Atlas / Skills / florianbruniaux / Security Check

Security CheckBLOCK

skills/florianbruniaux/security-check

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
—
Hosts
1 documented
License
CC-BY-SA-4.0
Stars
6,123
01

Overview

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Read from source at commit d90170da4369OBSERVED · 2026-10-07
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: security-check
description: Quick configuration security check against known threats database
argument-hint: "[path]"
effort: medium
disable-model-invocation: true
---

# Security check

Quick configuration security check against known threats database. Verifies your Claude Code setup for known malicious skills, vulnerable MCPs, dangerous patterns, and exposed secrets.

**Time**: ~30 seconds | **Scope**: Claude Code configuration only

## Instructions

You are a security analyst. Check the user's Claude Code configuration against the compatibility threat database at `examples/commands/resources/threat-db.yaml`. Produce a concise, actionable report.

### Phase 1: Load threat database

Read `examples/commands/resources/threat-db.yaml` from this repository to load:
- Known malicious authors and skills
- CVE database for MCP servers
- Suspicious patterns for hooks, agents, and config

### Phase 2: MCP server audit

Read the user's MCP configuration:

```bash
# Global MCP config
cat ~/.claude.json 2>/dev/null | jq '.mcpServers // empty'

# Project MCP config
cat .mcp.json 2>/dev/null
```

**Check against threat-db.yaml:**
- [ ] Any MCP server matching a CVE entry? → CRITICAL
- [ ] Version pinning: are all MCP servers pinned to exact versions (not `@latest`)? → HIGH if unpinned
- [ ] Any `--dangerous-*` flags in MCP args? → CRITICAL
- [ ] Any MCP servers not on the Safe List (see `guide/security/security-hardening.md` §1.1)? → MEDIUM (flag for manual review)

### Phase 3: Skills & agents audit

```bash
# List installed skills
ls -la .claude/skills/ 2>/dev/null
ls -la ~/.claude/skills/ 2>/dev/null

# List agents
ls -la .claude/agents/ 2>/dev/null
ls -la ~/.claude/agents/ 2>/dev/null

# Check agent tools field
grep -r "^tools:" .claude/agents/ 2>/dev/null
grep -r "^tools:" ~/.claude/agents/ 2>/dev/null
```

**Check against threat-db.yaml:**
- [ ] Any skill/agent name matching `malicious_skills` entries? → CRITICAL
- [ ] Any skill/agent author matching `malicious_authors` entries? → CRITICAL
- [ ] Any agent with `tools: Bash` only? → HIGH
- [ ] Any agent with overly broad tool access + vague description? → MEDIUM

**Deep skill content analysis (SkillSpector-inspired patterns):**

```bash
# Hidden instructions: HTML comments, zero-width chars, large base64 blobs
grep -rn '<!--' .claude/skills/ ~/.claude/skills/ 2>/dev/null | grep -iv 'example\|comment\|html'
grep -rPn '[\x{200B}-\x{200D}\x{FEFF}\x{00AD}]' .claude/skills/ ~/.claude/skills/ 2>/dev/null
grep -rn -E '[A-Za-z0-9+/]{40,}={0,2}' .claude/skills/ ~/.claude/skills/ 2>/dev/null | grep -v 'sha\|hash\|checksum' | head -10

# Unicode deception: RTL override characters
grep -rPn '[\x{202E}\x{202D}\x{200F}]' .claude/skills/ ~/.claude/skills/ 2>/dev/null

# Trigger abuse: generic keywords that shadow built-in commands
grep -rn "trigger\|keyword\|when.*user" .claude/skills/ ~/.claude/skills/ 2>/dev/null | \
  grep -iE '\b(help|run|go|do|yes|ok|the|a |an |it)\b' | head -10

# Supply chain: remote execution patterns in skill scripts
find .claude/skills/ ~/.claude/skills/ \( -name "*.sh" -o -name "*.py" \) 2>/dev/null | \
  xargs grep -l "curl.*|\|wget.*|\|bash.*http\|eval.*curl" 2>/dev/null

# Rogue agent: cron/startup persistence written by skill scripts
find .claude/skills/ ~/.claude/skills/ -type f 2>/dev/null | \
  xargs grep -l "crontab\|launchctl\|systemctl\|~/.bashrc\|~/.zshrc\|autostart" 2>/dev/null

# Data exfiltration: env harvesting combined with network calls
find .claude/skills/ ~/.claude/skills/ -type f 2>/dev/null | \
  xargs grep -l "os.environ\|process.env\|getenv\|printenv" 2>/dev/null | \
  xargs grep -l "curl\|requests\|fetch\|http" 2>/dev/null
```

