security-scan

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent for a security scanner, and reading `.claude/` files is proportionate. However, trust signals are mixed: the install/runtime path depends on third-party code, the publisher relationship is unclear across ECC / `ecc-agentshield` / `affaan-m`, examples use unpinned `npx`, and deep-analysis mode forwards `ANTHROPIC_API_KEY` to that CLI. This looks more like a potentially legitimate but trust-sensitive security tool than confirmed malware.

Confidence: 77%Severity: 64%
Audit Metadata
Analyzed At
Mar 13, 2026, 12:41 AM
Package URL
pkg:socket/skills-sh/xu-xiang%2Feverything-claude-code-zh%2Fsecurity-scan%2F@0edc5aa99081c58ce768962e31641b233cef0bcb