← Browse
security-guidance
anthropics ★ 36523
This plugin adds three layers of security review to Claude Code: instant regex pattern warnings for ~25 dangerous code patterns, LLM-powered diff analysis on Stop to catch injection, XSS, SSRF, and hardcoded secrets before Claude responds, and an agentic commit reviewer that traces data flow across files to detect multi-file vulnerabilities. It requires Python 3.8+ and a working Anthropic API configuration.
Install
> /plugin marketplace add anthropics/claude-plugins-official/tree/HEAD/plugins/security-guidance
> /plugin install security-guidance
Source: https://github.com/anthropics/claude-plugins-official/tree/HEAD/plugins/security-guidance
What it's made of
12 hooks
- Commands
- 0
- Agents
- 0
- Skills
- 0
- MCP servers
- 0
- Hooks
- 12 · PostToolUse, SessionStart, Stop, SubagentStop, UserPromptSubmit
What it needs & plugs into
- API keys
- none
- Paid services
- none detected
- External tools
bash- Talks to
- nothing external detected
Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.
Featured in
- ▶ YouTube · Make Claude Code 10x More Powerful (Only Plugins You Need) — Cloud-Codes · 5.8k views · Mon Aug 31
Is this your plugin?
Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (anthropics).