- [ ] Hidden HTML comments or zero-width characters in skill files? → HIGH
- [ ] Base64 blobs over 40 chars in skill content? → HIGH (verify: may be a legitimate hash)
- [ ] RTL unicode override characters? → HIGH
- [ ] Skill trigger keyword shadows a built-in (help, run, clear...)? → HIGH
- [ ] Executable scripts with `curl | bash` or remote eval? → CRITICAL
- [ ] Skill writes to crontab, launchctl, or shell rc files? → CRITICAL
- [ ] Skill reads env vars AND makes outbound network calls? → CRITICAL

### Phase 4: Hook security

```bash
# List all hooks
find .claude/hooks/ -type f 2>/dev/null
find ~/.claude/hooks/ -type f 2>/dev/null

# Scan hooks for suspicious patterns
grep -rn "curl\|wget\|nc \|ncat\|netcat\|base64\|eval\|exec\|/dev/tcp\|/dev/udp" .claude/hooks/ 2>/dev/null
grep -rn "curl\|wget\|nc \|ncat\|netcat\|base64\|eval\|exec\|/dev/tcp\|/dev/udp" ~/.claude/hooks/ 2>/dev/null

# Check for credential access in hooks
grep -rn "ssh\|id_rsa\|id_ed25519\|\.env\|credentials\|secret\|password\|token\|api.key" .claude/hooks/ 2>/dev/null
grep -rn "ssh\|id_rsa\|id_ed25519\|\.env\|credentials\|secret\|password\|token\|api.key" ~/.claude/hooks/ 2>/dev/null
```

**Check against threat-db.yaml `suspicious_patterns.hooks`:**
- [ ] Network calls (`curl`, `wget`) → HIGH
- [ ] Reverse shell indicators (`nc`, `/dev/tcp`) → CRITICAL
- [ ] Credential access (`ssh`, `.env`, `password`) → CRITICAL
- [ ] Base64 encoding → MEDIUM (review context)

### Phase 5: Memory poisoning check

```bash
# Check for suspicious instructions in memory/config files
grep -in "ignore\|forget\|override\|disregard\|you are now\|new role\|system prompt" \
  CLAUDE.md .claude/CLAUDE.md SOUL.md .claude/SOUL.md MEMORY.md .claude/MEMORY.md \
  ~/.claude/CLAUDE.md ~/.claude/MEMORY.md 2>/dev/null
```

- [ ] Prompt injection patterns in CLAUDE.md / SOUL.md / MEMORY.md? → HIGH
- [ ] Instructions to disable security, skip reviews, or grant broad permissions? → CRITICAL

### Phase 6: Permissions & settings

```bash
# Check settings
cat .claude/settings.json 2>/dev/null
cat ~/.claude/settings.json 2>/dev/null
```

- [ ] `permissions.deny` exists and covers `.env*`, `*.pem`, `*.key`, secrets? → MEDIUM if missing
- [ ] No wildcard `permissions.allow` for Bash or Write? → HIGH if present
- [ ] No `dangerouslySkipPermissions` 
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

HIGHPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SKILL.md:122
- [ ] Credential access (`ssh`, `.env`, `password`) → CRITICAL
Why it matters. asks the agent to read credentials
MEDIUMInventory / provenance · inv.symlink · CWE-1104
whitepapers/recap-cards/en/_extensions
whitepapers/recap-cards/en/_extensions
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
whitepapers/recap-cards/fr/_extensions
whitepapers/recap-cards/fr/_extensions
Why it matters. link not followed
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
SKILL.md:129
grep -in "ignore\|forget\|override\|disregard\|you are now\|new role\|system prompt" \
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
SKILL.md:99
- [ ] Executable scripts with `curl | bash` or remote eval? → CRITICAL

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d90170da4369full audit observations/trust-audit/skill/florianbruniaux__security-check.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-07d90170da4369BLOCKD69first audit
06

Questions

What does the Security Check skill do?

The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.

Is Security Check safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What can Security Check access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Security Check work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (d90170da4369), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement