security-scan

Audit Claude Code configurations for security vulnerabilities using AgentShield.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/rudi193-cmd/Aionic-Claude-Skills --skill security-scan-rudi193-cmd
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-scan
Source: https://github.com/rudi193-cmd/Aionic-Claude-Skills/tree/main/skills/security-scan
Command: npx skills add https://github.com/rudi193-cmd/Aionic-Claude-Skills --skill security-scan-rudi193-cmd

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Scan Claude Code configurations (.claude/ directory) for security vulnerabilities, misconfigurations, and prompt-injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.

Core Features & Use Cases

  • Checks CLAUDE.md for hardcoded secrets, auto-run instructions, and prompt-injection patterns
  • Scans settings.json, MCP configurations, and hooks for risky permissions and bypass flags
  • Audits MCP servers and agent definitions to prevent data exfiltration and unauthorized tool access
  • Provides a guided, repeatable security-hygiene workflow for new projects and ongoing maintenance

Quick Start

Run a security scan on your Claude Code configuration with AgentShield to identify vulnerabilities in CLAUDE.md, settings.json, MCP configurations, hooks, and agent definitions.

Frequently Asked Questions about security-scan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan Claude Code configurations for security vulnerabilities?

Scan Claude Code configurations for security vulnerabilities by auditing CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions to identify misconfigurations and prompt-injection risks using AgentShield.

What security risks should I check for in CLAUDE.md and MCP server settings?

Security risks in CLAUDE.md and MCP server settings include hardcoded secrets, auto-run instructions, risky permissions, bypass flags, and prompt-injection patterns that could enable data exfiltration or unauthorized tool access.

Do I need AgentShield installed to audit my Claude Code .claude directory?

Yes, you need AgentShield installed to audit your Claude Code .claude directory, as the security scan relies on AgentShield to execute automated checks and generate vulnerability reports for your configuration files.

Can I run a security scan on Claude Code hooks and agent definitions?

Yes, you can run a security scan on Claude Code hooks and agent definitions to detect risky permissions, prevent data exfiltration, and identify unauthorized tool access within your MCP configurations.

What's the best way to maintain security hygiene across Claude Code repositories?

The best way to maintain security hygiene across Claude Code repositories is to follow a guided, repeatable workflow with configurable severity checks during initial project setup and after any changes to Claude Code files.

Why does my Claude Code settings.json configuration need a vulnerability audit?

Your Claude Code settings.json configuration needs a vulnerability audit to identify bypass flags and risky permissions that could expose your project to prompt injection and unauthorized tool execution.