REPOSITORY EVIDENCE / INDEXABLE REPORT

affaan-m/ECC — MCP & Agent Security Evidence Report

MCP configuration evidence was observed. Observed evidence classes: Shell / command execution, Download / install, MCP configuration, Agent permissions / behavior, CI/CD automation, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.

Is affaan-m/ECC safe to run?

ShadowMCP does not issue a safe/unsafe verdict. This report shows bounded repository evidence that can help identify what deserves review before running or approving the project.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22
Scan completed2026-09-19T16:11:48.745Z
Repository branchmain
Scanned commit07756cee15788a54506031462794ad645719b028
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

MCP configuration evidence was observed. Observed evidence classes: Shell / command execution, Download / install, MCP configuration, Agent permissions / behavior, CI/CD automation, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.

Evidence categories

Shell / command execution

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • README.mdpowershell
  • install.ps1powershell

Download / install

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • README.mdnpm install, npx, pnpm, yarn, docker, git clone
  • install.ps1install/setup script · npm install, git clone
  • install.shinstall/setup script · npm install, git clone
  • package.jsonyarn, docker
  • yarn.lockyarn
  • .codex/AGENTS.mdpnpm, yarn
  • .codex/config.tomlnpx

MCP configuration

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • .mcp.jsonMCP configuration file · MCP server config, command config, arguments · server chrome-devtools · stdio / command · command npx · args present
  • .claude-plugin/PLUGIN_SCHEMA_NOTES.mdMCP server config
  • .claude-plugin/plugin.jsonMCP server config
  • .claude/ecc-tools.jsoncommand config
  • .cursor/hooks.jsoncommand config

Agent permissions / behavior

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • AGENTS.mdagent instruction/config file · hooks, agent instructions
  • CLAUDE.mdagent instruction/config file · tools / permissions, hooks, agent instructions, model config
  • .claude-plugin/PLUGIN_SCHEMA_NOTES.mdtools / permissions, hooks, agent instructions
  • .claude-plugin/README.mdhooks, agent instructions, model config
  • .claude-plugin/marketplace.jsontools / permissions, hooks, agent instructions
  • .claude-plugin/plugin.jsontools / permissions, hooks, agent instructions
  • .claude/ecc-tools.jsontools / permissions, agent instructions
  • .claude/identity.jsontools / permissions
  • .codex/AGENTS.mdtools / permissions, hooks, agent instructions, model config
  • .codex/config.tomlagent instructions, model config
  • .cursor/hooks.jsonhooks, agent instructions

CI/CD automation

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • .github/workflows12 direct workflow files

Supply-chain / dependencies

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • package-lock.jsondependency manifest observed
  • package.jsonparsed package manifest · 12 declared dependency entries
  • pyproject.tomlparsed pyproject manifest · 2 selected dependency entries
  • yarn.lockdependency manifest observed

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • NOT_FOUND_IN_SCANNED_SCOPE is not proof of absence outside the bounded scan.
  • Trust/community metadata is descriptive context, not a security guarantee.
  • Zero selected dependency evidence does not mean zero dependencies.
  • No repository clone or target-code execution.
  • No raw source-file bodies or secret/token values are included in this report.
  • No general recursive crawl.
  • No CVE lookup, package reputation lookup or package registry lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2026-01-18 · 244 days old · last push 2026-09-19 · 0 days since last push
Community signalsstars 262665 · forks 39302 · open issues 211
OwnershipUser · affaan-m
LicenseMIT
Repository statearchived NO · fork NO · default branch main

Continue the review