Agent skill

Security Scan

by affaan-m in affaan-m/ECC

AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。

MITAuto-check passedAgent Workflows

Install Security Scan

skills CLI
$ npx skills add affaan-m/ECC --skill security-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC security-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/ja-JP/skills/security-scan .claude/skills/security-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-scan
GitHub stars
276k
Used in
2 other repos
Token cost
~796 tokens
SKILL.md length
139 words
Files
1
Skills in repo
673
Repo updated
First seen
Licence
MIT

At a glance

AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。

  • Works in 3 steps: 攻撃者(レッドチーム) — 攻撃ベクトルを発見 → 防御者(ブルーチーム) — 強化を推奨 → 監査人(最終判定) — 両方の観点を統合
  • Tasks that involve Security review
  • SKILL.md covers 起動タイミング, スキャン対象, 前提条件 and 使用方法, plus 3 more sections
  • Calls npx and npm; needs ANTHROPIC_API_KEY

What it does

Security Scan is an agent skill from affaan-m/ECC. AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。

Its SKILL.md is about 800 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Security review and Agent instruction files. It works with Model Context Protocol. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Tasks that involve Security review
  • Tasks that involve Agent instruction files

Example prompts

  • “/security-scan”

Requirements

  • Node.js
  • A credential in ANTHROPIC_API_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. 攻撃者(レッドチーム) — 攻撃ベクトルを発見
  2. 防御者(ブルーチーム) — 強化を推奨
  3. 監査人(最終判定) — 両方の観点を統合

What it can do on your machine

Read from SKILL.md and the folder at commit ef648e0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • npmjs.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Scan loads about 796 tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 139 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~796

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit ef648e0, republished under its MIT licence (© affaan-m). 139 words, ~796 tokens.

Download SKILL.mdSave it as .claude/skills/security-scan/SKILL.md (or your agent's skills folder).
name
security-scan
description
AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。

Security Scan Skill

AgentShield を使用して、Claude Code の設定のセキュリティ問題を監査します。

起動タイミング

  • 新しい Claude Code プロジェクトのセットアップ時
  • .claude/settings.json、CLAUDE.md、または MCP 設定の変更後
  • 設定変更をコミットする前
  • 既存の Claude Code 設定を持つ新しいリポジトリにオンボーディングする際
  • 定期的なセキュリティ衛生チェック

スキャン対象

ファイルチェック内容
CLAUDE.mdハードコードされたシークレット、自動実行命令、プロンプトインジェクションパターン
settings.json過度に寛容な許可リスト、欠落した拒否リスト、危険なバイパスフラグ
mcp.jsonリスクのある MCP サーバー、ハードコードされた環境シークレット、npx サプライチェーンリスク
hooks/補間によるコマンドインジェクション、データ流出、サイレントエラー抑制
agents/*.md無制限のツールアクセス、プロンプトインジェクション表面、欠落したモデル仕様

前提条件

AgentShield がインストールされている必要があります。確認し、必要に応じてインストールします:

bash
# インストール済みか確認
npx ecc-agentshield --version

# グローバルにインストール(推奨)
npm install -g ecc-agentshield

# または npx 経由で直接実行(インストール不要)
npx ecc-agentshield scan .

使用方法

基本スキャン

現在のプロジェクトの .claude/ ディレクトリに対して実行します:

bash
# 現在のプロジェクトをスキャン
npx ecc-agentshield scan

# 特定のパスをスキャン
npx ecc-agentshield scan --path /path/to/.claude

# 最小深刻度フィルタでスキャン
npx ecc-agentshield scan --min-severity medium
出力フォーマット
bash
# ターミナル出力(デフォルト) — グレード付きのカラーレポート
npx ecc-agentshield scan

# JSON — CI/CD 統合用
npx ecc-agentshield scan --format json

# Markdown — ドキュメント用
npx ecc-agentshield scan --format markdown

# HTML — 自己完結型のダークテーマレポート
npx ecc-agentshield scan --format html > security-report.html
自動修正

安全な修正を自動的に適用します(自動修正可能とマークされた修正のみ):

bash
npx ecc-agentshield scan --fix

これにより以下が実行されます:

  • ハードコードされたシークレットを環境変数参照に置き換え
  • ワイルドカード権限をスコープ付き代替に厳格化
  • 手動のみの提案は変更しない
Opus 4.6 ディープ分析

より深い分析のために敵対的な3エージェントパイプラインを実行します:

bash
# ANTHROPIC_API_KEY が必要
export ANTHROPIC_API_KEY=your-key
npx ecc-agentshield scan --opus --stream

これにより以下が実行されます:

  1. 攻撃者(レッドチーム) — 攻撃ベクトルを発見
  2. 防御者(ブルーチーム) — 強化を推奨
  3. 監査人(最終判定) — 両方の観点を統合
安全な設定の初期化

新しい安全な .claude/ 設定をゼロから構築します:

bash
npx ecc-agentshield init

作成されるもの:

  • スコープ付き権限と拒否リストを持つ settings.json
  • セキュリティベストプラクティスを含む CLAUDE.md
  • mcp.json プレースホルダー
GitHub Action

CI パイプラインに追加します:

yaml
- uses: affaan-m/agentshield@v1
  with:
    path: '.'
    min-severity: 'medium'
    fail-on-findings: true

