Source profileQuality 71/100Review permissions

affaan-m/ECC/docs/ja-JP/skills/security-scan/SKILL.md

security-scan

Use it for engineering tasks; the detail page covers purpose, installation, and practical steps.

Source repository stars
234,327
Declared platforms
1
Static risk flags
1
Last source update
2026-07-27
Source checked
2026-07-28

Decision brief

What it does—and where it fits

AgentShield を使用して、Claude Code の設定のセキュリティ問題を監査します。

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeDeclaredSource recordInstall path and trigger
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/affaan-m/ECC --skill "docs/ja-JP/skills/security-scan"
    Safe inspection promptEditorial

    Inspect the Agent Skill "security-scan" from https://github.com/affaan-m/ECC/blob/4e973d3eaf92d97f8d2e2d8abb39d8bdc8711b38/docs/ja-JP/skills/security-scan/SKILL.md at commit 4e973d3eaf92d97f8d2e2d8abb39d8bdc8711b38. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      起動タイミング

      新しい Claude Code プロジェクトのセットアップ時

      新しい Claude Code プロジェクトのセットアップ時.claude/settings.json、CLAUDE.md、または MCP 設定の変更後設定変更をコミットする前
    2. 02

      スキャン対象

      Review the “スキャン対象” section in the pinned source before continuing.

      Review and apply the “スキャン対象” source section.
    3. 03

      前提条件

      AgentShield がインストールされている必要があります。確認し、必要に応じてインストールします:

      AgentShield がインストールされている必要があります。確認し、必要に応じてインストールします:
    4. 04

      インストール済みか確認

      Review the “インストール済みか確認” section in the pinned source before continuing.

      Review and apply the “インストール済みか確認” source section.

    Permission review

    Static risk signals and limitations

    Runs scripts

    medium · line 29

    The documentation asks the agent to run terminal commands or scripts.

    npx ecc-agentshield --version

    Runs scripts

    medium · line 32

    The documentation asks the agent to run terminal commands or scripts.

    npm install -g ecc-agentshield

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score71/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars234,327SourceRepository attention, not individual Skill quality
    Compatibility1 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    affaan-m/ECC
    Skill path
    docs/ja-JP/skills/security-scan/SKILL.md
    Commit
    4e973d3eaf92d97f8d2e2d8abb39d8bdc8711b38
    License
    MIT
    Collected
    2026-07-28
    Default branch
    main
    View the original SKILL.md

    Security Scan Skill

    AgentShield を使用して、Claude Code の設定のセキュリティ問題を監査します。

    起動タイミング

    • 新しい Claude Code プロジェクトのセットアップ時
    • .claude/settings.jsonCLAUDE.md、または MCP 設定の変更後
    • 設定変更をコミットする前
    • 既存の Claude Code 設定を持つ新しいリポジトリにオンボーディングする際
    • 定期的なセキュリティ衛生チェック

    スキャン対象

    ファイルチェック内容
    CLAUDE.mdハードコードされたシークレット、自動実行命令、プロンプトインジェクションパターン
    settings.json過度に寛容な許可リスト、欠落した拒否リスト、危険なバイパスフラグ
    mcp.jsonリスクのある MCP サーバー、ハードコードされた環境シークレット、npx サプライチェーンリスク
    hooks/補間によるコマンドインジェクション、データ流出、サイレントエラー抑制
    agents/*.md無制限のツールアクセス、プロンプトインジェクション表面、欠落したモデル仕様

    前提条件

    AgentShield がインストールされている必要があります。確認し、必要に応じてインストールします:

    # インストール済みか確認
    npx ecc-agentshield --version
    
    # グローバルにインストール(推奨)
    npm install -g ecc-agentshield
    
    # または npx 経由で直接実行(インストール不要)
    npx ecc-agentshield scan .
    

    使用方法

    基本スキャン

    現在のプロジェクトの .claude/ ディレクトリに対して実行します:

    # 現在のプロジェクトをスキャン
    npx ecc-agentshield scan
    
    # 特定のパスをスキャン
    npx ecc-agentshield scan --path /path/to/.claude
    
    # 最小深刻度フィルタでスキャン
    npx ecc-agentshield scan --min-severity medium
    

    出力フォーマット

    # ターミナル出力(デフォルト) — グレード付きのカラーレポート
    npx ecc-agentshield scan
    
    # JSON — CI/CD 統合用
    npx ecc-agentshield scan --format json
    
    # Markdown — ドキュメント用
    npx ecc-agentshield scan --format markdown
    
    # HTML — 自己完結型のダークテーマレポート
    npx ecc-agentshield scan --format html > security-report.html
    

    自動修正

    安全な修正を自動的に適用します(自動修正可能とマークされた修正のみ):

    npx ecc-agentshield scan --fix
    

    これにより以下が実行されます:

    • ハードコードされたシークレットを環境変数参照に置き換え
    • ワイルドカード権限をスコープ付き代替に厳格化
    • 手動のみの提案は変更しない

    Opus 4.6 ディープ分析

    より深い分析のために敵対的な3エージェントパイプラインを実行します:

    # ANTHROPIC_API_KEY が必要
    export ANTHROPIC_API_KEY=your-key
    npx ecc-agentshield scan --opus --stream
    

    これにより以下が実行されます:

    1. 攻撃者(レッドチーム) — 攻撃ベクトルを発見
    2. 防御者(ブルーチーム) — 強化を推奨
    3. 監査人(最終判定) — 両方の観点を統合

    安全な設定の初期化

    新しい安全な .claude/ 設定をゼロから構築します:

    npx ecc-agentshield init
    

    作成されるもの:

    • スコープ付き権限と拒否リストを持つ settings.json
    • セキュリティベストプラクティスを含む CLAUDE.md
    • mcp.json プレースホルダー

    GitHub Action

    CI パイプラインに追加します:

    - uses: affaan-m/agentshield@v1
      with:
        path: '.'
        min-severity: 'medium'
        fail-on-findings: true
    

    深刻度レベル

    グレードスコア意味
    A90-100安全な設定
    B75-89軽微な問題
    C60-74注意が必要
    D40-59重大なリスク
    F0-39クリティカルな脆弱性

    結果の解釈

    クリティカルな発見(即座に修正)

    • 設定ファイル内のハードコードされた API キーまたはトークン
    • 許可リスト内の Bash(*)(無制限のシェルアクセス)
    • ${file} 補間によるフック内のコマンドインジェクション
    • シェルを実行する MCP サーバー

    高い発見(本番前に修正)

    • CLAUDE.md 内の自動実行命令(プロンプトインジェクションベクトル)
    • 権限内の欠落した拒否リスト
    • 不要な Bash アクセスを持つエージェント

    中程度の発見(推奨)

    • フック内のサイレントエラー抑制(2>/dev/null|| true
    • 欠落した PreToolUse セキュリティフック
    • MCP サーバー設定内の npx -y 自動インストール

    情報の発見(認識)

    • MCP サーバーの欠落した説明
    • 正しくフラグ付けされた禁止命令(グッドプラクティス)

    リンク

    Alternatives

    Compare before choosing