security-scan

Scan Claude Code configurations for security vulnerabilities and misconfigurations.

1|Updated Mar 19, 2026
One-click install
npx skills add https://github.com/devs6186/claude-private-skills-agents-commands --skill security-scan-devs6186
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-scan
Source: https://github.com/devs6186/claude-private-skills-agents-commands/tree/main/skills/security-scan
Command: npx skills add https://github.com/devs6186/claude-private-skills-agents-commands --skill security-scan-devs6186

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audit Claude Code configurations for security issues and misconfigurations, preventing sensitive data exposure and supply-chain risks.

Core Features & Use Cases

  • Automated vulnerability scanning of CLAUDE.md, settings.json, MCP configurations, hooks, and agent definitions.
  • Remediation guidance with actionable recommendations from AgentShield.
  • Compliance and onboarding checks for new Claude Code projects and periodic hygiene.

Quick Start

Run a security scan against your Claude Code configuration to identify vulnerabilities and misconfigurations.

Frequently Asked Questions about security-scan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan Claude Code configurations for security vulnerabilities?

To scan Claude Code configurations for security vulnerabilities, you can run an automated scan targeting CLAUDE.md, settings.json, MCP servers, and hooks to identify misconfigurations and receive actionable remediation guidance.

What security risks should I check for in MCP servers and Claude Code hooks?

Security risks in MCP servers and Claude Code hooks include sensitive data exposure and supply-chain threats. An automated vulnerability scan identifies these misconfigurations across agent definitions and config files, providing severity grading and remediation steps.

Can I audit CLAUDE.md and settings.json files for misconfigurations automatically?

Yes, you can automatically audit CLAUDE.md and settings.json files for misconfigurations. The scan evaluates these configuration files to detect security vulnerabilities, prevent sensitive data exposure, and generate actionable recommendations.

Does AgentShield work with Claude Code projects to provide security compliance checks?

AgentShield works with Claude Code projects to provide security compliance checks during onboarding and periodic hygiene. It implements an automated scan workflow across configurations, grading vulnerability severity and supplying remediation guidance.

What is the best way to remediate security vulnerabilities found in Claude Code agent definitions?

The best way to remediate security vulnerabilities in Claude Code agent definitions is to run an automated scan that identifies the risks and provides actionable remediation guidance, addressing supply-chain vulnerabilities and preventing sensitive data exposure.

When should I run a security scan on my Claude Code project configuration?

You should run a security scan on your Claude Code project configuration during new project onboarding and for periodic hygiene. This detects security vulnerabilities and misconfigurations in settings, hooks, and MCP servers before they cause data exposure.