Version: ecc-agentshield 1.6.0 (via npx), Windows 11, Node 24
What happens
When the scan target is the user config dir (agentshield scan -p ~/.claude, the documented default), its settings.json is judged project scope. The "Helper command runs at session start" rule then rates a plain local statusLine.command as critical and explains that "this file travels with the repository", which isn't true of ~/.claude/settings.json.
Cause (from dist/index.js)
isUserScopeSettingsPath(filePath) receives the path relative to the scan root, here just settings.json. That matches none of its three tests:
startsWith(${home}/.claude/)
^~\/\.claude\/
^\/(?:Users|home)\/[^/]+\/\.claude\/[^/]+\.json$, which also never matches Windows paths like C:/Users/<name>/.claude/settings.json
As a result, isProjectScopeSettings returns true.
Repro (synthetic data)
mkdir scope && echo '{"statusLine":{"type":"command","command":"python ~/.claude/statusline.py"}}' > scope/settings.json
npx -y ecc-agentshield@1.6.0 scan -p scope --format json
→ critical statusLine.command runs a command at startup settings.json
Placing the same file under <root>/~/.claude/settings.json gives medium, which is the intended user-scope rating.
Suggestion
Resolve scope from the absolute path (scan root + relative path), and treat a scan root that is the user's Claude config dir (~/.claude or CLAUDE_CONFIG_DIR) as user scope. Normalise Windows drive paths before the regex.
Version: ecc-agentshield 1.6.0 (via
npx), Windows 11, Node 24What happens
When the scan target is the user config dir (
agentshield scan -p ~/.claude, the documented default), itssettings.jsonis judged project scope. The "Helper command runs at session start" rule then rates a plain localstatusLine.commandas critical and explains that "this file travels with the repository", which isn't true of~/.claude/settings.json.Cause (from
dist/index.js)isUserScopeSettingsPath(filePath)receives the path relative to the scan root, here justsettings.json. That matches none of its three tests:startsWith(${home}/.claude/)^~\/\.claude\/^\/(?:Users|home)\/[^/]+\/\.claude\/[^/]+\.json$, which also never matches Windows paths likeC:/Users/<name>/.claude/settings.jsonAs a result,
isProjectScopeSettingsreturns true.Repro (synthetic data)
→
critical statusLine.command runs a command at startup settings.jsonPlacing the same file under
<root>/~/.claude/settings.jsongives medium, which is the intended user-scope rating.Suggestion
Resolve scope from the absolute path (scan root + relative path), and treat a scan root that is the user's Claude config dir (
~/.claudeorCLAUDE_CONFIG_DIR) as user scope. Normalise Windows drive paths before the regex.