Use when Configuration validation and workspace self-auditing mastery. Verifying .agent directory integrity, checking JSON schemas, resolving broken pointers to missing scripts/skills, validating environment states, and enforcing configuration constraints before execution. Use when loading settings, modifying manifests, or diagnosing system configuration rot.
Installs into .claude/skills of the current project.
Are you the author of Config Validator?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/harmitx7-config-validator-tribunal-kit)
---
name: config-validator
description: "Use when Configuration validation and workspace self-auditing mastery. Verifying .agent directory integrity, checking JSON schemas, resolving broken pointers to missing scripts/skills, validating environment states, and enforcing configuration constraints before execution. Use when loading settings, modifying manifests, or diagnosing system configuration rot."
version: 5.0.0
last-updated: 2026-09-13
skills:
- lint-and-validate
- backend-security-expert
- clean-code
tools: Read, Grep, Glob, Bash, Edit, Write
scripts-binding:
- .agent/scripts/lint_runner.js
- .agent/scripts/verify_all.js
---
# Config Validator β System Integrity Mastery
---
## π οΈ Technical Architecture & Reference Recipes
---
## Hallucination Traps (Read First)
- β Silently using default values for missing config -> β Fail fast with a clear error message naming the missing field
- β Trusting environment variables without validation -> β Validate ALL env vars at startup with Zod or a schema, not at usage time
- β Mixing config source precedence without documenting it -> β Document: CLI args > env vars > config file > defaults
---
---
## 1. Fail Fast, Fail Loudly
Never allow a system to boot, run, or proceed into a workflow if the underlying configuration is invalid. Parse configurations at the absolute boundary.
```typescript
import { z } from 'zod';
// β VULNERABLE: Implicit Trust
// Assumes the JSON file is correct. Will crash randomly deep in the execution stack
// if 'maxRetries' is missing or set to a string.
const config = JSON.parse(fs.readFileSync('./.agent/config.json', 'utf8'));
runAgent(config.maxRetries);
// β SAFE: Boundary Validation via Zod
const ConfigSchema = z.object({
version: z.string().regex(/^\d+\.\d+\.\d+$/),
maxRetries: z.number().min(0).max(10).default(3),
enabledSkills: z.array(z.string()),
environment: z.enum(['development', 'production', 'test']),
apiEndpoint: z.string().url().optional(),
});
try {
const rawData = JSON.parse(fs.readFileSync('./.agent/config.json', 'utf8'));
const config = ConfigSchema.parse(rawData); // Throws heavily detailed error instantly
} catch (err) {
logger.fatal('System boot aborted. Invalid config.json:', err.errors);
process.exit(1);
}
```
---
## 2. Directory & Manifest Self-Auditing
Configuration files often reference physical system assets (scripts, workflows, other config files). The validator must check referential integrity.
If `manifest.json` says `{"workflow": "scripts/deploy.sh"}`, the validator MUST verify that `scripts/deploy.sh` actually exists before the orchestrator tries to run it.
```typescript
// Validating Referential Integrity
function auditAgentDirectory(config: Config) {
const missingFiles = [];
for (const skill of config.enabledSkills) {
const skillPath = path.join('.agent/skills', skill, 'SKILL.md');
if (!fs.existsSync(skillPath)) {
missingFiles.push(`Skill manifest definition missing: ${skillPath}`);
}
}
if (missingFiles.length > 0) {
throw new Error(`Referential Integrity Failure:\n${missingFiles.join('\n')}`);
}
}
```
---
## 3. Environment Variable Validation
Missing or malformed `.env` files are the #1 cause of deployment failure.
Treat environment variables exactly like JSON configs: apply a rigid schema mapping at boot.
```typescript
// Instead of checking process.env.DATABASE_URL throughout the app,
// export a strictly validated object once.
// src/env.ts
import { z } from 'zod';
const EnvSchema = z.object({
DATABASE_URL: z.string().url(),
PORT: z.coerce.number().default(3000), // Transforms string "3000" to number 3000
NODE_ENV: z.enum(['development', 'production']).default('development'),
API_KEY: z.string().min(16), // Ensures keys aren't empty or mock data
});
export const ENV = EnvSchema.parse(process.env);
```
---
## 4. Safe Configuration Mutation
When automating updates to a JSON configuration (e.g., adding a new skill to `config.json`), never serialize over the original file blindly.
1. **Read** original JSON.
2. **Apply** modifications in memory.
3. **Validate** the new object against the Zod schema.
4. **Write** atomically (write to `config.json.tmp`, then standard OS file rename to `config.json` to prevent corruption if power dies mid-write).