agentshield
AI agent security scanner that detects vulnerabilities in configurations, MCP servers, and tool permissions.
- Type
- MCP
- Open source
- Yes
- GitHub Stars
- ★ 1.0k
- Source
- mcp-github
- Repository
- github.com/affaan-m/agentshield
Overview
AgentShield is an AI agent security scanner designed to detect hardcoded keys in Claude Code settings, misconfigured permissions, hook injection, MCP server risks, and agent prompt injection vectors. It can be integrated via CLI, GitHub Action, and GitHub App. AgentShield automatically discovers the `.claude/` directory and scans all configuration files, generating a prioritized security report. Ideal for developers who need to ensure the security of their AI agent configurations.
Capabilities
- ▪Detect hardcoded keys
- ▪Audit permission configurations
- ▪Check for hook injection
- ▪Assess MCP server risks
- ▪Identify agent prompt injection
Use cases
Setup
npx ecc-agentshield scan or npm install -g ecc-agentshield
This information was compiled by AI from public sources and may contain inaccuracies — please refer to the source.
FAQ
How do I get started with AgentShield?
Run `npx ecc-agentshield scan` or use `agentshield scan` after global installation.
Which platforms does AgentShield support?
Supports CLI, GitHub Action, and GitHub App integrations.
Related skills
gemini-cli
Gemini CLI is an open-source AI agent that brings Gemini's powerful capabilities directly into the terminal.
sast-skills
Transform your AI coding assistant into a SAST scanner to automatically detect vulnerabilities in code.
skills
Solidity security audit AI skill provided by Pashov Audit Group.
scientific-agent-skills
Transform any AI agent into a scientific assistant with 147 ready-to-use research skills.
susi_alexa_skill
A skill that enables question-and-answer interactions between Alexa and Susi AI.
claude-context
Provides code search capabilities for Claude Code, turning the entire codebase into context.