Security Scan
Use AgentShield to check Claude Code setup files.
AgentShield was made by affaan-m. Full credit goes to the author and project team.
When to use this skill
Use it:
- When you set up a Claude Code project
- After you change
CLAUDE.md,.claude/settings.json, hooks, agents, or MCP settings - Before you commit setup changes
- When you join a project that already has Claude Code files
- During a regular safety check
What to scan
| Path | Check for |
|---|---|
CLAUDE.md |
Secrets, auto-run rules, and prompt attacks |
.claude/settings.json |
Wide access, missing deny rules, and bypass flags |
.claude/mcp.json or mcp.json |
Risky servers, saved secrets, and unsafe package use |
.claude/hooks/ |
Shell input bugs, data leaks, and hidden errors |
.claude/agents/*.md |
Wide tool access, prompt attacks, and missing model rules |
Also check user-level files if they are in scope. Do not scan files outside the path the user asked for.
Before the scan
- Find the project root.
- Check that the target path exists.
- Check whether AgentShield is installed:
npx ecc-agentshield --versionIf the command is not available, ask before installing it. Do not install tools without clear approval.
Install it with:
npm install -g ecc-agentshieldOr run it once with npx:
npx ecc-agentshield scan .Note that npx may fetch and run code from npm. Tell the user before the first use.
Scan steps
1. Run a basic scan
From the project root:
npx ecc-agentshield scanFor one Claude Code folder:
npx ecc-agentshield scan --path /path/to/project/.claudeShow only medium or higher issues:
npx ecc-agentshield scan --min-severity mediumIf the project has more than one .claude/ folder, scan each one. Do not assume the root folder covers all workspaces.
2. Pick an output form
Use the normal terminal report for a local check:
npx ecc-agentshield scanUse JSON for scripts:
npx ecc-agentshield scan --format jsonUse Markdown for a report:
npx ecc-agentshield scan --format markdownUse HTML for a local web report:
npx ecc-agentshield scan --format html > security-report.htmlReports may contain file names, commands, or secret-like text. Do not commit or share a report until you check it.
3. Review each result
For every issue:
- Open the named file and line.
- Check that the result is real.
- Rate its harm and reach.
- Give the smallest safe fix.
- Mark false alarms as such. Do not hide them without a reason.
Never print a full key, token, cookie, or password. Mask all but a few safe chars.
4. Apply fixes with care
AgentShield can apply fixes that it marks as safe:
npx ecc-agentshield scan --fixBefore using --fix:
- Ask for approval.
- Make sure work can be restored with Git or a backup.
- Note any work that is not yet saved.
- Do not run it on a path with unknown files.
After using --fix:
- Review every file change.
- Run the scan again.
- Run any project tests that cover the changed files.
- Do not claim an issue is fixed until the new scan confirms it.
Auto-fix may:
- Replace saved secrets with environment variable names
- Narrow wildcard access
- Leave hard fixes for manual review
It may miss custom file forms or break a setup that needs wide access. Review all changes.
Deep scan
A deep scan uses an Anthropic API key:
export ANTHROPIC_API_KEY=your-key
npx ecc-agentshield scan --opus --streamUse this only when the user asks for it and the key is already set in a safe place. Never put a real key in a command, file, log, chat, or report.
The deep scan uses three roles:
- Attacker: Looks for ways to break the setup
- Defender: Gives safer rules
- Reviewer: Checks both views and gives a final result
Treat model findings as leads. Check each one in the real files.
Create a safe setup
For a new project only:
npx ecc-agentshield initThis may create:
settings.jsonwith narrow access and deny rulesCLAUDE.mdwith safe use rules- An MCP settings file
Do not run init over an existing setup until you know which files it may replace. Save or commit current work first.
GitHub Actions
Add this step only when the user asks for a CI check:
- uses: affaan-m/agentshield@v1
with:
path: "."
min-severity: "medium"
fail-on-findings: truePin the action to a trusted release or full commit ID when the project rules require it. Check that the path matches the real project root.
Grades
| Grade | Score | Meaning |
|---|---|---|
| A | 90 to 100 | Strong setup |
| B | 75 to 89 | Small issues |
| C | 60 to 74 | Needs review |
| D | 40 to 59 | High risk |
| F | 0 to 39 | Severe risk |
A high grade does not prove the setup is safe. A scan can miss new or custom risks.
Issue order
Fix issues in this order.
Critical
Fix now:
- API keys or tokens saved in setup files
Bash(*)or other full shell access- Hook input placed into a shell command without safe checks
- MCP servers that can run any shell command
If a secret is found, removing it from the file is not enough. Revoke it, make a new one, and check Git history.
High
Fix before real use:
- Rules that tell Claude to run commands without review
- Missing deny rules
- Agents with shell access they do not need
Medium
Fix when you can:
- Hidden hook errors such as
2>/dev/nullor|| true - Missing
PreToolUsesafety hooks - MCP servers that use
npx -yand fetch code on run
Info
Review and note:
- MCP servers with no clear note about their job
- Safe deny rules that the scan lists as good practice
Edge cases
- If no Claude Code files exist, report that there was nothing to scan.
- If a file cannot be read, name it and say the scan was not complete.
- If a path is a link, show where it points before scanning it.
- If generated files cause repeat alerts, fix the source file first.
- If a needed rule looks risky, explain why it is needed and narrow its scope.
- If the scan tool fails, report the command, safe error text, and exit code. Do not call the project safe.
- If a result is unclear, do not auto-fix it.
Example
A user asks: “Check this project before I commit my Claude settings.”
Run:
npx ecc-agentshield scan --path .claude --min-severity mediumThen report:
Scan result: C, 3 issues
Critical:
- .claude/settings.json allows Bash(*).
Fix: allow only the few commands this project needs.
High:
- .claude/hooks/check.sh puts file input into a shell command.
Fix: pass the file as a quoted argument and check its path.
Medium:
- .claude/mcp.json uses npx -y with no fixed package version.
Fix: use a reviewed, fixed version.
No files were changed.Ask before running --fix.
Links
- Author and source: affaan-m/agentshield
- npm package: ecc-agentshield