security-scan
Warn
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill relies on an external utility, ecc-agentshield, hosted on the npm registry and GitHub, which is not part of a pre-defined trusted vendor list.
- [REMOTE_CODE_EXECUTION]: Instructions specify the use of npx ecc-agentshield, which downloads and executes code from the npm registry at runtime.
- [COMMAND_EXECUTION]: The skill uses shell commands to install packages, run security scans, and initialize configuration files within the project's .claude/ directory.
Audit Metadata