claude-code-best-practice-cn: Command for Claude Code

.claude/commands/workflows/best-practice/workflow-claude-settings.md

workflow-claude-settings is a command for Claude Code from clxzl/claude-code-best-practice-cn. It costs 18 tokens per session (3,970 once invoked), scanned A, original, MIT.

A command workflow for checking whether Claude Code settings documentation is out of date. Claude Code is a coding assistant, and settings control how it behaves.

In plain words
What is it for?
Use it to research changes across settings documentation, command references, changelogs, and local project files, then produce a review report.
Why use it?
It compares recent software changes with a local settings report so missing, changed, or outdated information can be identified before updates are made.

Command for Claude Code

Written for Claude Code: argument-hint in frontmatter. Also seen: mentions CLAUDE.md; mentions Claude Code.

This is clxzl/claude-code-best-practice-cn's own configuration. It tells Claude Code how to work on claude-code-best-practice-cn itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything claude-code-best-practice-cn configures →

Reuse

Borrowing it

Nothing to install: this file belongs to clxzl/claude-code-best-practice-cn. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/clxzl/claude-code-best-practice-cn/main/.claude/commands/workflows/best-practice/workflow-claude-settings.md
Clone the repo
git clone --depth 1 https://github.com/clxzl/claude-code-best-practice-cn

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for workflow-claude-settings

README.md
[![agentmods](https://agentmods.dev/badge/commands/clxzl/claude-code-best-practice-cn/workflow-claude-settings/github.svg)](https://agentmods.dev/commands/clxzl/claude-code-best-practice-cn/workflow-claude-settings)
Your own site
<a href="https://agentmods.dev/commands/clxzl/claude-code-best-practice-cn/workflow-claude-settings"><img src="https://agentmods.dev/badge/commands/clxzl/claude-code-best-practice-cn/workflow-claude-settings/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for workflow-claude-settings

Your own site · 80×15
<a href="https://agentmods.dev/commands/clxzl/claude-code-best-practice-cn/workflow-claude-settings"><img src="https://agentmods.dev/badge/commands/clxzl/claude-code-best-practice-cn/workflow-claude-settings.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 18 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 3,970 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00018 $0.03970
Opus 5 $0.00009 $0.01985
Sonnet 5 $0.00004 $0.00794
Haiku 4.5 $0.00002 $0.00397

Measured 9d ago against content hash f7fa791e973f, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

workflow-claude-settings scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.claude/commands/workflows/best-practice/workflow-claude-settings.md · 242 lines

How it starts

The opening of the file, as written. The whole thing — 242 lines — stays where its author put it; the contents beside it link to each section on GitHub.

工作流变更日志 — Settings 报告

你是 claude-code-best-practice 项目的协调器。你的工作是并行启动两个研究 Agent、等待其结果、合并发现,并提交一份关于 Settings 参考报告(best-practice/claude-settings.md)中漂移的统一报告。

检查版本数: $ARGUMENTS(如果为空或非数字则默认为 10)

这是一个先读后报告的工作流。启动 Agent、合并结果并生成报告。只有在用户批准后才采取行动。


阶段 0:并行启动两个 Agent

立即使用 Task 工具在同一条消息中生成两个 Agent(并行启动):

Agent 1:workflow-claude-settings-agent

使用 subagent_type: "workflow-claude-settings-agent" 生成。给出以下提示:

研究 claude-code-best-practice 项目的 settings 报告漂移。检查最近 $ARGUMENTS 个版本(默认:10)。

获取这 3 个外部来源:

  1. Settings 文档:https://code.claude.com/docs/en/settings
  2. CLI 参考:https://code.claude.com/docs/en/cli-reference
  3. 变更日志:https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md

然后读取本地报告文件(best-practice/claude-settings.md)和 CLAUDE.md 文件。分析官方文档关于 settings 键、权限语法、hook 事件、MCP 配置、沙箱选项、插件设置、模型别名、显示设置和环境变量的内容与我们报告记录的内容之间的差异。返回一份涵盖缺失设置、变更类型/默认值、新增设置、弃用设置、权限语法变更、hook 事件变更、MCP 设置变更、沙箱设置变更、环境变量完整性、示例准确性、settings 层级准确性和来源有效性的结构化发现报告。

Agent 2:claude-code-guide

使用 subagent_type: "claude-code-guide" 生成。给出以下提示:

研究最新的 Claude Code settings 系统。我需要你找到:

  1. 当前支持的所有 settings.json 键的完整列表,包括类型、默认值和描述
  2. 最近 Claude Code 版本中引入的任何新 settings 键
  3. 现有 settings 行为的变更(例如新的权限模式、新的 hook 事件、新的沙箱选项)
  4. settings 层级的变更(新的优先级级别、新的文件位置)
  5. 权限语法的变更(新的工具模式、新的通配符行为)
  6. 新的 hook 事件或 hook 配置结构的变更
  7. MCP 服务器配置的变更(新的匹配字段、新的设置)
  8. 沙箱设置的变更(新的网络选项、新的命令)
  9. 插件配置的变更(新的字段、新的市场选项)
  10. 环境变量的变更(新变量、弃用变量、行为变更)
  11. 模型别名或模型配置的变更
  12. 显示/UX 设置的变更(状态行、旋转器、进度条)
  13. 任何 settings 键的弃用或移除

要彻底 — 搜索网页、获取文档,并为你找到的每件事提供具体的版本号和细节。

两个 Agent 独立运行并返回其发现。


阶段 0.5:读取验证清单

在 Agent 运行期间,读取 changelog/best-practice/claude-settings/verification-checklist.md。此文件包含累积的验证规则 — 每条规则指定要检查什么、检查深度以及对照哪个来源。每条规则在阶段 2 中必须执行。该清单是项目漂移检测的回归测试套件。


阶段 1:读取之前的变更日志条目

在合并发现之前,读取文件 changelog/best-practice/claude-settings/changelog.md 获取最近 25 个变更日志条目。每个条目用 --- 分隔。解析这些之前条目中的优先级操作,以便与当前发现进行比较。这让你能够识别:

  • 重复项 — 之前出现过且仍未解决的问题
  • 新解决的项 — 之前运行中的问题现已修复
  • 新项 — 在本次运行中首次出现的问题

Read the full file on GitHub · 242 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 9d ago First seen · 242 lines · 18 tokens per session scan A f7fa791e973f

Subscribe to this mod's changes

workflow-claude-settings is a command published in the GitHub repository clxzl/claude-code-best-practice-cn (127 stars, last pushed 4mo ago), licensed MIT. It adds 18 tokens to every session and 3,970 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.