affaan-m/ECC

security-scan

使用AgentShield扫描您的Claude代码配置(.claude/目录),以发现安全漏洞、配置错误和注入风险。检查CLAUDE.md、settings.json、MCP服务器、钩子和代理定义。

78CollectingRuns scripts
See how to use itView GitHub source
npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/security-scan"
Automated source guide

Source checked Jul 28, 2026·Refresh due Oct 26, 2026

Reorganized from the pinned upstream SKILL.md

Turn security-scan's source instructions into a guide you can follow

According to the pinned SKILL.md from affaan-m/ECC: 使用 AgentShield 审计您的 Claude Code 配置中的安全问题。

npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/security-scan"
Check the pinned source

Best fit

  • 使用AgentShield扫描您的Claude代码配置(.claude/目录),以发现安全漏洞、配置错误和注入风险。检查CLAUDE.md、settings.json、MCP服务器、钩子和代理定义。

Bring this context

  • A concrete task that matches the documented purpose of security-scan.
  • The files, examples, or context the task depends on.
  • Your constraints, target environment, and definition of done.

Expected outputs

  • A result that follows the pinned security-scan instructions.
  • A concise record of assumptions, inputs used, and unresolved questions.
  • A final check against the source workflow and relevant permission signals.

Key source sections

Read security-scan through these 5 source sections

Sections are extracted automatically from the pinned SKILL.md and link back to the source.

01

何时激活

设置新的 Claude Code 项目时 修改 .claude/settings.json、CLAUDE.md 或 MCP 配置后 提交配置更改前 加入具有现有 Claude Code 配置的新代码库时 定期进行安全卫生检查时

SKILL.md · 何时激活
设置新的 Claude Code 项目时修改 .claude/settings.json、CLAUDE.md 或 MCP 配置后提交配置更改前
02

扫描内容

Review the “扫描内容” section in the pinned source before continuing.

SKILL.md · 扫描内容
Review and apply the “扫描内容” source section.
03

先决条件

必须安装 AgentShield。检查并在需要时安装:

SKILL.md · 先决条件
必须安装 AgentShield。检查并在需要时安装:
04

Check if installed

Review the “Check if installed” section in the pinned source before continuing.

SKILL.md · Check if installed
Review and apply the “Check if installed” source section.
05

Install globally (recommended)

Review the “Install globally (recommended)” section in the pinned source before continuing.

SKILL.md · Install globally (recommended)
Review and apply the “Install globally (recommended)” source section.

SkillSignal prompt templates

Provide the task, context, and acceptance criteria

These prompts were written by SkillSignal from the source structure; they are not upstream text.

Task-start prompt

Confirm source fit, inputs, and outputs before acting.

Use security-scan to help me with: [specific task]. Context: [files, data, or background]. Constraints: [environment, scope, and prohibited actions]. Before acting, check the pinned SKILL.md and explain which sections apply, what inputs are still missing, and what you will deliver.

Source-guided execution

Make the Agent explicitly follow the key extracted sections.

Apply the pinned security-scan source to [task]. Pay particular attention to these source sections: “何时激活”, “扫描内容”, “先决条件”, “Check if installed”, “Install globally (recommended)”. Preserve the important decision at each step. Mark facts not covered by the source as “needs confirmation” instead of inventing them. Then verify the result against my acceptance criteria: [criteria].

Result-review prompt

Check omissions, permissions, and source drift before delivery.

Review the current security-scan result: (1) does it satisfy the original task; (2) were any applicable steps or limits in the pinned SKILL.md missed; (3) did it perform any unauthorized file, command, network, or data action; and (4) which conclusions remain unverified? List issues first, then fix only what the source or user authorization supports.

Output checklist

Verify each item before delivery

The task matches the purpose documented in the SKILL.md.

The source section “何时激活” has been checked.

The source section “扫描内容” has been checked.

The source section “先决条件” has been checked.

The source section “Check if installed” has been checked.

Inputs, constraints, and acceptance criteria are explicit.

Unverified facts, compatibility, and outcome claims are clearly marked.

Any file, command, network, or data action has been reviewed.

Choose a different workflow

When another Skill is the better fit

FAQ

What does security-scan do?

使用 AgentShield 审计您的 Claude Code 配置中的安全问题。

How do I start using security-scan?

The catalog detected this source-specific install command: npx skills add https://github.com/affaan-m/ECC --skill "docs/zh-CN/skills/security-scan". Inspect the command and pinned source before running it.

Which Agent platforms does it declare?

No dedicated Agent platform is declared in the pinned source record.

Repository stars
234,327
Repository forks
35,711
Quality
78/100
Source repository last pushed

Quality breakdown

Based on traceable docs and repository signals; stars are not treated as quality.

