Audits an agent's shipped configuration — a `.claude/settings.json` / `settings.local.json`, hooks, and permission rules (and equivalents like `.cursor/`) — for hooks that auto-run code, permission rules that remove the human-in-the-loop, or secrets in config, and assigns a 0–8 danger score with evidence. Use when a repo ships agent settings and you want to know what opening it will do. Triggers include "is this settings.json safe", "audit these agent hooks", "does this config auto-run anything", "check this .claude/settings for dangerous permissions", "review this repo's agent config".