security-scan

Warn

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the ecc-agentshield package from the public npm registry and references a GitHub repository at github.com/affaan-m/agentshield which are not associated with trusted organizations or well-known services.
  • [REMOTE_CODE_EXECUTION]: The skill uses npx and npm install -g to execute the downloaded ecc-agentshield package. This constitutes execution of remote code from a third-party, non-standard source on the host system.
  • [COMMAND_EXECUTION]: The skill executes multiple shell commands to perform scans, initialize configurations, and apply 'auto-fixes' to the local file system.
  • [CREDENTIALS_UNSAFE]: The 'Deep Analysis' feature instructs the user to export ANTHROPIC_API_KEY. Providing sensitive API credentials to third-party CLI tools from unverified sources presents a risk of credential exposure or theft.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans files like CLAUDE.md and agent definitions which can contain untrusted content. When using the --opus analysis mode, there is a surface for indirect prompt injection if the processed content contains adversarial instructions that influence the LLM-based auditor.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — security-scan