Security Scan

affaan-m/ECC/skills/security-scan

作者 affaan-mef648e01899ba3e8dc6371642deaaf64b4477775无许可证275K 个星标收录于 2026年10月9日更新于 2026年10月9日仓库4天前更新

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. Use when auditing a .claude/ directory — CLAUDE.md, settings.json, MCP servers, hooks, or agent definitions.

仅含说明Security
AI 生成的概览

使用 AgentShield 审计 Claude Code 的 .claude/ 配置,检查安全漏洞、错误配置和注入风险。

功能
该技能指导使用 AgentShield 工具审计 Claude Code 配置目录。检查范围包括 CLAUDE.md、settings.json、mcp.json、hooks 和代理定义中的硬编码密钥、过于宽松的权限、命令注入和提示注入模式。文档说明了扫描命令、输出格式(终端、JSON、Markdown、HTML)、自动修复模式、可选的多代理深度分析、安全配置脚手架和 GitHub Action,并解释严重级别分级及结果解读方式。
适用场景
适用于新建 Claude Code 项目时、修改 .claude/settings.json、CLAUDE.md 或 MCP 配置之后、提交配置变更之前、接手带有既有 Claude Code 配置的代码库时,或进行定期安全卫生检查。
运行要求
需要安装 AgentShield(ecc-agentshield),可通过 npm 全局安装或使用 npx 运行,因此需要 Node.js、npm 以及获取软件包的网络访问。可选的深度分析需要 ANTHROPIC_API_KEY。该技能不附带脚本,仅包含说明。

Security Scan Skill

Audit your Claude Code configuration for security issues using AgentShield.

When to Activate

  • Setting up a new Claude Code project
  • After modifying .claude/settings.json, CLAUDE.md, or MCP configs
  • Before committing configuration changes
  • When onboarding to a new repository with existing Claude Code configs
  • Periodic security hygiene checks

What It Scans

FileChecks
CLAUDE.mdHardcoded secrets, auto-run instructions, prompt injection patterns
settings.jsonOverly permissive allow lists, missing deny lists, dangerous bypass flags
mcp.jsonRisky MCP servers, hardcoded env secrets, npx supply chain risks
hooks/Command injection via interpolation, data exfiltration, silent error suppression
agents/*.mdUnrestricted tool access, prompt injection surface, missing model specs

Prerequisites

AgentShield must be installed. Check and install if needed:

bash
# Check if installednpx ecc-agentshield --version
# Install globally (recommended)npm install -g ecc-agentshield
# Or run directly via npx (no install needed)npx ecc-agentshield scan .

Usage

Basic Scan

Run against the current project's .claude/ directory:

bash
# Scan current projectnpx ecc-agentshield scan
# Scan a specific pathnpx ecc-agentshield scan --path /path/to/.claude
# Scan with minimum severity filternpx ecc-agentshield scan --min-severity medium

Output Formats

bash
# Terminal output (default) — colored report with gradenpx ecc-agentshield scan
# JSON — for CI/CD integrationnpx ecc-agentshield scan --format json
# Markdown — for documentationnpx ecc-agentshield scan --format markdown
# HTML — self-contained dark-theme reportnpx ecc-agentshield scan --format html > security-report.html

Auto-Fix

Apply safe fixes automatically (only fixes marked as auto-fixable):

bash
npx ecc-agentshield scan --fix

This will:

  • Replace hardcoded secrets with environment variable references
  • Tighten wildcard permissions to scoped alternatives
  • Never modify manual-only suggestions

Opus 4.6 Deep Analysis

Run the adversarial three-agent pipeline for deeper analysis:

bash
# Requires ANTHROPIC_API_KEYexport ANTHROPIC_API_KEY=your-keynpx ecc-agentshield scan --opus --stream

This runs:

  1. Attacker (Red Team) — finds attack vectors
  2. Defender (Blue Team) — recommends hardening
  3. Auditor (Final Verdict) — synthesizes both perspectives

Initialize Secure Config

Scaffold a new secure .claude/ configuration from scratch:

bash
npx ecc-agentshield init

Creates:

  • settings.json with scoped permissions and deny list
  • CLAUDE.md with security best practices
  • mcp.json placeholder

GitHub Action

Add to your CI pipeline:

yaml
- uses: affaan-m/agentshield@v1  with:    path: '.'    min-severity: 'medium'    fail-on-findings: true

Severity Levels

GradeScoreMeaning
A90-100Secure configuration
B75-89Minor issues
C60-74Needs attention
D40-59Significant risks
F0-39Critical vulnerabilities

Interpreting Results

Critical Findings (fix immediately)

  • Hardcoded API keys or tokens in config files
  • Bash(*) in the allow list (unrestricted shell access)
  • Command injection in hooks via ${file} interpolation
  • Shell-running MCP servers

High Findings (fix before production)

  • Auto-run instructions in CLAUDE.md (prompt injection vector)
  • Missing deny lists in permissions
  • Agents with unnecessary Bash access

Medium Findings (recommended)

  • Silent error suppression in hooks (2>/dev/null, || true)
  • Missing PreToolUse security hooks
  • npx -y auto-install in MCP server configs

Info Findings (awareness)

  • Missing descriptions on MCP servers
  • Prohibitive instructions correctly flagged as good practice

Links

来源与署名

来源:affaan-m/ECC位于skills/security-scan提交ef648e0

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架