Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

agent-setup-shield-plus

hero

License: MIT Works with Claude Code Skill version 1.0 Stars welcome

Built on affaan-m/ECC by @affaan-m (262,781 stars, MIT). All credit for the original idea to them. This fork improves and repackages it; upstream license preserved in UPSTREAM_LICENSE.

A Claude Code skill that checks setup files for secrets, unsafe access, bad hooks, risky MCP servers, and prompt attacks.

Made for developers who use Claude Code in local or shared projects.

🛡️ Why

Claude Code setup files can hold keys or unsafe rules.

Hooks may leak data or run unsafe shell input.

Agents and MCP servers may have more access than they need.

This skill gives Claude a clear, careful scan process. It plugs into your normal setup, review, and commit flow.

⚡ Install

Replace OWNER with the GitHub owner. Then run this one command:

mkdir -p ~/.claude/skills/security-scan && curl -fsSL https://raw.githubusercontent.com/OWNER/agent-setup-shield-plus/main/skill/SKILL.md -o ~/.claude/skills/security-scan/SKILL.md

The skill has one file and no skill-side packages. AgentShield is a separate tool. Claude will check before installing or running downloaded code.

🔍 Usage

Ask Claude Code:

Use the security-scan skill to scan this project. Check each result, mask any secrets, and do not change files.

Expected output:

Security scan complete.

Critical: 0
High: 1
Medium: 2
Info: 1

Each result was checked in its file.
Possible secrets were masked.
No files were changed.

Claude checks the project path first. It can scan CLAUDE.md, .claude/settings.json, MCP settings, hooks, and agent files. It can also scan user-level files when they are in the scope you gave.

The skill tells Claude to warn you before first use of npx, since npx may download and run code. It also requires approval before installation or --fix.

🧰 What we changed vs upstream

  • Rewritten from Japanese into concise, plain English with a clearer purpose and usage-focused description.
  • Adds explicit attribution to AgentShield’s author and tighter scope rules, including user-level files and multiple .claude/ folders.
  • Introduces safer execution guidance: verify paths, request approval before installation or --fix, and warn that npx may download code.
  • Expands result handling with false-positive review, secret masking, report-sharing cautions, and file-by-file validation.
  • Strengthens remediation guidance by requiring backups, change review, rescanning, and relevant tests before claiming a fix.

📄 License

This repo uses the MIT License. See LICENSE.

The upstream MIT license and credit are preserved in UPSTREAM_LICENSE.

About

Free Claude Code skill to scan setup files for secrets, bad hooks, risky MCP servers, and prompt attacks. Built on @affaan-m/ECC.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors