From agent-config-audit
Audit AI agent instruction files (AGENTS.override.md, AGENTS.md, configured fallbacks, CLAUDE.md, hooks, and settings) across workspaces in read-only report mode. Use when agent configs drift, rules duplicate, files go stale, or after workspace restructuring; apply fixes only when explicitly requested.
How this skill is triggered — by the user, by Claude, or both
Slash command
/agent-config-audit:agent-config-auditWhen to use
audit AGENTS.md, audit CLAUDE.md, agent config audit, sync agent configs, check AGENTS.md, docs out of date, rules duplicated, config drift, stale cursorrules, agent config maintenance
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Inputs:
Inputs:
Outputs:
Creates/Modifies:
.agents/ docs, and related settings, but only
after an explicit fix request and confirmation of the exact planExternal Side Effects:
Confirmation Required:
Delegates To:
rules-capture for single new preferencesagent-folder-init for missing .agents/ structuresession-documenter when audit findings should be recordedbug or refactor-dispatchauditlinter-formatter-init.agents/ from scratch → use agent-folder-init| Input | Required | Description |
|---|---|---|
| Workspace root | Yes | Path to the workspace containing repos (auto-detected from cwd) |
| Scope | No | full (all checks) or specific: dedup, stale, instructions, cursor, settings |
| Fix mode | No | report (default, read-only) or fix (apply recommended changes) |
Scan the workspace for every agent config file:
# Find all agent config files across workspace (including sub-repos)
glob "**/CLAUDE.md"
glob "**/AGENTS.override.md"
glob "**/AGENTS.md"
glob "**/.cursorrules"
glob "**/.cursor/rules"
glob "**/.claude/settings.json"
glob "**/.claude/settings.local.json"
glob "**/.claude/hooks.json"
glob "**/.agents/memory/*.md"
Build an inventory table:
| Layer | Files Found | Total Lines |
|-----------------|-------------|-------------|
| CLAUDE.md | N | N |
| AGENTS.override.md | N | N |
| AGENTS.md | N | N |
| Configured fallbacks | N | N |
| .cursorrules | N | N |
| .claude/ config | N | N |
| .agents/memory/ | N | N |
These rules commonly appear in multiple places. Search for each across ALL config files:
Rules to check:
any types / No any — should be in AGENTS.md + hooks onlyconsole.log / logger — should be in AGENTS.md only.agents/memory/ topic only.agents/memory/coding-standards.md onlyisDeleted) — should be in .agents/memory/data-guardrails.md onlyorganization: orgId) — should be in .agents/memory/security.md onlyFor each rule, count occurrences:
grep "No \`any\`\|NO \`any\`\|no any types" across all config files
Healthy target: Each rule appears in max 2 files (one "teach" doc + one runtime enforcement like hooks).
Flag: Any rule appearing 3+ times across config files.
Check for stale dates and paths:
# Find files with old "Last Updated" dates (> 90 days old)
grep -r "Last Updated:" across .cursorrules, .cursor/rules
# Find hardcoded workspace paths that should be relative
grep -r "/Users/" across .agents/ config files
# Find references to directories that no longer exist
# Compare referenced paths against actual directory listing
Flag: Any file with "Last Updated" > 90 days behind current date. Flag: Any hardcoded absolute path in config files. Flag: Any reference to a directory that doesn't exist.
For each workspace, check the instruction chain Codex actually resolves:
AGENTS.override.md, AGENTS.md, then configured fallback filenamesAGENTS.override.md is used only where a subtree intentionally replaces the same-directory AGENTS.mdAGENTS.md contains repo-specific rules and entry points.codex/config.toml.codex/config.toml or hooks, not in assumed prose.codex/instructions.md file or .codex/commands directory is presented
as a supported Codex entry surfaceRead the effective Codex configuration and record
project_doc_fallback_filenames plus any runtime policy before judging the
instruction chain.
Flag: Undocumented fallback files, accidental overrides, instruction files that
contradict runtime configuration, or unsupported .codex/instructions.md and .codex/commands
surfaces.
For each AGENTS.md:
.agents/ paths that actually existFlag: Any AGENTS.md that's a pure generic stub (< 20 lines with no repo-specific content).
For .cursorrules and .cursor/rules:
For .claude/settings.json and .claude/settings.local.json:
Output format:
# Agent Config Audit Report
**Date:** YYYY-MM-DD
**Workspace:** [path]
**Files Scanned:** N
## Summary
- Critical issues: N
- Moderate issues: N
- Minor issues: N
- Total config lines: N (target: reduce by dedup)
## Critical: Rule Duplication
| Rule | Occurrences | Files | Target |
|------|-------------|-------|--------|
| "No any types" | 6 | [list] | 2 |
## Critical: Stale Files
| File | Last Updated | Days Stale |
|------|-------------|------------|
## Moderate: Instruction Resolution Drift
| Workspace | Override | AGENTS.md | Configured Fallbacks | Runtime Policy Location |
|-----------|----------|-----------|----------------------|-------------------------|
## Moderate: Stub AGENTS.md
| File | Lines | Has Repo Context |
|------|-------|------------------|
## Minor: Emoji in Config
| File | Emoji Count |
|------|-------------|
## Recommendations
1. [Specific actionable fix]
2. [Specific actionable fix]
Never infer fix mode from the audit findings or from a request to "sync" configs. Enter fix mode only when the user explicitly requests mutation, show the exact files and operations, and obtain confirmation before using write/edit or mutating shell behavior. Then apply changes following these principles:
.codex/config.toml or hooksreferences/canonical-ownership.md — Which rule belongs in which filereferences/healthy-config-example.md — Example of a well-structured config set| DON'T | DO | Why |
|---|---|---|
Repeat the same rule in AGENTS.md, CLAUDE.md, .agents/memory/, and hooks | Put the rule in ONE canonical file; others reference it | Duplication wastes context tokens and creates drift when one copy gets updated but others don't |
| Leave "Last Updated: 2025-10-07" in a file touched in 2026 | Update dates when modifying any config file | Stale dates signal neglect and erode trust in the config system |
| Create an extra instruction filename without configuring it | Put shared project guidance in AGENTS.md; use AGENTS.override.md for scoped overrides and configure any genuine fallback in the effective .codex/config.toml | Codex resolves native instruction names plus explicitly configured fallbacks |
| Use emoji in config headers | Use plain text headers | Emoji waste tokens on every context load and violate "no emoji unless requested" |
Hardcode /Users/username/path/ in config files | Use relative paths or describe location generically | Hardcoded paths break when workspace moves or another developer joins |
Recreate a parallel legacy instruction tree under .agents/ | Put durable guardrails in topic files under .agents/memory/; put shared actionable rules in AGENTS.md | The current memory layout keeps durable context discoverable without parallel hierarchies |
After running the audit:
.cursorrules files have "Last Updated" within 90 daysAGENTS.override.md or AGENTS.md) or an explicitly configured fallback.codex/config.toml or hooks.cursorrules or .cursor/rules headersrules-capture — capture one new preference instead of auditing a config setagent-folder-init — scaffold a missing .agents/ structurelinter-formatter-init — set up or repair formatter/linter configurationaudit — audit application quality instead of agent configurationsession-documenter — preserve session learnings before proposing instruction updatesGuides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.
Dispatches multiple subagents concurrently for independent tasks without shared state. Use when facing 2+ unrelated failures or subsystems that can be investigated in parallel.
npx claudepluginhub shipshitdev/skills --plugin agent-config-audit