security-scan

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill relies on the ecc-agentshield package from npm. It suggests running npx ecc-agentshield, which downloads and executes code from a third-party source not listed as a trusted vendor or well-known service, posing a potential supply chain risk.
  • [COMMAND_EXECUTION]: The instructions include the use of the --fix flag, which allows the tool to automatically modify configuration files in the .claude/ directory. This grants an external tool write access to project settings.
  • [DATA_EXFILTRATION]: The 'Deep Analysis' feature (--opus flag) requires an ANTHROPIC_API_KEY and sends project configuration data to an external API. This involves transmitting potentially sensitive local configuration details to a third-party service.
  • [PROMPT_INJECTION]: The skill represents an indirect prompt injection surface because the tool processes content from project files that could be controlled by an external contributor.
  • Ingestion points: Reads .claude/ directory files including CLAUDE.md, mcp.json, and agent definitions.
  • Boundary markers: Absent from the skill instructions.
  • Capability inventory: Can modify files (--fix), execute shell commands (npx), and perform network operations (--opus).
  • Sanitization: No mention of input validation or sanitization before processing project files.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — security-scan