Security Scan
Audit your Claude Code setup for Muse: scans .claude/ configs (CLAUDE.md, settings, MCP servers, hooks, agents) with AgentShield, grades A to F, auto-fix included.
- What
- Audit your Claude Code setup for Muse: scans .claude/ configs (CLAUDE.md, settings, MCP servers, hooks, agents) with AgentShield, grades A to F, auto-fix included.
- Cost
- Free
- Needs
- Use "Security Scan" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: a security audit for your Claude Code configuration, so Muse helps you find the holes in the very setup it runs on. Uses AgentShield (github.com/affaan-m/agentshield, npm package ecc-agentshield). Scans the .claude/ directory file by file: CLAUDE.md for hardcoded secrets, auto-run instructions and prompt injection patterns ; settings.json for overly permissive allow lists, missing deny lists and dangerous bypass flags ; mcp.json for risky MCP servers, hardcoded env secrets and npx supply chain risks ; hooks/ for command injection via interpolation, data exfiltration and silent error suppression ; agents/*.md for unrestricted tool access and prompt injection surface. Produces a graded report (A secure to F critical) in terminal, JSON, Markdown or self-contained HTML, with severity-ranked findings and an auto-fix mode that replaces hardcoded secrets with env references and tightens wildcard permissions (manual-only suggestions are never touched). Includes an Opus deep-analysis mode running an attacker/defender/auditor three-agent pipeline, plus a GitHub Action for CI. Use when setting up a new Claude Code project, after modifying configs, before committing configuration changes, or for periodic security hygiene. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: AgentShield must be installed (npm install -g ecc-agentshield, or run via npx) ; the Opus deep analysis needs an ANTHROPIC_API_KEY (paid API usage) ; grades are heuristics, not a security guarantee ; the skill scans configs, it does not patch your application code. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Security Scan" with your Muse. Prerequisites: AgentShield installed. Run: npm install -g ecc-agentshield (or use npx ecc-agentshield, no install needed). The Opus deep-analysis mode needs an ANTHROPIC_API_KEY (paid API usage). 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/security-scan/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Audit my .claude/ directory for security issues: [paste the repo path or describe the setup]." 3. Run the scan (npx ecc-agentshield scan), share the graded report with Muse, and ask it to fix the critical and high findings first. Tip: add the GitHub Action from the skill to your CI to catch config regressions automatically. Safety: a skill is plain-text instructions; it runs nothing by itself. Never paste real secrets into a chat; rotate any secret the scan flags.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.