security-scan

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to download and install the ecc-agentshield package from the npm registry and references a third-party GitHub repository located at github.com/affaan-m/agentshield.
  • [REMOTE_CODE_EXECUTION]: The skill utilizes npx to execute the ecc-agentshield tool directly, which involves fetching and running external code from a non-trusted repository at runtime.
  • [COMMAND_EXECUTION]: The skill provides various shell commands for project auditing, auto-fixing configurations, and initializing project structures, specifically npx ecc-agentshield scan and npm install -g ecc-agentshield.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and scan project-specific configuration and documentation files (such as CLAUDE.md, agents/*.md, and hooks/). This creates an attack surface where malicious instructions embedded in those files could attempt to influence the scanner's logic or the agent's behavior.
  • Ingestion points: Project configuration files including .claude/settings.json, .claude/CLAUDE.md, and agent definitions in .claude/agents/*.md.
  • Capability inventory: The skill possesses the ability to execute shell commands and modify project configuration files (via the --fix flag).
  • Boundary markers: The skill lacks explicit boundary markers or instructions telling the agent to treat scanned content as untrusted data.
  • Sanitization: No sanitization or validation methods for the scanned file content are described in the skill instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 03:41 PM
Security Audit — agent-trust-hub — security-scan