Nifty Agent Config
See which AGENTS.md, CLAUDE.md, Cursor, Copilot, Windsurf and Gemini rules apply to the file you are editing. Lint rule and MCP files for hidden text, secrets and broken links, and keep them in sync.
Maintained. No sign-in. No telemetry. Works in VS Code, Cursor, Windsurf, VSCodium and other editors that use Open VSX.
Why
A repository used with more than one coding agent ends up with a pile of instruction files: AGENTS.md (nested per package), CLAUDE.md, .cursor/rules/*.mdc, .github/copilot-instructions.md, .github/instructions/*.instructions.md, .windsurf/rules, GEMINI.md, .clinerules, plus an MCP server config for each tool. Each format has its own frontmatter, its own glob rules and its own idea of which file wins. Nothing tells you which of them an agent actually loads for the file in front of you, whether a glob matches anything, or whether someone slipped invisible instructions into a rule file.
This extension reads those files. It isn't an AI assistant and never calls one: everything runs locally, with no network requests.
Features

- Which rules apply here? The Rules for Current File view lists, for each agent, every instruction and rule file it loads for the active file, most specific first, with the reason:
globs: packages/web/**/*.tsx matches, in packages/api/, trigger: always_on, the agent decides from its description. Expand a file to see its @imports and headings. The status bar shows how many files apply; hover it for the list.
- CodeLens on rule files: Applies to 12 files (click for the list), Loaded for every file in packages/api/, and which agents read the file.

- Hidden text. Invisible Unicode (tag characters, zero-width characters, bidi controls, variation selectors) in agent files is reported as an error, and tag characters are decoded so you can read what they say. This is the "Rules File Backdoor" attack: text an agent follows but a reviewer never sees. Quick fixes remove one run or every hidden character in the file. Emoji joiners and a leading byte order mark are left alone.

- Frontmatter checks per format: unknown or misspelled keys (with a rename fix), wrong value types (
alwaysApply: "true"), invalid values (trigger: always in Windsurf, inclusion in Kiro, excludeAgent in Copilot), an applyTo written as a list, Windsurf rules without a trigger, Kiro fileMatch without a pattern, and skill names.
- Globs: patterns that can't work (backslashes, absolute paths, unbalanced braces,
src**) and patterns that match no file in the workspace.
- Links and imports: relative Markdown links,
@path imports (CLAUDE.md, AGENTS.md, GEMINI.md) and Kiro #[[file:…]] references that point at files that don't exist.
- Size: a token estimate for files that are always loaded, and each format's own limits: Windsurf reads 12,000 characters per rule, Codex stops at 32 KiB of AGENTS.md, Claude Code recommends keeping CLAUDE.md under 200 lines.
- Secrets: API keys and tokens pasted into agent files (GitHub, GitLab, OpenAI, Anthropic, AWS, Google, Slack, Stripe, npm, Hugging Face, private keys, passwords in URLs). Messages show only the start of the key.

- Duplicated and conflicting instructions across formats: the same paragraph pasted into several files, "never X" in one and "always X" in another, and different choices for the same thing (
use pnpm vs use npm, tabs vs spaces, jest vs vitest) in files for the same folder. A nested AGENTS.md overriding its parent is how nesting is meant to work, so that isn't flagged.

- MCP configs:
.vscode/mcp.json, .cursor/mcp.json, .mcp.json, .gemini/settings.json, .kiro/settings/mcp.json and .roo/mcp.json. It reports the wrong root key (mcpServers in VS Code's file, servers elsewhere) with a fix, unknown or misspelled fields, a server with neither a command nor a url, type values the tool doesn't know, plain http:// to a remote host, secrets written inline in env, headers or arguments (with a fix that references an environment variable in that tool's syntax), another tool's variable syntax (${env:X} in Claude Code's file, ${X} in VS Code's), undefined ${input:…} ids, and commands that aren't on the PATH (desktop only). The MCP Servers view lists each server across all configs and marks the ones that are started differently.


