LLM Skills
~/catalogue/sécurité//security-scan
Sécuritésource GitHub

Commande d'analyse de sécurité

/security-scan

Exécutez AgentShield sur le projet en cours ou sur une trajectoire cible, puis transformez les résultats en un plan de remédiation hiérarchisé.

affaan-maffaan-m
240.5k
4 juin 2026
MIT
// contenu du skill

description: Run AgentShield against agent, hook, MCP, permission, and secret surfaces.

agent: everything-claude-code:security-reviewer

subtask: true


Security Scan Command

Run AgentShield against the current project or a target path, then turn the findings into a prioritized remediation plan.

Usage

/security-scan [path] [--format text|json|markdown|html] [--min-severity low|medium|high|critical] [--fix]

  • path (optional): defaults to the current project. Use a .claude/ path, a repo root, or a checked-in template directory.
  • --format: output format. Use json for CI, markdown for handoffs, and html for standalone review reports.
  • --min-severity: filters lower-priority findings.
  • --fix: applies only AgentShield fixes explicitly marked as safe and auto-fixable.

Deterministic Engine

Prefer the packaged scanner:

bash
npx ecc-agentshield scan --path "${TARGET_PATH:-.}" --format text

For local AgentShield development, run from the AgentShield checkout:

bash
npm run scan -- --path "${TARGET_PATH:-.}" --format text

Do not invent findings. Use AgentShield output as the source of truth and separate scanner facts from follow-up judgment.

Review Checklist

  1. Identify active runtime findings first:
  • hardcoded secrets
  • broad permissions
  • executable hooks
  • MCP servers with shell, filesystem, remote transport, or unpinned npx
  • agent prompts that handle untrusted content without defenses
  1. Separate lower-confidence inventory:
  • docs examples
  • template examples
  • plugin manifests
  • project-local optional settings
  1. For each critical or high finding, return:
  • file path
  • severity
  • runtime confidence
  • why it matters
  • exact remediation
  • whether it is safe to auto-fix
  1. If --fix is requested, state the planned edits before applying fixes.
  2. Re-run the scan after fixes and report the before/after score.

Output Contract

Return:

  1. Security grade and score.
  2. Counts by severity and runtime confidence.
  3. Critical/high findings with exact paths.
  4. Lower-confidence findings grouped separately.
  5. A remediation order.
  6. Commands run and whether the scan was local, CI, or npx-backed.

CI Pattern

Use AgentShield in GitHub Actions for enforced gates:

yaml
- uses: affaan-m/agentshield@v1
  with:
    path: "."
    min-severity: "medium"
    fail-on-findings: true

Links

  • Skill: skills/security-scan/SKILL.md
  • Agent: agents/security-reviewer.md
  • Scanner: <https://github.com/affaan-m/agentshield>

Arguments

$ARGUMENTS:

  • optional target path
  • optional AgentShield flags
// source originale publique
affaan-m/ECC
/.opencode/commands/security-scan.md
Licence : MIT
Projet indépendant, non affilié à Anthropic. Ce skill reste la propriété de son auteur original.
// installer ce skill
Collez cette commande dans votre terminal à la racine de votre projet :
mkdir -p .claude/commands && curl -o ".claude/commands/security-scan.md" "https://raw.githubusercontent.com/affaan-m/ECC/main/.opencode/commands/security-scan.md"
Ensuite dans Claude Code, tapez /security-scan pour l'activer.
open_in_newVoir la source originale
// sauvegarder
Sauvegarde disponible après connexion.
loginSe connecter pour sauvegarder
// informations
Créateuraffaan-m
Étoiles 240.5k
CatégorieSécurité
LicenceMIT
Mis à jour4 juin 2026
Format.md
AccèsGratuit
// similaires

Skills Sécurité

Voir toutarrow_forward