security-scan
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
ecc-agentshieldpackage from npm and references the project repository atgithub.com/affaan-m/agentshield. - [REMOTE_CODE_EXECUTION]: Recommends running
npx ecc-agentshield, which downloads and executes remote code from the npm registry at runtime. - [COMMAND_EXECUTION]: Provides various shell commands for scanning projects, fixing security issues, and initializing new configuration files.
- [CREDENTIALS_UNSAFE]: Instructs the user to manually export their
ANTHROPIC_API_KEYto the environment for use by the tool's deep analysis feature. - [PROMPT_INJECTION]: The skill analyzes external, potentially untrusted project data, creating a surface for indirect prompt injection.
- Ingestion points: Files in the
.claude/directory, includingCLAUDE.md,settings.json, andhooks/scripts (SKILL.md). - Boundary markers: No explicit boundary markers or ignore instructions for the agent are specified in the provided text.
- Capability inventory: The skill uses shell command execution (
npx) and broad file reading capabilities. - Sanitization: No validation or sanitization mechanisms for the processed configuration content are described.
Audit Metadata