No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by trailofbits · Claude Skill · ★ 2.1k
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is claude-code-config safe to install? View the security audit →
Trail of Bits Claude Code Config Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits. Covers sandboxing, permissions, hooks, skills, MCP servers, and usage patterns we've found effective across security audits, development, and research. Also see: skills · skills-curated · claude-code-devcontainer · dropkit First-time setup: Then inside the session, run . It walks you through installing each component, detects what you already have, and self-installs the command so future runs work from any directory. Run again after updates. Contents Getting Started Read These First Prerequisites Shell Setup Settings Global CLAUDE.md Configuration Sandboxing Hooks Plugins and Skills MCP Servers Local Models Personalization Usage Continuous Improvement Project-level CLAUDE.md [Context
| Stars | 2,080 |
| Forks | 158 |
| Language | Shell |
| Category | Claude Skill |
| Quality Score | 72.6724787146432/100 |
| Open Issues | 18 |
| Last Updated | 2026-08-24 |
| Created | 2026-02-04 |
| Platforms | claude-code, cli |
| Est. Tokens | ~14k |
These tools work well together with claude-code-config for enhanced workflows:
Looking for a claude-code-config alternative? If you're comparing claude-code-config with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Use your OpenCode Go subscription with Claude Code.
Autonomous AI development loop for Claude Code with intelligent exit detection
Claude Code Guide - Setup, Commands, workflows, agents, skills & tips-n-tricks from beginner to power user!
AI Skills, MCP Tools, and CLI for Unity Engine. Full AI develop and test loop. Use cli for quick setup. Effici
Context management for Claude Code. Hooks maintain state via ledgers and handoffs. MCP execution without conte
Open-source MCP server for LinkedIn. Give Claude and any MCP-compatible AI agent access to profiles, companies
Explore other popular claude skill tools:
claude-code-config is Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits. It is categorized as a Claude Skill with 2.1k GitHub stars.
claude-code-config is primarily written in Shell. It covers topics such as claude, claude-code, claude-code-cli.
You can find installation instructions and usage details in the claude-code-config GitHub repository at github.com/trailofbits/claude-code-config. The project has 2.1k stars and 158 forks, indicating an active community.
The top alternatives to claude-code-config on Agent Skills Hub include oc-go-cc, ralph-claude-code, claude-code-guide. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: