Security Scan
affaan-m/ECC
Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield.
使用 AgentShield 扫描 Claude Code 配置(.claude/ 目录)中的安全漏洞、配置错误和注入风险。检查 CLAUDE.md、settings.json、MCP 服务端、钩子(Hooks)和智能体(Agents)定义。
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/ja-JP/skills/security-scan .claude/skills/security-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-scan" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-scan into .claude/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .agents/skills && cp -r skills-src/docs/ja-JP/skills/security-scan .agents/skills/security-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-scan" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-scan into .agents/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/docs/ja-JP/skills/security-scan .cursor/skills/security-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-scan" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-scan into .cursor/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/xu-xiang/everything-claude-code-zh.git --path docs/ja-JP/skills/security-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/docs/ja-JP/skills/security-scan .gemini/skills/security-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-scan into .gemini/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install xu-xiang/everything-claude-code-zh security-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .github/skills && cp -r skills-src/docs/ja-JP/skills/security-scan .github/skills/security-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-scan into .github/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install xu-xiang/everything-claude-code-zh security-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/docs/ja-JP/skills/security-scan .opencode/skills/security-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-scan" agent skill from https://github.com/xu-xiang/everything-claude-code-zh/tree/main/docs/ja-JP/skills/security-scan into .opencode/skills/security-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-scan使用 AgentShield 扫描 Claude Code 配置(.claude/ 目录)中的安全漏洞、配置错误和注入风险。检查 CLAUDE.md、settings.json、MCP 服务端、钩子(Hooks)和智能体(Agents)定义。
Security Scan is an agent skill from xu-xiang/everything-claude-code-zh. 使用 AgentShield 扫描 Claude Code 配置(.claude/ 目录)中的安全漏洞、配置错误和注入风险。检查 CLAUDE.md、settings.json、MCP 服务端、钩子(Hooks)和智能体(Agents)定义。
Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Agent Workflows, covering Security review and Agent instruction files. It works with Model Context Protocol. The repository describes itself as: everything-claude-code 中文翻译项目:完整的 Claude Code 配置集合(agents, skills, hooks, commands, rules, MCPs)。源自 Anthropic 黑客松获胜者的实战配置,助力中文工程师高效理解与使用 Claude Code。 The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit dfbf946. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comnpmjs.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ANTHROPIC_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Scan loads about 723 tokens when it runs. Until then it costs about 34 tokens; SKILL.md has 155 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from xu-xiang/everything-claude-code-zh at commit dfbf946, republished under its MIT licence (© xu-xiang). 155 words, ~723 tokens.
.claude/skills/security-scan/SKILL.md (or your agent's skills folder).使用 AgentShield 审计 Claude Code 配置的安全问题。
.claude/settings.json、CLAUDE.md 或 MCP 配置后| 文件 | 检查内容 |
|---|---|
CLAUDE.md | 硬编码的密钥(Secrets)、自动执行指令、提示词注入(Prompt Injection)模式 |
settings.json | 过度宽松的允许列表(Allowlist)、缺失的拒绝列表(Denylist)、危险的绕过标志位 |
mcp.json | 存在风险的 MCP 服务端、硬编码的环境密钥、npx 供应链风险 |
hooks/ | 由插值引起的命令注入、数据泄露、静默错误抑制 |
agents/*.md | 无限制的工具访问、提示词注入攻击面、缺失的模型规范 |
必须安装 AgentShield。请检查并根据需要进行安装:
# 确认是否已安装
npx ecc-agentshield --version
# 全局安装(推荐)
npm install -g ecc-agentshield
# 或通过 npx 直接运行(无需安装)
npx ecc-agentshield scan .针对当前项目的 .claude/ 目录运行:
# 扫描当前项目
npx ecc-agentshield scan
# 扫描特定路径
npx ecc-agentshield scan --path /path/to/.claude
# 按最小严重程度过滤扫描
npx ecc-agentshield scan --min-severity medium# 终端输出(默认) — 带有分级的彩色报告
npx ecc-agentshield scan
# JSON — 用于 CI/CD 集成
npx ecc-agentshield scan --format json
# Markdown — 用于文档
npx ecc-agentshield scan --format markdown
# HTML — 自包含的深色主题报告
npx ecc-agentshield scan --format html > security-report.html自动应用安全的修复(仅限标记为可自动修复的项目):
npx ecc-agentshield scan --fix这将执行以下操作:
运行对抗性的三智能体(3-Agent)流水线以进行更深层次的分析:
# 需要 ANTHROPIC_API_KEY
export ANTHROPIC_API_KEY=your-key
npx ecc-agentshield scan --opus --stream这将执行以下操作:
从零开始构建新的安全 .claude/ 配置:
npx ecc-agentshield init将创建的内容:
settings.jsonCLAUDE.mdmcp.json 占位符添加到 CI 流水线中:
- uses: affaan-m/agentshield@v1
with:
path: '.'
min-severity: 'medium'
fail-on-findings: true| 分级 | 分数 | 含义 |
|---|---|---|
| A | 90-100 | 安全的配置 |
| B | 75-89 | 轻微问题 |
| C | 60-74 | 需要注意 |
| D | 40-59 | 重大风险 |
| F | 0-39 | 关键漏洞 |
Bash(*)(无限制的 Shell 访问)${file} 插值引起的钩子(Hooks)内命令注入2>/dev/null、|| true)PreToolUse 安全钩子npx -y 自动安装© xu-xiang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in docs/ja-JP/skills/security-scan of xu-xiang/everything-claude-code-zh.
Open the folder on GitHubat commit dfbf946
Security Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Scan this skillxu-xiang/everything-claude-code-zh | 2k | — | ~723 | Automated safety check: Pass | MIT | |
| Security Scanaffaan-m/ECC | 276k | 5 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Security Scanaffaan-m/ECC | 276k | 2 repos | ~796 | Automated safety check: Pass | MIT | |
| Security Scanaffaan-m/ECC | 276k | 3 repos | ~738 | Automated safety check: Pass | MIT | |
| MCP Security Auditboshi-xixixi/TraeSkill | 275 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Agent Setup Health Audittw93/Waza | 7.2k | — | ~5.2k | Automated safety check: Notes | MIT |
affaan-m/ECC
Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield.
affaan-m/ECC
AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。
affaan-m/ECC
使用AgentShield扫描您的Claude代码配置(.claude/目录),以发现安全漏洞、配置错误和注入风险。检查CLAUDE.md、settings.json、MCP服务器、钩子和代理定义。
boshi-xixixi/TraeSkill
Audit MCP (Model Context Protocol) server configurations for security issues.
tw93/Waza
Audits a project's agent configuration, instruction drift, hooks, MCP and AI maintainability, then reports prioritized findings with evidence and next actions.
Gnosil/semantix
Troubleshoot and configure Semantix capabilities: Skills (project/custom/global/builtin priority, discovery dirs), Commands (override order, /dir:file naming), Hooks (11 events, automatic project…
xu-xiang/everything-claude-code-zh
Everything Claude Code 的交互式安装程序 — 引导用户选择并安装技能和规则到用户级或项目级目录,验证路径,并可选择优化已安装文件。
xu-xiang/everything-claude-code-zh
基于本能(Instinct)的学习系统,通过钩子(hooks)观察会话,创建带有置信度评分的原子本能,并将其演化为技能(Skills)、命令(Commands)或智能体(Agents)。v2.1 版本增加了项目作用域(project-scoped)的本能,以防止跨项目污染。
xu-xiang/everything-claude-code-zh
生产级 API 的 REST API 设计模式,包括资源命名、状态码、分页、过滤、错误响应、版本控制和速率限制. An agent skill from xu-xiang/everything-claude-code-zh.
xu-xiang/everything-claude-code-zh
后端架构模式、API 设计、数据库优化以及适用于 Node.js、Express 和 Next.js API 路由的服务端最佳实践。
xu-xiang/everything-claude-code-zh
后端架构模式、API 设计、数据库优化以及 Node.js、Express 和 Next.js API 路由的服务端最佳实践。
xu-xiang/everything-claude-code-zh
后端架构模式、API 设计、数据库优化以及针对 Node.js、Express 和 Next.js API 路由的服务端最佳实践。
Works with
Categories
使用 AgentShield 扫描 Claude Code 配置(.claude/ 目录)中的安全漏洞、配置错误和注入风险。检查 CLAUDE.md、settings.json、MCP 服务端、钩子(Hooks)和智能体(Agents)定义。. Security Scan is an agent skill from xu-xiang/everything-claude-code-zh.
Security Scan fits situations like: tasks that involve Security review; tasks that involve Agent instruction files.
Run `npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a claude-code`. Or copy the skill folder (docs/ja-JP/skills/security-scan in xu-xiang/everything-claude-code-zh) into .claude/skills/security-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a codex`. Or copy the skill folder (docs/ja-JP/skills/security-scan in xu-xiang/everything-claude-code-zh) into .agents/skills/security-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xu-xiang/everything-claude-code-zh --skill security-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-scan, .gemini/skills/security-scan, .github/skills/security-scan and .opencode/skills/security-scan in your project.
Going by SKILL.md and its folder, Security Scan needs the command-line tools its instructions call (npx and npm) and credentials named ANTHROPIC_API_KEY. Our summary lists: Node.js; A credential in ANTHROPIC_API_KEY.
SKILL.md names 2 domains. As links in the text: github.com and npmjs.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 723 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Security Scan: Security Scan (affaan-m/ECC, 276k stars), Security Scan (affaan-m/ECC, 276k stars), Security Scan (affaan-m/ECC, 276k stars) and MCP Security Audit (boshi-xixixi/TraeSkill, 275 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
xu-xiang (a GitHub user) maintains it in xu-xiang/everything-claude-code-zh, which has 1,976 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on March 5, 2026.
Source: xu-xiang/everything-claude-code-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.