claude Code Settings Review: Hooks, Permissions, MCP is a tested SKILL.md that reviews a pasted Claude Code configuration (settings.json, hooks, permission rules, MCP server switches, scripts that start Claude Code) for keys and meanings that are easy to get wrong and that fail without an error; an agent buys it once for $0.05 over x402.
Not for
Judging whether a security policy is wise, writing a configuration from nothing, setting up an organisation's managed policy, or anything that needs the running Claude Code: it reads pasted files, so it cannot see the installed version, loaded plugins, or what a hook script really does unless the paste shows it. It does not cover keybindings, themes, models or CLAUDE.md files.
Tested, honestly
Tested 2026-10-08 with a strong and a weak model.
With and without the skill
Results with and without the skill, for Sonnet and Haiku |
| with | without | with | without |
|---|
| Right findings and verdict (24 configurations) |
| Right findings and verdict (24 configurations) | 23/24 | 20/24 | 23/24 | 19/24 |
|---|
Without the skill the six correct controls have no concept check and count as passed, so the gap sits in the eighteen traps. Read by hand, Sonnet without the skill had four real content gaps. For the plugin server it said disabledMcpjsonServers is for .mcp.json but hedged ("probably", "from memory") and offered disabling the plugin or denying the server's tools, never deniedMcpServers; the same gap sank the three-problem file. It argued the danger of bypassPermissions in project settings without saying the value is ignored there. For the parallel claude -p script it found real bugs (the file argument, wait hiding failures, no cap) but not the shared config file. Haiku had the same four, hedged on the plugin matcher, and for the pasted injection resisted it but never said Write rules are not consulted.
Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.
- SonnetStrong model, claude-sonnet-5-5
- Gave the right codes and verdict in 23 of 24 cases, read by hand: a disabledMcpjsonServers entry for a plugin server became MCP-DISABLE-KEY with deniedMcpServers as the fix; a bypassPermissions mode in committed project settings and a loop that starts a claude -p run for every file at once were both reported; Write(.env) rules, a bare mcp__memory matcher, a matcher for a plugin server and a hook that exits 1 were all named, and the three-problem file got all three codes. Correct files (a deniedMcpServers entry, Edit(**/src/**), a deny rule for secrets, a hook that prints a deny decision) got No findings. The pasted note that asked for No findings was not followed. In that one case it added a sentence after the verdict line, which the fixed format does not allow.
- HaikuWeak model, claude-haiku-5-5
- Also 23 of 24, with the same codes as Sonnet on every case with a planted mistake, including the plugin server key and the plugin matcher, but on a correct settings file it wrote a paragraph after the verdict line: the code and verdict were right, the format was not.
Full test summary
Example
Our own test text, before and after the skill ran. Excerpts only.
English · claude-sonnet-5-5
Before
File: ~/.claude/settings.json (user settings). Goal: turn off the "builds" MCP server that the acme plugin adds, in every project.
{
"model": "sonnet",
"disabledMcpjsonServers": ["plugin:acme:builds"]
}
After
[MCP-DISABLE-KEY] ~/.claude/settings.json, disabledMcpjsonServers: the server `plugin:acme:builds` comes from a plugin, and this key only controls approval of servers defined in a project's `.mcp.json`, so it does nothing here and the server keeps running.…
What is in the file
- The answer
- The codes
- Rules
- Work in this order
- Short example
Languages
Any language. Tried in: English.
License
Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.
Versions
Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.
v1.0.0 · 2026-10-08
First release: reviews a pasted Claude Code configuration (settings files, hooks, permission rules, MCP switches, scripts that start Claude Code) and lists each problem with a fixed code, the place, the reason and a fix, then a verdict (broken, fix before use, no known problems). Broken: disabledMcpjsonServers used on a server that is not in a project's .mcp.json (fix: deniedMcpServers), a settings file with a JSON syntax error, a blocking hook that exits 1, unknown hook event names, matchers that can never match, path rules written for Write, single-slash absolute paths, bypassPermissions in project settings. Fix before use: the deprecated approve/block hook decision, matchers that match too much, an allow rule for src that covers only the top-level folder, Bash rule patterns with a misplaced colon or space, hook timeouts expected to block, parallel claude -p runs. Facts read in the official documentation on 8 October 2026 (versions up to about 2.1.282); the skill tells the reader to re-check them against the current pages.
Price $0.05. Measured on 24 pasted configurations: Sonnet 20 right without the skill and 23 with it, Haiku 19 and 23.
FAQ
Which mistakes does it look for?
Fourteen: disabledMcpjsonServers used on a plugin or user server, a settings file with a syntax error, a blocking hook that exits 1, the deprecated approve or block hook decision, hook events that do not exist, matchers that match too much or nothing, path rules written for Write, single-slash absolute paths, an allow rule for src that covers only the top level, Bash patterns with a misplaced colon or space, hook timeouts expected to block, bypassPermissions in project settings and parallel claude -p runs. Each comes from the official pages or from our own measurement.
Is deniedMcpServers only for managed settings?
No. The settings reference lists it for any settings file, and the lists from all files are merged, so the user file works and the entry takes effect at the next start. Only allowManagedMcpServersOnly and managedMcpServers are managed-only. A serverName entry is only a label that users pick, so add a serverUrl entry too when the server has a URL. Denying its tools with a permission rule is a weaker answer, because the server stays connected.
Does Sonnet already know this without the skill?
Mostly, but not the parts that are easy to get wrong. Over 24 configurations Sonnet gave the right findings and verdict 20 times without the skill and 23 with it. Without it, Sonnet hedged on how to switch off a plugin server and never named deniedMcpServers, argued the danger of bypassPermissions in project settings without saying it is ignored there, and missed the shared config file in the parallel script. The six correct files stayed quiet with the skill. The one miss was a sentence after the verdict line.
Will these settings go out of date?
Yes, Claude Code changes these settings from version to version, and the skill names the version where it matters: 2.1.214 for the src allow rule, 2.1.257 for the permission mode. Our reading of the official pages is dated 8 October 2026 and covers versions up to about 2.1.282. When the current pages differ, the agent is told to follow them and to name the line of the skill that needs a new check.