Security Scan

affaan-m/ECC/skills/security-scan

作者 affaan-mef648e01899ba3e8dc6371642deaaf64b4477775無授權條款275K 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫4 天前更新

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. Use when auditing a .claude/ directory — CLAUDE.md, settings.json, MCP servers, hooks, or agent definitions.

僅含說明Security
AI 產生的概覽

使用 AgentShield 稽核 Claude Code 的 .claude/ 設定,檢查安全弱點、錯誤設定與注入風險。

功能
此技能會引導使用 AgentShield 工具稽核 Claude Code 設定目錄。檢查範圍涵蓋 CLAUDE.md、settings.json、mcp.json、hooks 與代理定義中的硬編碼密鑰、過於寬鬆的權限、指令注入與提示注入模式。文件說明了掃描指令、輸出格式(終端機、JSON、Markdown、HTML)、自動修正模式、可選的多代理深度分析、安全設定範本與 GitHub Action,並解釋嚴重程度分級與結果判讀方式。
適用情境
適用於建立新的 Claude Code 專案時、修改 .claude/settings.json、CLAUDE.md 或 MCP 設定之後、提交設定變更之前、接手已有 Claude Code 設定的程式庫時,或進行定期安全衛生檢查。
執行需求
需要安裝 AgentShield(ecc-agentshield),可透過 npm 全域安裝或以 npx 執行,因此需要 Node.js、npm 以及取得套件的網路存取。可選的深度分析需要 ANTHROPIC_API_KEY。此技能未附帶指令碼,僅包含說明。

Security Scan Skill

Audit your Claude Code configuration for security issues using AgentShield.

When to Activate

  • Setting up a new Claude Code project
  • After modifying .claude/settings.json, CLAUDE.md, or MCP configs
  • Before committing configuration changes
  • When onboarding to a new repository with existing Claude Code configs
  • Periodic security hygiene checks

What It Scans

FileChecks
CLAUDE.mdHardcoded secrets, auto-run instructions, prompt injection patterns
settings.jsonOverly permissive allow lists, missing deny lists, dangerous bypass flags
mcp.jsonRisky MCP servers, hardcoded env secrets, npx supply chain risks
hooks/Command injection via interpolation, data exfiltration, silent error suppression
agents/*.mdUnrestricted tool access, prompt injection surface, missing model specs

Prerequisites

AgentShield must be installed. Check and install if needed:

bash
# Check if installednpx ecc-agentshield --version
# Install globally (recommended)npm install -g ecc-agentshield
# Or run directly via npx (no install needed)npx ecc-agentshield scan .

Usage

Basic Scan

Run against the current project's .claude/ directory:

bash
# Scan current projectnpx ecc-agentshield scan
# Scan a specific pathnpx ecc-agentshield scan --path /path/to/.claude
# Scan with minimum severity filternpx ecc-agentshield scan --min-severity medium

Output Formats

bash
# Terminal output (default) — colored report with gradenpx ecc-agentshield scan
# JSON — for CI/CD integrationnpx ecc-agentshield scan --format json
# Markdown — for documentationnpx ecc-agentshield scan --format markdown
# HTML — self-contained dark-theme reportnpx ecc-agentshield scan --format html > security-report.html

Auto-Fix

Apply safe fixes automatically (only fixes marked as auto-fixable):

bash
npx ecc-agentshield scan --fix

This will:

  • Replace hardcoded secrets with environment variable references
  • Tighten wildcard permissions to scoped alternatives
  • Never modify manual-only suggestions

Opus 4.6 Deep Analysis

Run the adversarial three-agent pipeline for deeper analysis:

bash
# Requires ANTHROPIC_API_KEYexport ANTHROPIC_API_KEY=your-keynpx ecc-agentshield scan --opus --stream

This runs:

  1. Attacker (Red Team) — finds attack vectors
  2. Defender (Blue Team) — recommends hardening
  3. Auditor (Final Verdict) — synthesizes both perspectives

Initialize Secure Config

Scaffold a new secure .claude/ configuration from scratch:

bash
npx ecc-agentshield init

Creates:

  • settings.json with scoped permissions and deny list
  • CLAUDE.md with security best practices
  • mcp.json placeholder

GitHub Action

Add to your CI pipeline:

yaml
- uses: affaan-m/agentshield@v1  with:    path: '.'    min-severity: 'medium'    fail-on-findings: true

Severity Levels

GradeScoreMeaning
A90-100Secure configuration
B75-89Minor issues
C60-74Needs attention
D40-59Significant risks
F0-39Critical vulnerabilities

Interpreting Results

Critical Findings (fix immediately)

  • Hardcoded API keys or tokens in config files
  • Bash(*) in the allow list (unrestricted shell access)
  • Command injection in hooks via ${file} interpolation
  • Shell-running MCP servers

High Findings (fix before production)

  • Auto-run instructions in CLAUDE.md (prompt injection vector)
  • Missing deny lists in permissions
  • Agents with unnecessary Bash access

Medium Findings (recommended)

  • Silent error suppression in hooks (2>/dev/null, || true)
  • Missing PreToolUse security hooks
  • npx -y auto-install in MCP server configs

Info Findings (awareness)

  • Missing descriptions on MCP servers
  • Prohibitive instructions correctly flagged as good practice

Links

來源與署名

來源:affaan-m/ECC位於skills/security-scan提交ef648e0

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架