使用AgentShield扫描您的Claude代码配置(.claude/目录),以发现安全漏洞、配置错误和注入风险。检查CLAUDE.md、settings.json、MCP服务器、钩子和代理定义。
77
66%
Does it follow best practices?
Impact
100%
1.72xAverage score across 3 eval scenarios
Low
Low-risk findings worth noting
Fix and improve this skill with Tessl
tessl review fix ./docs/zh-CN/skills/security-scan/SKILL.mdCI/CD security pipeline integration
Correct GitHub Action
0%
100%
Path parameter set
100%
100%
min-severity parameter
100%
100%
fail-on-findings parameter
100%
100%
Push trigger
100%
100%
Pull request trigger
100%
100%
Valid workflow structure
100%
100%
Critical issues documented
10%
100%
High issues documented
25%
100%
Medium issues documented
25%
100%
Files covered documented
37%
100%
Workflow file location
100%
100%
Security scan with JSON output
Correct package used
0%
100%
Targets .claude directory
0%
100%
JSON output format
0%
100%
JSON report file created
100%
100%
Bash wildcard finding
100%
100%
Hardcoded secret finding
100%
100%
Hook injection finding
75%
100%
MCP shell server finding
100%
100%
Summary file created
100%
100%
Grade reported
100%
100%
Severity counts reported
100%
100%
Initialize secure Claude configuration
Correct package used
0%
100%
Init command used
0%
100%
settings.json created
100%
100%
CLAUDE.md created
0%
100%
mcp.json created
0%
100%
Post-init scan run
100%
100%
JSON scan output
60%
100%
Setup report created
100%
100%
Grade mentioned in report
100%
100%
Deny list referenced
100%
100%
Scoped permissions referenced
100%
100%
e04ea0b
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.