Free tools

Agent config check.

Check the files that program coding agents in a public GitHub repository: CLAUDE.md, AGENTS.md, Cursor rules, MCP servers, hooks and settings. The check runs in your browser.

Your browser fetches the files from GitHub and checks them in this page. Nothing about the repository or the result is sent to LaunchSafe.

What it checks

Checks

  • Hooks, folder-open tasks and helpers that download and run code, or send credentials off the machine, when an agent or editor starts.

  • MCP servers installed at an unpinned version or from git, reached over plain HTTP, or given the whole disk.

  • Settings that turn permission prompts off or allow any shell command, and instructions to skip the repository's own checks.

  • Hidden text in instruction files: invisible characters, commands in HTML comments, encoded blocks, and text telling the agent to ignore its rules or hide what it does.

  • Keys and tokens written into agent files, shown masked, and model traffic sent to a host other than the provider.

  • Everything the files make run or connect on their own, listed for review even when nothing is wrong with it.

Doesn’t check

  • Private repositories, branches other than the default one, and the Git history.

  • What an MCP server, skill or script does once installed. Nothing the files name is run, installed or contacted.

  • The rest of the code. The repository grade covers that.

Questions

Is the repository sent to LaunchSafe?

No. Your browser fetches the files straight from GitHub and the check runs in this page's JavaScript. LaunchSafe never sees the repository or the result.

Nothing was found. Is the repository safe?

It means none of the known-bad patterns matched the files checked. The check reads files and never runs them, so it can't prove that a server, a skill or an instruction is harmless. Review what the result lists under what runs on its own.

Why does it say GitHub's limit was reached?

Without signing in, GitHub allows 60 requests an hour from one network, and each check uses two. The message says when the limit resets.

Which files does it read?

CLAUDE.md, AGENTS.md and GEMINI.md anywhere in the tree; Cursor, Windsurf, Cline and Copilot rules; Claude Code settings, hooks, skills, sub-agents and commands; MCP server lists; Gemini and Codex settings; VS Code tasks and settings; the root package.json scripts. Root .env files are read only to tell whether production credentials sit beside the agent.

Check a whole repository,
free.