security-scan

Warn

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill relies on an external utility, ecc-agentshield, hosted on the npm registry and GitHub, which is not part of a pre-defined trusted vendor list.
  • [REMOTE_CODE_EXECUTION]: Instructions specify the use of npx ecc-agentshield, which downloads and executes code from the npm registry at runtime.
  • [COMMAND_EXECUTION]: The skill uses shell commands to install packages, run security scans, and initialize configuration files within the project's .claude/ directory.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 6, 2026, 04:01 AM
Security Audit — agent-trust-hub — security-scan