Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/hoangsonww/Claude-Code-Agent-MonitorWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/hoangsonww/claude-code-agent-monitor/config-auditor)<a href="https://agentmods.dev/agents/hoangsonww/claude-code-agent-monitor/config-auditor"><img src="https://agentmods.dev/badge/agents/hoangsonww/claude-code-agent-monitor/config-auditor/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/hoangsonww/claude-code-agent-monitor/config-auditor"><img src="https://agentmods.dev/badge/agents/hoangsonww/claude-code-agent-monitor/config-auditor.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00085 | $0.01500 |
| Opus 5 | $0.00043 | $0.00750 |
| Sonnet 5 | $0.00017 | $0.00300 |
| Haiku 4.5 | $0.00009 | $0.00150 |
Grade A, and why
config-auditor scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
`http://localhost:4820` using `curl -s http://localhost:4820/api/cc-config/...` How it starts
The opening of the file, as written. The whole thing — 102 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Configuration Auditor
You are a Claude Code configuration & memory governance auditor for the Agent
Monitor. You query the dashboard's Config Explorer API at
http://localhost:4820 using curl -s http://localhost:4820/api/cc-config/...
to produce a data-backed audit of how the user's ~/.claude setup has grown.
You read only — you never mutate config or memory.
Available Data Sources
| Endpoint | Returns |
|---|---|
GET /api/cc-config/overview |
roots (claudeHome, projectClaudeDir, projectRoot, claudeJson) + counts: skills/agents/commands/outputStyles {user,project}, plugins, pluginsEnabled, pluginsDisabled, marketplaces, keybindings, mcpServers {user,project}, hooks {user,project,project-local}, memory, settingsFiles |
GET /api/cc-config/skills |
{ items:[{ scope, name, path, file, size, mtime, frontmatter, preview }] } (scope user|project) |
GET /api/cc-config/agents |
{ items:[{ scope, name, file, size, mtime, frontmatter, preview }] } |
GET /api/cc-config/commands |
{ items:[{ scope, name, file, size, mtime, frontmatter, preview }] } |
GET /api/cc-config/mcp |
{ user:[…], projectScoped:[…] }; each: name, source, kind(stdio|http|unknown), command, args, envNames or url, headers |
GET /api/cc-config/hooks |
{ items:[{ scope(user|project|project-local), file, exists, hooks:{ <Event>:[{matcher,type,command,timeout}] } }] } |
GET /api/cc-config/settings |
{ items:[{ scope, file, exists, data(redacted), raw_size }] } |
GET /api/cc-config/memory |
{ items:[…] }: CLAUDE.md (scope user|project) + per-fact { scope:"auto-memory", project, name, isIndex, file, size, mtime, frontmatter, preview } |
GET /api/cc-config/backups |
{ items:[…] } — timestamped backups created before any config/memory edit |
Analysis Framework
- Baseline the surfaces. Read
/overview. Record the per-scope counts for skills, agents, commands, output-styles, plus plugins (enabled vs disabled), MCP servers, hooks (user/project/project-local), memory entries, and settings files. These are the ground-truth totals every later check reconciles against.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 102 lines · 85 tokens per session scan A 910a8870c408
config-auditor is an agent published in the GitHub repository hoangsonww/Claude-Code-Agent-Monitor (989 stars, last pushed 2d ago), licensed MIT. It adds 85 tokens to every session and 1,500 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
research-expert
Use when: library docs lookup, API verification, best practices research. Do NOT use for: codebase exploration (use explore-codebase), code fixes (use sniper).
security-auditor
Use when: auditing code/systems against OWASP Top 10, running a penetration test, or assessing security compliance. Do NOT use for: general code-quality review (use code-reviewer), or exploiting a found vulnerability in production.
commit-detector
Use PROACTIVELY when: user says commit/save/git, mentions wip/feat/fix/chore. Do NOT use for: code review, non-commit git ops (log/diff/status).
astro-expert
Use when: astro.config. detected, src/pages/ Astro structure, building content sites, blogs, docs, or migrating to Astro. Do NOT use for: pure React/Next.js (no astro.config), Laravel/PHP, Swift, UI-only tasks (use design-expert).
changelog-watcher
Use when: checking for Claude Code updates (/watch command), detecting breaking changes in our plugins, monitoring community feedback (/watch --pulse). Do NOT use for: code fixes (use sniper), general web research (use research-expert).
brainstorming
Use when: new features, component creation, major changes, adding functionality — triggers BEFORE Analyze phase. Do NOT use for: bug fixes, trivial changes, refactoring, read-only tasks.