security-scan
Warn
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the
ecc-agentshieldpackage from the public npm registry and references a GitHub repository atgithub.com/affaan-m/agentshieldwhich are not associated with trusted organizations or well-known services. - [REMOTE_CODE_EXECUTION]: The skill uses
npxandnpm install -gto execute the downloadedecc-agentshieldpackage. This constitutes execution of remote code from a third-party, non-standard source on the host system. - [COMMAND_EXECUTION]: The skill executes multiple shell commands to perform scans, initialize configurations, and apply 'auto-fixes' to the local file system.
- [CREDENTIALS_UNSAFE]: The 'Deep Analysis' feature instructs the user to
export ANTHROPIC_API_KEY. Providing sensitive API credentials to third-party CLI tools from unverified sources presents a risk of credential exposure or theft. - [INDIRECT_PROMPT_INJECTION]: The skill scans files like
CLAUDE.mdand agent definitions which can contain untrusted content. When using the--opusanalysis mode, there is a surface for indirect prompt injection if the processed content contains adversarial instructions that influence the LLM-based auditor.
Audit Metadata