Skip to content

AI Configs

Evidence: AI Configs
Description: Parse AI tool configuration files for provider, model, and permission metadata
Category: AI
Platform: macos
Short Name: aicfg
Is Parsed: Yes
Sent to Investigation Hub: Yes
Collect File(s): No

AI tools store provider, model, permission, and trust settings in files such as claude.json, settings.json, and cli-config.json. Those settings determine which models are used and whether the agent can act without approval.

This collector gathers structured data about AI tool configurations, including provider, model, permission mode, trust overrides, and secret-like value indicators.

This collector scans per-user and project-scope config files and parses JSON content to extract provider, model, and permission metadata and to flag risky configurations.

Reveals which AI providers and models are configured, whether auto-approve or manual permission modes are in use, and whether configs contain secret-like values. Risk flags highlight permission bypasses and broad tool allowlists.