Skip to content

chore: add agentshield, trim CLAUDE.md and skills#574

Merged
John-David Dalton (jdalton) merged 4 commits intomainfrom
chore/skill-cleanup-v2
Apr 9, 2026
Merged

chore: add agentshield, trim CLAUDE.md and skills#574
John-David Dalton (jdalton) merged 4 commits intomainfrom
chore/skill-cleanup-v2

Conversation

@jdalton
Copy link
Copy Markdown
Contributor

Summary

  • Add ecc-agentshield@1.4.0 devDep and security script
  • Fix security-scan skill description to third-person
  • Trim quality-scan SKILL.md from 602 to 63 lines

@socket-security
Copy link
Copy Markdown

socket-security bot commented Apr 9, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​ecc-agentshield@​1.4.08010010089100

View full report

@socket-security-staging
Copy link
Copy Markdown

socket-security-staging bot commented Apr 9, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Deprecated by its maintainer: npm glob

Reason: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me

From: pnpm-lock.yamlnpm/glob@11.1.0

ℹ Read more on: This package | This alert | What is a deprecated package?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Research the state of the package and determine if there are non-deprecated versions that can be used, or if it should be replaced with a new, supported solution.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/glob@11.1.0. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@jdalton John-David Dalton (jdalton) merged commit 3905010 into main Apr 9, 2026
10 checks passed
@jdalton John-David Dalton (jdalton) deleted the chore/skill-cleanup-v2 branch April 9, 2026 21:56
John-David Dalton (jdalton) added a commit that referenced this pull request Apr 9, 2026
* chore: add ecc-agentshield devDep and security script

* fix: use third-person in security-scan skill description

* chore: trim quality-scan skill to 63 lines (was 602)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants