PluginBench
Skill
Review
Audit score 70

security-scan

affaan-m/ecc

Audit Claude Code configuration for security vulnerabilities, misconfigurations, and injection risks.

What is security-scan?

Scans your .claude/ directory using AgentShield to detect hardcoded secrets, overly permissive permissions, command injection, and prompt injection patterns. Use this when setting up a new project, after modifying configuration files, or before committing changes.

  • Checks CLAUDE.md for hardcoded secrets, auto-run instructions, and prompt injection patterns
  • Audits settings.json for overly permissive allow lists, missing deny lists, and dangerous bypass flags
  • Scans mcp.json for risky MCP servers, hardcoded environment secrets, and supply chain risks
  • Analyzes hooks/ for command injection via interpolation, data exfiltration, and error suppression
  • Reviews agents/*.md for unrestricted tool access and missing model specifications
  • Provides severity grades (A–F) and auto-fix for safe issues

How to install security-scan

npx skills add null --skill security-scan
Prerequisites
  • AgentShield installed globally (npm install -g ecc-agentshield) or available via npx
  • ANTHROPIC_API_KEY environment variable (only required for Opus 4.6 deep analysis)
Claude Code
Cursor
Windsurf
Cline

How to use security-scan

  1. 1.Run npx ecc-agentshield scan to audit your .claude/ directory
  2. 2.Review the colored terminal report and severity grades (A–F)
  3. 3.For deeper analysis, set ANTHROPIC_API_KEY and run npx ecc-agentshield scan --opus --stream
  4. 4.Apply safe fixes automatically with npx ecc-agentshield scan --fix
  5. 5.Export results as JSON, Markdown, or HTML for documentation or CI/CD integration using --format flag

Use cases

Good for
  • Setting up a new Claude Code project to establish secure defaults
  • Auditing configuration after modifying .claude/settings.json, CLAUDE.md, or MCP servers
  • Pre-commit security checks before pushing configuration changes
  • Onboarding to a repository with existing Claude Code configurations
  • Running periodic security hygiene checks in CI/CD pipelines
Who it's for
  • Claude Code users managing agent configurations
  • DevOps and security engineers reviewing agent setups
  • Teams enforcing security standards across Claude Code projects
  • Developers onboarding to repositories with existing agent configurations

security-scan FAQ

What files does the security scan check?

It scans CLAUDE.md, settings.json, mcp.json, hooks/, and agents/*.md for hardcoded secrets, injection patterns, overly permissive permissions, and command injection risks.

Can I automatically fix security issues?

Yes, run npx ecc-agentshield scan --fix to apply safe, auto-fixable corrections like replacing hardcoded secrets with environment variable references and tightening wildcard permissions.

What does the Opus 4.6 deep analysis do?

It runs a three-agent adversarial pipeline (Attacker, Defender, Auditor) for comprehensive vulnerability analysis; requires ANTHROPIC_API_KEY and costs API credits.

How do I integrate this into CI/CD?

Use the GitHub Action (affaan-m/agentshield@v1) or export results as JSON (npx ecc-agentshield scan --format json) for pipeline integration with fail-on-findings flag.

What severity grades mean?

A (90–100) is secure, B (75–89) has minor issues, C (60–74) needs attention, D (40–59) has significant risks, and F (0–39) has critical vulnerabilities.

Full instructions (SKILL.md)

Source of truth, from affaan-m/ecc.


name: security-scan description: Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. metadata: origin: ECC

Security Scan Skill

Audit your Claude Code configuration for security issues using AgentShield.

When to Activate

  • Setting up a new Claude Code project
  • After modifying .claude/settings.json, CLAUDE.md, or MCP configs
  • Before committing configuration changes
  • When onboarding to a new repository with existing Claude Code configs
  • Periodic security hygiene checks

What It Scans

FileChecks
CLAUDE.mdHardcoded secrets, auto-run instructions, prompt injection patterns
settings.jsonOverly permissive allow lists, missing deny lists, dangerous bypass flags
mcp.jsonRisky MCP servers, hardcoded env secrets, npx supply chain risks
hooks/Command injection via interpolation, data exfiltration, silent error suppression
agents/*.mdUnrestricted tool access, prompt injection surface, missing model specs

Prerequisites

AgentShield must be installed. Check and install if needed:

# Check if installed
npx ecc-agentshield --version

# Install globally (recommended)
npm install -g ecc-agentshield

# Or run directly via npx (no install needed)
npx ecc-agentshield scan .

Usage

Basic Scan

Run against the current project's .claude/ directory:

# Scan current project
npx ecc-agentshield scan

# Scan a specific path
npx ecc-agentshield scan --path /path/to/.claude

# Scan with minimum severity filter
npx ecc-agentshield scan --min-severity medium

Output Formats

# Terminal output (default) — colored report with grade
npx ecc-agentshield scan

# JSON — for CI/CD integration
npx ecc-agentshield scan --format json

# Markdown — for documentation
npx ecc-agentshield scan --format markdown

# HTML — self-contained dark-theme report
npx ecc-agentshield scan --format html > security-report.html

Auto-Fix

Apply safe fixes automatically (only fixes marked as auto-fixable):

npx ecc-agentshield scan --fix

This will:

  • Replace hardcoded secrets with environment variable references
  • Tighten wildcard permissions to scoped alternatives
  • Never modify manual-only suggestions

Opus 4.6 Deep Analysis

Run the adversarial three-agent pipeline for deeper analysis:

# Requires ANTHROPIC_API_KEY
export ANTHROPIC_API_KEY=your-key
npx ecc-agentshield scan --opus --stream

This runs:

  1. Attacker (Red Team) — finds attack vectors
  2. Defender (Blue Team) — recommends hardening
  3. Auditor (Final Verdict) — synthesizes both perspectives

Initialize Secure Config

Scaffold a new secure .claude/ configuration from scratch:

npx ecc-agentshield init

Creates:

  • settings.json with scoped permissions and deny list
  • CLAUDE.md with security best practices
  • mcp.json placeholder

GitHub Action

Add to your CI pipeline:

- uses: affaan-m/agentshield@v1
  with:
    path: '.'
    min-severity: 'medium'
    fail-on-findings: true

Severity Levels

GradeScoreMeaning
A90-100Secure configuration
B75-89Minor issues
C60-74Needs attention
D40-59Significant risks
F0-39Critical vulnerabilities

Interpreting Results

Critical Findings (fix immediately)

  • Hardcoded API keys or tokens in config files
  • Bash(*) in the allow list (unrestricted shell access)
  • Command injection in hooks via ${file} interpolation
  • Shell-running MCP servers

High Findings (fix before production)

  • Auto-run instructions in CLAUDE.md (prompt injection vector)
  • Missing deny lists in permissions
  • Agents with unnecessary Bash access

Medium Findings (recommended)

  • Silent error suppression in hooks (2>/dev/null, || true)
  • Missing PreToolUse security hooks
  • npx -y auto-install in MCP server configs

Info Findings (awareness)

  • Missing descriptions on MCP servers
  • Prohibitive instructions correctly flagged as good practice

Links