# Scan Claude Code configs for secrets permission drift and unsafe MCP hookups with AgentShield

> Audit a Claude Code setup before use by flagging hardcoded secrets, broad allow rules, risky hooks, and dangerous MCP server config.

- Skill: `agentskillexchange/scan-claude-code-configs-for-secrets-permission-drift-and-un` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/scan-claude-code-configs-for-secrets-permission-drift-and-un`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/scan-claude-code-configs-for-secrets-permission-drift-and-un/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: AI & ML
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/scan-claude-code-configs-for-secrets-permission-drift-and-un

---


# Scan Claude Code configs for secrets permission drift and unsafe MCP hookups with AgentShield

Audit a Claude Code setup before use by flagging hardcoded secrets, broad allow rules, risky hooks, and dangerous MCP server config.

## Prerequisites

Claude Code configuration directory, AgentShield CLI or npx path, local shell access, optional CI environment for GitHub Action usage

## Installation

Install or set up from the source-backed instructions:

Run AgentShield with the no-install npx flow or install the documented package globally, then scan the target Claude Code configuration directory and review or apply the reported fixes.

- Source: https://github.com/affaan-m/agentshield

## Documentation

- https://github.com/affaan-m/agentshield

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/scan-claude-code-configs-for-secrets-permission-drift-and-unsafe-mcp-hookups-with-agentshield/)

