settings-setup

A setup workflow for managing Claude Code settings in JSONC, a JSON format that allows comments. It keeps an editable commented file and generates the standard settings file from it.

In plain words
What is it for?
Use it to inspect a repository, set up the JSONC workflow, and configure hooks or dotfile layouts when needed.
Why use it?
It prevents direct edits to the generated settings file from drifting away from the commented source.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/bengous/claude-code-plugins/settings-setup
Clone the repo
git clone --depth 1 https://github.com/bengous/claude-code-plugins
Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,357 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00009 $0.01357
Opus 5 $0.00005 $0.00678
Sonnet 5 $0.00002 $0.00271
Haiku 4.5 $0.00001 $0.00136

Measured yesterday against content hash 2303d7da98bb, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

settings-setup scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

- Does `~/.claude/settings.json` exist (global)?
claude-settings-manager/commands/settings-setup.md · 195 lines

How it starts

The opening of the file, as written. The whole thing — 195 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Settings Setup Wizard

You are setting up a JSONC workflow for Claude Code settings in this repository.

The JSONC Workflow

Claude Code's settings.json doesn't support comments. This workflow:

  1. Maintains __settings.jsonc as the editable source (supports // and /* */ comments)
  2. Auto-generates settings.json via hooks
  3. Blocks direct edits to prevent drift

Your Task

Step 1: Analyze the Repository

Explore the repo to understand its structure. Check:

  1. Repo type detection:

    • Is there a .chezmoi.yaml.tmpl, .chezmoi.toml.tmpl, or .chezmoiroot? (chezmoi dotfiles)
    • Are there dot_* prefixed directories? (chezmoi dotfiles)
    • Is there a stow or package-based structure? (stow dotfiles)
    • Otherwise: regular project repo
  2. Existing settings:

    • Does .claude/settings.json exist?
    • Does ~/.claude/settings.json exist (global)?
    • Is there already a __settings.jsonc file?
  3. Hook system:

    • Is there a lefthook.yml or lefthook.yaml?
    • Is there a .husky/ directory?
    • For chezmoi: hooks aren't needed (uses run_onchange_)
  4. Project structure:

    • What's the scripts directory pattern? (scripts/, bin/, etc.)
    • Is there a package.json?

Use ls, Glob, and Read to explore. Example commands:

ls -la
ls -la .claude/ 2>/dev/null || echo "No .claude directory"

Step 2: Determine Configuration

Based on your analysis, determine the appropriate flags:

For regular projects:

  • --source .claude/__settings.jsonc
  • --target .claude/settings.json
  • --hook-system lefthook (or husky if .husky/ exists)
  • --scripts-path scripts/claude

For chezmoi dotfiles:

  • --source dot_claude/__settings.jsonc
  • --target dot_claude/settings.json
  • --hook-system chezmoi
  • --install-global (optional, installs settings-manager to PATH)

For stow dotfiles:

  • --source <package>/__settings.jsonc (e.g., claude/__settings.jsonc)
  • --target <package>/settings.json
  • --hook-system lefthook
  • --scripts-path <package>/scripts

Read the full file on GitHub · 195 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 195 lines · 9 tokens per session scan B 2303d7da98bb

Subscribe to this mod's changes

settings-setup is a command published in the GitHub repository bengous/claude-code-plugins (4 stars, last pushed 2d ago), licensed MIT. It adds 9 tokens to every session and 1,357 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it B with 1 finding (reads agent configuration directories). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.