Borrowing it
Nothing to install: this file belongs to tonyc726/china-administrative-division. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/tonyc726/china-administrative-division/master/.claude/settings.jsongit clone --depth 1 https://github.com/tonyc726/china-administrative-divisionWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/settings/tonyc726/china-administrative-division/settings)<a href="https://agentmods.dev/settings/tonyc726/china-administrative-division/settings"><img src="https://agentmods.dev/badge/settings/tonyc726/china-administrative-division/settings.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
china-administrative-division scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"env": { "NODE_ENV": "development" },
"permissions": {
"allow": [],
"deny": [
"Read(.env.production)",
"Read(.env.*.local)",
"Write(.env.*)",
"Bash(git push:*)",
"Bash(git reset --hard:*)",
"Bash(git rebase:*)"
]
},
"hooks": {
"SessionStart": [
{
"hooks": [
{
"type": "command",
"command": "test -d node_modules || echo 'WARNING: 依赖未安装,请先运行 pnpm install'"
}
]
}
],
"PreToolUse": [
{
"matcher": "Write|Edit|MultiEdit",
"hooks": [
{
"type": "command",
"command": "[ \"$(git branch --show-current)\" != \"main\" ] && [ \"$(git branch --show-current)\" != \"master\" ] || { echo '{\"block\": true, \"message\": \"禁止直接修改主分支,请先 git checkout -b feat/xxx\"}' >&2; exit 2; }",
"timeout": 5
}
]
}
],
"PostToolUse": [
{
"matcher": "Write|Edit|MultiEdit",
"hooks": [
{
"type": "command",
"command": "jq -r '.tool_input.file_path // empty' | xargs -I{} sh -c 'test -x node_modules/.bin/prettier && case \"{}\" in *.ts|*.tsx|*.vue|*.js|*.jsx) node_modules/.bin/prettier --write \"{}\" 2>/dev/null ;; esac || true'",
"timeout": 15
}
]
}
]
}
}
What else settings.json configures
This page is one entry in a file that holds 4. Installing the file brings all of them; each is measured and scanned on its own page.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 51 lines scan A 025fa29ff103
china-administrative-division is a settings file published in the GitHub repository tonyc726/china-administrative-division (231 stars, last pushed 12d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.
Other settings, from other repositories
supabase
Agent settings declaring 2 hook events (SessionStart, PostToolUse).
superset
Agent settings declaring 1 hook event (PreToolUse).
RuView
Agent settings declaring 8 hook events (PreToolUse, PostToolUse, UserPromptSubmit, SessionStart) and 4 allowed tools.
claude-cookbooks
Agent settings declaring 2 hook events (SessionStart, PreToolUse).
orm
Agent settings declaring 4 hook events (PreToolUse, PostToolUse, WorktreeCreate, Stop) and 21 allowed tools.
claude-code-best-practice
Agent settings declaring 30 hook events (PreToolUse, PermissionRequest, PostToolUse, PostToolUseFailure) and 24 allowed tools.