Catalog
affaan-m/security-scan

affaan-m

security-scan

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

global
origin:ECC
New~1.1k
v1.2Saved Jul 14, 2026

Security Scan Skill

Audit your Claude Code configuration for security issues using AgentShield.

When to Activate

  • Setting up a new Claude Code project
  • After modifying .claude/settings.json, CLAUDE.md, or MCP configs
  • Before committing configuration changes
  • When onboarding to a new repository with existing Claude Code configs
  • Periodic security hygiene checks

What It Scans

File Checks
CLAUDE.md Hardcoded secrets, auto-run instructions, prompt injection patterns
settings.json Overly permissive allow lists, missing deny lists, dangerous bypass flags
mcp.json Risky MCP servers, hardcoded env secrets, npx supply chain risks
hooks/ Command injection via interpolation, data exfiltration, silent error suppression
agents/*.md Unrestricted tool access, prompt injection surface, missing model specs

Prerequisites

AgentShield must be installed. Check and install if needed:

# Check if installed
npx ecc-agentshield --version

# Install globally (recommended)
npm install -g ecc-agentshield

# Or run directly via npx (no install needed)
npx ecc-agentshield scan .

Usage

Basic Scan

Run against the current project's .claude/ directory:

# Scan current project
npx ecc-agentshield scan

# Scan a specific path
npx ecc-agentshield scan --path /path/to/.claude

# Scan with minimum severity filter
npx ecc-agentshield scan --min-severity medium

Output Formats

# Terminal output (default) — colored report with grade
npx ecc-agentshield scan

# JSON — for CI/CD integration
npx ecc-agentshield scan --format json

# Markdown — for documentation
npx ecc-agentshield scan --format markdown

# HTML — self-contained dark-theme report
npx ecc-agentshield scan --format html > security-report.html

Auto-Fix

Apply safe fixes automatically (only fixes marked as auto-fixable):

npx ecc-agentshield scan --fix

This will:

  • Replace hardcoded secrets with environment variable references
  • Tighten wildcard permissions to scoped alternatives
  • Never modify manual-only suggestions

Opus 4.6 Deep Analysis

Run the adversarial three-agent pipeline for deeper analysis:

# Requires ANTHROPIC_API_KEY
export ANTHROPIC_API_KEY=your-key
npx ecc-agentshield scan --opus --stream

This runs:

  1. Attacker (Red Team) — finds attack vectors
  2. Defender (Blue Team) — recommends hardening
  3. Auditor (Final Verdict) — synthesizes both perspectives

Initialize Secure Config

Scaffold a new secure .claude/ configuration from scratch:

npx ecc-agentshield init

Creates:

  • settings.json with scoped permissions and deny list
  • CLAUDE.md with security best practices
  • mcp.json placeholder

GitHub Action

Add to your CI pipeline:

- uses: affaan-m/agentshield@v1
  with:
    path: '.'
    min-severity: 'medium'
    fail-on-findings: true

Severity Levels

Grade Score Meaning
A 90-100 Secure configuration
B 75-89 Minor issues
C 60-74 Needs attention
D 40-59 Significant risks
F 0-39 Critical vulnerabilities

Interpreting Results

Critical Findings (fix immediately)

  • Hardcoded API keys or tokens in config files
  • Bash(*) in the allow list (unrestricted shell access)
  • Command injection in hooks via ${file} interpolation
  • Shell-running MCP servers

High Findings (fix before production)

  • Auto-run instructions in CLAUDE.md (prompt injection vector)
  • Missing deny lists in permissions
  • Agents with unnecessary Bash access
  • Silent error suppression in hooks (2>/dev/null, || true)
  • Missing PreToolUse security hooks
  • npx -y auto-install in MCP server configs

Info Findings (awareness)

  • Missing descriptions on MCP servers
  • Prohibitive instructions correctly flagged as good practice
Files1
1 files · 1.0 KB

Select a file to preview

Overall Score

82/100

Grade

B

Good

Safety

80

Quality

85

Clarity

88

Completeness

78

Summary

This skill guides an agent to audit Claude Code security configurations using AgentShield, a specialized security scanning tool. It scans CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions for hardcoded secrets, command injection, prompt injection, and permission misconfigurations. The skill provides instructions for basic scans, deep analysis via Claude Opus, auto-fixing, and CI/CD integration, with clear severity levels and interpretation guidance.

Detected Capabilities

tool execution (npm/npx)directory scanningfile reading (.claude/ configs)environment variable reading (ANTHROPIC_API_KEY)output to multiple formats (terminal, json, markdown, html)file writing (initialization of .claude/ directory)CI/CD integration (GitHub Actions)

Trigger Keywords

Phrases that MCP clients use to match this skill to user intent.

security auditscan claude configagentshield scanvulnerability detectionconfig validationcredential exposure check

Risk Signals

INFO

Requires ANTHROPIC_API_KEY environment variable for Opus deep analysis

Usage section, Opus 4.6 Deep Analysis subsection
INFO

Environment variable reading for API authentication

Opus 4.6 Deep Analysis code example
WARNING

Auto-fix modifies configuration files (settings.json, CLAUDE.md)

Auto-Fix subsection
INFO

GitHub Action integration writes findings to workflow context

GitHub Action subsection

Referenced Domains

External domains referenced in skill content, detected by static analysis.

github.comwww.npmjs.com

Use Cases

  • Audit Claude Code security configuration before deployment
  • Identify hardcoded secrets and credential exposure in .claude/ configs
  • Detect command injection and prompt injection vulnerabilities
  • Validate MCP server configurations for supply chain risks
  • Establish secure configuration baselines for new projects
  • Run security scans as part of CI/CD pipeline
  • Perform periodic security hygiene checks on existing projects

Quality Notes

  • Skill is well-structured with clear section hierarchy and practical examples
  • Prerequisites clearly documented with fallback options (global install vs npx)
  • Usage patterns cover both basic and advanced scenarios (basic scan, deep analysis, auto-fix)
  • Severity levels table provides clear decision framework for triage
  • Interpreting Results section offers concrete guidance on critical vs high vs medium findings
  • Links to external resources (GitHub, npm) are complete
  • No examples of actual vulnerability detection are shown (minor gap for clarity)
  • Auto-fix behavior is appropriately constrained to 'safe fixes' with explicit documentation
Model: claude-haiku-4-5-20251001Analyzed: Jul 14, 2026

Reviews

Add this skill to your library to leave a review.

No reviews yet

Be the first to share your experience.

Version History

v1.2

Content updated

2026-07-14

Latest
v1.1

Content updated

2026-04-20

v1.0

Seeded from github.com/affaan-m/everything-claude-code

2026-03-16

Use affaan-m/security-scan in your dev environment

Command Palette

Search for a command to run...