- One source of truth (optional). Sync Agent Files from AGENTS.md generates the other formats from
AGENTS.md (or another file you choose): CLAUDE.md and GEMINI.md get an @import of it, the others get a copy with relative links rewritten, and new Cursor, Windsurf and Kiro files get the frontmatter that makes them load every time. The generated text goes in a block between nifty-agent-config markers, so the rest of each file stays yours. Every change is shown as a diff before anything is written. Afterwards, a warning with a quick fix appears when the source changes or someone edits inside a block, and Check Generated Agent Files Are in Sync lists them all.
- Works in the browser on vscode.dev and github.dev (all but the PATH check).
Supported files
| Agent |
Files |
How they apply |
| Codex |
AGENTS.md, AGENTS.override.md |
One per folder from the root down; closer files take precedence |
| Claude Code |
CLAUDE.md, .claude/CLAUDE.md, CLAUDE.local.md, .claude/rules/**/*.md, skills and commands |
Folders on the path; rules by paths; AGENTS.md when there's no CLAUDE.md |
| GitHub Copilot |
.github/copilot-instructions.md, .github/instructions/*.instructions.md, AGENTS.md |
Always; by applyTo; nested AGENTS.md and CLAUDE.md follow VS Code's chat.useNestedAgentsMdFiles and chat.useClaudeMdFile |
| Cursor |
.cursor/rules/**/*.mdc (nested folders too), AGENTS.md, .cursorrules |
alwaysApply, globs, description, manual |
| Windsurf |
.windsurf/rules/*.md, .devin/rules/*.md, .windsurfrules, AGENTS.md |
trigger: always_on, glob, model_decision, manual |
| Gemini CLI |
GEMINI.md |
This folder and every parent |
| Cline |
.clinerules (file or folder), .cline/rules, .cursorrules, .windsurfrules, AGENTS.md |
Rules by paths |
| Kiro |
.kiro/steering/*.md, AGENTS.md |
inclusion: always, fileMatch, auto, manual |
| Aider |
CONVENTIONS.md and anything under read: in .aider.conf.yml |
When listed |
User-level and organisation files (~/.claude/CLAUDE.md, Cursor user rules, Copilot personal instructions) live outside the workspace, so they aren't shown.
How it differs from other Nifty extensions
- Nifty AI Review reviews the code changes an agent makes. This extension works on the instruction and config files that steer the agent.
- Nifty Generated keeps agents out of generated files (and writes
.cursorignore and similar). This extension doesn't touch ignore files; it checks the files agents read as instructions.
- Nifty Dependency Guard checks packages before you install them. This extension checks MCP server configs: how each server is started, and whether secrets or plain http slipped in.
Commands
| Command |
What it does |
Nifty Agent Config: Show Rules for Current File |
Open the view for the active file (also the status bar item) |
Nifty Agent Config: Check Agent Files |
Re-scan every agent file and MCP config and show the problems |
Nifty Agent Config: Sync Agent Files from AGENTS.md… |
Generate the other formats from the source, with a diff preview |
Nifty Agent Config: Check Generated Agent Files Are in Sync |
List generated files that are out of date or edited by hand |
Nifty Agent Config: Update Generated Block from Its Source |
Regenerate the current file's block |
Nifty Agent Config: Remove Hidden Characters from This File |
Strip every invisible character the checks report |
Nifty Agent Config: Refresh |
Re-scan the workspace |
Settings
| Setting |
Default |
What it does |
nifty.agent-config.agents |
all |
Agents shown in the view and the status bar |
nifty.agent-config.showAgentDecided |
true |
Also list rules an agent may pull in by itself from their description |
nifty.agent-config.maxTokens |
4000 |
Warn above this estimate for files that are always loaded (0 = off) |
nifty.agent-config.check.hiddenCharacters |
true |
Report invisible Unicode |
nifty.agent-config.check.secrets |
true |
Report pasted API keys and tokens |
nifty.agent-config.check.links |
true |
Report broken links and @imports |
nifty.agent-config.check.frontmatter |
true |
Check frontmatter and globs |
nifty.agent-config.check.duplicates |
true |
Report paragraphs repeated across files |
nifty.agent-config.check.conflicts |
true |
Report instructions that may contradict each other |
nifty.agent-config.check.mcpCommands |
true |
Report MCP commands that aren't on the PATH |
nifty.agent-config.statusBar |
true |
Show the count in the status bar |
nifty.agent-config.codeLens |
ruleFiles |
ruleFiles, all (also a count on every file) or off |
nifty.agent-config.sync.source |
AGENTS.md |
The file the others are generated from |
nifty.agent-config.sync.targets |
[] |
Files to keep generated; empty asks each time |
Sources
The loading rules follow each tool's documentation as of September 2026:
AGENTS.md,
Codex AGENTS.md discovery,
Claude Code memory and rules,
Claude Code skills,
Claude Code MCP,
Cursor rules,
Cursor MCP,
VS Code custom instructions,
VS Code MCP servers,
GitHub Copilot repository instructions,
Windsurf rules,
Gemini CLI GEMINI.md,
Gemini CLI MCP,
Cline rules,
Kiro steering.
These tools change often; if one has moved on, please open an issue.
Install
- VS Code: search for "Nifty Agent Config" in the Extensions view, or install from the Visual Studio Marketplace.
- Cursor, Windsurf, VSCodium, Kiro, Antigravity: install from Open VSX.
Privacy
This extension collects no telemetry, needs no account and makes no network requests.
- Nifty Code Metrics: Complexity & Hotspots: Complexity and size for every function in any language, as CodeLens and warnings, plus a hotspots view of the complex files that change most often. (Open VSX)
- Nifty i18n: Inline Translations & Missing Keys: See translations inline next to t('key') calls, find missing keys and translations, complete and jump to keys, and extract strings into your locale files. (Open VSX)
- Nifty JSON Schema: Validate with Draft 2020-12 & 2019-09: Validate JSON, JSONC and YAML against JSON Schema 2020-12, 2019-09, draft-07, 06 and 04, with precise errors, hover, completion, SchemaStore lookup and schema generation. (Open VSX)
- Nifty Licenses: Dependency License Checker & SBOM: See the license of every dependency (npm, Python, Cargo, Go, NuGet, Composer), get warned about GPL and unknown licenses, and export an SBOM or third-party notices. (Open VSX)
- Nifty OpenAPI: Outline, Checks and Try It for API Specs: Edit OpenAPI and Swagger files with an outline, $ref navigation and completion, error checking, example payloads, and Try it requests for your REST client. (Open VSX)
- Nifty Pretty Errors: Readable Error Messages: Readable error messages for every language: TypeScript types formatted as code, long C++ and Rust types folded, and a docs link for every error code, in the hover and a side panel. (Open VSX)
See all 100+ Nifty extensions and web tools at https://getnifty.dev
| |