78/100
Documentation21/30
Specificity14/25
Maintenance20/20
Trust signals23/25

Compare before choosing

Related Agent Skills and source variants

These links are selected from shared tasks, functions, stacks, platforms, and same-name variants. Compare the source owner, documentation, permissions, and maintenance signals.

security-scan by affaan-m

Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

security-scan by affaan-m

AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。

ab-testing by coreyhaines31

When the user wants to plan, design, or implement an A/B test or experiment, or build a growth experimentation program. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," "hypothesis," "should I test this," "which version is better," "test two versions," "statistical significance," "how long should I run this test," "growth experiments," "experiment velocity," "experiment backlog," "ICE score," "experimentation program

churn-prevention by coreyhaines31

When the user wants to reduce churn, build cancellation flows, set up save offers, recover failed payments, or implement retention strategies. Also use when the user mentions 'churn,' 'cancel flow,' 'offboarding,' 'save offer,' 'dunning,' 'failed payment recovery,' 'win-back,' 'retention,' 'exit survey,' 'pause subscription,' 'involuntary churn,' 'people keep canceling,' 'churn rate is too high,' 'how do I keep users,' or 'customers are leaving.' Use this whenever someone is losing subscribers o

design-intelligence by event4u-app

Grounded design brief from the adopted corpus — style, WCAG-checked color tokens, typography, layout pattern, anti-patterns. Use on ui-design-brief or any which-style/palette/font/chart decision.

View original Skill.mdThis page is parsed directly from the repository SKILL.md without editorial rewriting. Collected: Jul 28, 2026 · about 1 min

安全扫描技能

使用 AgentShield 审计您的 Claude Code 配置中的安全问题。

何时激活

  • 设置新的 Claude Code 项目时
  • 修改 .claude/settings.jsonCLAUDE.md 或 MCP 配置后
  • 提交配置更改前
  • 加入具有现有 Claude Code 配置的新代码库时
  • 定期进行安全卫生检查时

扫描内容

文件检查项
CLAUDE.md硬编码的密钥、自动运行指令、提示词注入模式
settings.json过于宽松的允许列表、缺失的拒绝列表、危险的绕过标志
mcp.json有风险的 MCP 服务器、硬编码的环境变量密钥、npx 供应链风险
hooks/通过 ${file} 插值导致的命令注入、数据泄露、静默错误抑制
agents/*.md无限制的工具访问、提示词注入攻击面、缺失的模型规格

先决条件

必须安装 AgentShield。检查并在需要时安装:

# Check if installed
npx ecc-agentshield --version

# Install globally (recommended)
npm install -g ecc-agentshield

# Or run directly via npx (no install needed)
npx ecc-agentshield scan .

使用方法

基础扫描

针对当前项目的 .claude/ 目录运行:

# Scan current project
npx ecc-agentshield scan

# Scan a specific path
npx ecc-agentshield scan --path /path/to/.claude

# Scan with minimum severity filter
npx ecc-agentshield scan --min-severity medium

输出格式

# Terminal output (default) — colored report with grade
npx ecc-agentshield scan

# JSON — for CI/CD integration
npx ecc-agentshield scan --format json

# Markdown — for documentation
npx ecc-agentshield scan --format markdown

# HTML — self-contained dark-theme report
npx ecc-agentshield scan --format html > security-report.html

自动修复

自动应用安全的修复(仅修复标记为可自动修复的问题):

npx ecc-agentshield scan --fix

这将:

  • 用环境变量引用替换硬编码的密钥
  • 将通配符权限收紧为作用域明确的替代方案
  • 绝不修改仅限手动修复的建议

Opus 4.6 深度分析

运行对抗性的三智能体流程以进行更深入的分析:

# Requires ANTHROPIC_API_KEY
export ANTHROPIC_API_KEY=your-key
npx ecc-agentshield scan --opus --stream

这将运行:

  1. 攻击者(红队) — 寻找攻击向量
  2. 防御者(蓝队) — 建议加固措施
  3. 审计员(最终裁决) — 综合双方观点

初始化安全配置

从头开始搭建一个新的安全 .claude/ 配置:

npx ecc-agentshield init

创建:

  • 具有作用域权限和拒绝列表的 settings.json
  • 遵循安全最佳实践的 CLAUDE.md
  • mcp.json 占位符

GitHub Action

添加到您的 CI 流水线中:

- uses: affaan-m/agentshield@v1
  with:
    path: '.'
    min-severity: 'medium'
    fail-on-findings: true

严重性等级

等级分数含义
A90-100安全配置
B75-89轻微问题
C60-74需要注意
D40-59显著风险
F0-39严重漏洞

结果解读

关键发现(立即修复)

  • 配置文件中硬编码的 API 密钥或令牌
  • 允许列表中存在 Bash(*)(无限制的 shell 访问)
  • 钩子中通过 ${file} 插值导致的命令注入
  • 运行 shell 的 MCP 服务器

高优先级发现(生产前修复)

  • CLAUDE.md 中的自动运行指令(提示词注入向量)
  • 权限配置中缺少拒绝列表
  • 具有不必要 Bash 访问权限的代理

中优先级发现(建议修复)

  • 钩子中的静默错误抑制(2>/dev/null|| true
  • 缺少 PreToolUse 安全钩子
  • MCP 服务器配置中的 npx -y 自动安装

信息性发现(了解情况)

  • MCP 服务器缺少描述信息
  • 正确标记为良好实践的限制性指令

链接

Source repo
affaan-m/ECC
Skill path
docs/zh-CN/skills/security-scan/SKILL.md
Commit SHA
4e973d3eaf92
Repository license
MIT
Data collected