PlugMyPlugin
← Browse

security-guidance

anthropics ★ 36523

This plugin adds three layers of security review to Claude Code: instant regex pattern warnings for ~25 dangerous code patterns, LLM-powered diff analysis on Stop to catch injection, XSS, SSRF, and hardcoded secrets before Claude responds, and an agentic commit reviewer that traces data flow across files to detect multi-file vulnerabilities. It requires Python 3.8+ and a working Anthropic API configuration.

Security Code Review free runs shell

Install

> /plugin marketplace add anthropics/claude-plugins-official/tree/HEAD/plugins/security-guidance
> /plugin install security-guidance

Source: https://github.com/anthropics/claude-plugins-official/tree/HEAD/plugins/security-guidance

What it's made of

12 hooks

Commands
0
Agents
0
Skills
0
MCP servers
0
Hooks
12 · PostToolUse, SessionStart, Stop, SubagentStop, UserPromptSubmit

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
bash
Talks to
nothing external detected

Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Featured in

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (anthropics).