Claude Settings Audit
Analyze this repository and generate recommended Claude Code settings.json permissions for read-only commands.
Phase 1: Detect Tech Stack
Run these commands to detect the repository structure:
Check for these indicator files:
Phase 2: Detect Services
Check for service integrations:
Read dependency files to identify frameworks:
package.json→ checkdependenciesanddevDependenciespyproject.toml→ check[project.dependencies]or[tool.poetry.dependencies]Gemfile→ check gem namesCargo.toml→ check[dependencies]
Phase 3: Check Existing Settings
Phase 4: Generate Recommendations
Build the allow list by combining:
Baseline Commands (Always Include)
Stack-Specific Commands
Only include commands for tools actually detected in the project.
Python (if any Python files or config detected)
Node.js (if package.json detected)
Other Languages
Build Tools
Skills (for Sentry Projects)
If this is a Sentry project (or sentry-skills plugin is installed), include:
WebFetch Domains
Always Include (Sentry Projects)
Framework-Specific
MCP Server Suggestions
MCP servers are configured in .mcp.json (not settings.json). Check for existing config:
Sentry MCP (if Sentry SDK detected)
Add to .mcp.json (replace {org-slug} and {project-slug} with your Sentry organization and project slugs):
Linear MCP (if Linear usage detected)
Add to .mcp.json:
Note: Never suggest GitHub MCP. Always use gh CLI commands for GitHub.
Output Format
Present your findings as:
- Summary Table - What was detected
- Recommended settings.json - Complete JSON ready to copy
- MCP Suggestions - If applicable
- Merge Instructions - If existing settings found
Example output structure:
Important Rules
What to Include
- Only READ-ONLY commands that cannot modify state
- Only tools that are actually used by the project (detected via lock files)
- Standard system commands (ls, cat, find, etc.)
- The
:*suffix allows any arguments to the base command
What to NEVER Include
- Absolute paths - Never include user-specific paths like
/home/user/scripts/fooor/Users/name/bin/bar - Custom scripts - Never include project scripts that may have side effects (e.g.,
./scripts/deploy.sh) - Alternative package managers - If the project uses pnpm, do NOT include npm/yarn commands
- Commands that modify state - No install, build, run, write, or delete commands
Package Manager Rules
Only include the package manager actually used by the project:
If multiple lock files exist, include only the commands for each detected manager.


