Claude Operator: Prompt to Autonomy · 45 min · 15 XP

Capstone: safety review and drill

Audit everything you've configured, then rehearse recovering from a failure.

Audit your practice environment end to end: every skill, every settings scope that applies, every MCP server still connected from Level 3, and every hook. For each one — do you still need it, does it have the narrowest scope that works, and could you explain to someone else why it's there?

Then run a drill, because a control you've never seen fire is a control you're guessing about. Deliberately trigger a denied action or a failing hook and walk through what happens: what message you get, what state things are left in, and how you recover. Doing this once on purpose is how you find out whether your deny rule actually denies.

Do it now, in your own tools. Keep this evidence: the audit with a keep/narrow/remove decision per item, the corrected configuration, and a recovery note describing the drill and what you'd do differently. No secrets in any of it — if your notes need a token to make sense, that's a finding in itself.

Official references
Claude Code skills · https://code.claude.com/docs/en/skills
Configure permissions · https://code.claude.com/docs/en/permissions

Loading your workspace…