security-scan
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill relies on the
ecc-agentshieldpackage from npm. It suggests runningnpx ecc-agentshield, which downloads and executes code from a third-party source not listed as a trusted vendor or well-known service, posing a potential supply chain risk. - [COMMAND_EXECUTION]: The instructions include the use of the
--fixflag, which allows the tool to automatically modify configuration files in the.claude/directory. This grants an external tool write access to project settings. - [DATA_EXFILTRATION]: The 'Deep Analysis' feature (
--opusflag) requires anANTHROPIC_API_KEYand sends project configuration data to an external API. This involves transmitting potentially sensitive local configuration details to a third-party service. - [PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because the tool processes content from project files that could be controlled by an external contributor.
- Ingestion points: Reads
.claude/directory files includingCLAUDE.md,mcp.json, and agent definitions. - Boundary markers: Absent from the skill instructions.
- Capability inventory: Can modify files (
--fix), execute shell commands (npx), and perform network operations (--opus). - Sanitization: No mention of input validation or sanitization before processing project files.
Audit Metadata