Security Guidance
148,649 starsOfficial Anthropic plugin for Claude Code (v2.0.0) with three review layers: (1) instant regex warnings on Edit/Write for ~25 known-dangerous patterns (yaml.load, pickle, raw innerHTML, hardcoded secrets...); (2) at turn end the diff goes to a fast LLM call (Opus 4.7 by default), with high-severity findings fed back so Claude fixes them before you see the response; (3) on git commit an SDK-driven agentic reviewer uses Read/Grep/Glob to trace cross-file data flow, catching IDOR, auth bypass and cross-file SSRF that pattern matching misses.
- First published:2025-10-09
- data as of:
- 2026-09-30
Host
The hooks observe every Edit/Write tool call and each turn's diff; the agentic reviewer can read related files across the codebase at commit time. Layers 2 and 3 send diffs and code fragments into additional LLM calls over your configured model/API path.
All three layers bind to Claude Code extension points: pattern warnings are a PreToolUse hook, diff review hangs on the Stop event, and commit review runs through the Claude Agent SDK. These hook events and the SDK are Claude Code's proprietary execution surface; other hosts have no equivalent seams.
Risk
An extra LLM review call every turn means continuous additional token spend; too many warnings cause alert fatigue (the "maximum strictness" trap from the permission-gate glossary entry); it is a mitigation layer, not a guarantee — officially positioned as review, not a substitute for formal security audit or pen-testing. Code fragments flow through the review model's provider.
Install prompt
在 Claude Code 的插件管理介面中,從官方 marketplace(claude-plugins-official)安裝 security-guidance;需要 Claude Code CLI 2.1.144 以上、PATH 上有 Python 3.8+,以及可用的 API 通路(訂閱、API key 或第三方 provider)。所有配置都以環境變數進行,預設零配置即可用。Paste this to your agent. It deliberately contains no tool subcommands — check the tool's official docs for commands.