深刻度レベル

グレードスコア意味
A90-100安全な設定
B75-89軽微な問題
C60-74注意が必要
D40-59重大なリスク
F0-39クリティカルな脆弱性

結果の解釈

クリティカルな発見(即座に修正)
  • 設定ファイル内のハードコードされた API キーまたはトークン
  • 許可リスト内の Bash(*)(無制限のシェルアクセス)
  • ${file} 補間によるフック内のコマンドインジェクション
  • シェルを実行する MCP サーバー
高い発見(本番前に修正)
  • CLAUDE.md 内の自動実行命令(プロンプトインジェクションベクトル)
  • 権限内の欠落した拒否リスト
  • 不要な Bash アクセスを持つエージェント
中程度の発見(推奨)
  • フック内のサイレントエラー抑制(2>/dev/null、|| true)
  • 欠落した PreToolUse セキュリティフック
  • MCP サーバー設定内の npx -y 自動インストール
情報の発見(認識)
  • MCP サーバーの欠落した説明
  • 正しくフラグ付けされた禁止命令(グッドプラクティス)

リンク

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/ja-JP/skills/security-scan of affaan-m/ECC.

Open the folder on GitHubat commit ef648e0

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in affaan-m/ECC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Scan this skillaffaan-m/ECC276k2 repos~796Automated safety check: PassMIT
Security Scanxu-xiang/everything-claude-code-zh2k—~723Automated safety check: PassMIT
Security Scanxu-xiang/everything-claude-code-zh2k—~771Automated safety check: PassMIT
MCP Security Auditboshi-xixixi/TraeSkill275—~2.2kAutomated safety check: PassMIT
Agent Setup Health Audittw93/Waza7.2k—~5.2kAutomated safety check: NotesMIT
Semantix GuideGnosil/semantix821—~2.1kAutomated safety check: PassMIT

Similar skills

  • Security Scan

    xu-xiang/everything-claude-code-zh

    使用 AgentShield 扫描 Claude Code 配置(.claude/ 目录)中的安全漏洞、配置错误和注入风险。检查 CLAUDE.md、settings.json、MCP 服务端、钩子(Hooks)和智能体(Agents)定义。

    2k GitHub stars~723 tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Security Scan

    xu-xiang/everything-claude-code-zh

    使用 AgentShield 扫描您的 Claude Code 配置(.claude/ 目录)是否存在安全漏洞、配置错误和注入风险。检查项包括 CLAUDE.md、settings.json、MCP 服务器、钩子(Hooks)以及智能体(Agent)定义。

    2k GitHub stars~771 tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • MCP Security Audit

    boshi-xixixi/TraeSkill

    Audit MCP (Model Context Protocol) server configurations for security issues.

    275 GitHub stars~2.2k tokensUpdated 5 mo ago
    Agent WorkflowsAuto-check passed
  • Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.

    7.2k GitHub stars~5.2k tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Semantix Guide

    Gnosil/semantix

    Troubleshoot and configure Semantix capabilities: Skills (project/custom/global/builtin priority, discovery dirs), Commands (override order, /dir:file naming), Hooks (11 events, automatic project…

    821 GitHub stars~2.1k tokensUpdated 4 days ago
    Agent WorkflowsAuto-check passed
  • Working With Claude Code Docs

    obra/superpowers-developing-for-claude-code

    Looks up official Claude Code documentation stored as reference files instead of guessing about CLI commands, configuration, or plugin APIs.

    142 GitHub stars~1.5k tokensUpdated 10 mo ago
    Agent WorkflowsAuto-check passed

More from affaan-m/ECC

All 673 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    276k GitHub starsUsed in 5 repos~1.9k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    276k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    276k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    276k GitHub stars~2.9k tokensUpdated 4 days ago
    Auto-check passed
  • Measures whether agents actually follow a skill, rule or agent definition by generating scenarios at three strictness levels and scoring tool-call traces.

    276k GitHub starsUsed in 1 repo~623 tokens
    Auto-check passed
  • Instinct-based learning system that observes sessions via hooks, creates atomic instincts with confidence scoring, and evolves them into skills/commands/agents.

    276k GitHub stars~3.5k tokensUpdated 4 days ago
    Auto-check passed

Questions about Security Scan

What does Security Scan do?

AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。. Security Scan is an agent skill from affaan-m/ECC.

When should I use Security Scan?

Security Scan fits situations like: tasks that involve Security review; tasks that involve Agent instruction files.

How do I install Security Scan in Claude Code?

Run `npx skills add affaan-m/ECC --skill security-scan -a claude-code`. Or copy the skill folder (docs/ja-JP/skills/security-scan in affaan-m/ECC) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.

How do I install Security Scan in Codex?

Run `npx skills add affaan-m/ECC --skill security-scan -a codex`. Or copy the skill folder (docs/ja-JP/skills/security-scan in affaan-m/ECC) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.

Can I use Security Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.

What does Security Scan need to run?

Going by SKILL.md and its folder, Security Scan needs the command-line tools its instructions call (npx and npm) and credentials named ANTHROPIC_API_KEY. Our summary lists: Node.js; A credential in ANTHROPIC_API_KEY.

Does Security Scan access the network?

SKILL.md names 2 domains. As links in the text: github.com and npmjs.com. This is read from the text; nothing was executed.

Is Security Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Security Scan use?

Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Scan use?

About 796 tokens (SKILL.md is roughly 3.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Scan?

Skills that share tags, products or a category with Security Scan: Security Scan (xu-xiang/everything-claude-code-zh, 2k stars), Security Scan (xu-xiang/everything-claude-code-zh, 2k stars), MCP Security Audit (boshi-xixixi/TraeSkill, 275 stars) and Agent Setup Health Audit (tw93/Waza, 7.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Scan?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 275,546 GitHub stars. The repository holds 673 skills in this directory. The repository was last updated on October 5, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.