security-scan
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and install the
ecc-agentshieldpackage from the npm registry and references a third-party GitHub repository located atgithub.com/affaan-m/agentshield. - [REMOTE_CODE_EXECUTION]: The skill utilizes
npxto execute theecc-agentshieldtool directly, which involves fetching and running external code from a non-trusted repository at runtime. - [COMMAND_EXECUTION]: The skill provides various shell commands for project auditing, auto-fixing configurations, and initializing project structures, specifically
npx ecc-agentshield scanandnpm install -g ecc-agentshield. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and scan project-specific configuration and documentation files (such as
CLAUDE.md,agents/*.md, andhooks/). This creates an attack surface where malicious instructions embedded in those files could attempt to influence the scanner's logic or the agent's behavior. - Ingestion points: Project configuration files including
.claude/settings.json,.claude/CLAUDE.md, and agent definitions in.claude/agents/*.md. - Capability inventory: The skill possesses the ability to execute shell commands and modify project configuration files (via the
--fixflag). - Boundary markers: The skill lacks explicit boundary markers or instructions telling the agent to treat scanned content as untrusted data.
- Sanitization: No sanitization or validation methods for the scanned file content are described in the skill instructions.
Audit Metadata