跳过主要内容
security-guidanceby AnthropicOfficialDevelopmentGitHub stars: 37.3k

Security Guidance plugin: what it installs and how to add it

Reviews Claude-generated code for security risks with pattern warnings, diff analysis, and commit-time checks.

From the Marketplace: claude-plugins-official marketplace

Install

> /plugin install security-guidance@claude-plugins-official

Run it inside Claude Code. The official marketplace is already known, so there is nothing to add first.

What is inside

  • 12hooks

About this plugin

The plugin checks code as Claude edits it, warning about patterns such as unsafe deserialisation, raw HTML insertion, hardcoded secrets and dangerous file or network operations. When a turn ends, it sends the diff for LLM review and feeds high-severity findings back to Claude. A separate commit-time reviewer can inspect related files to trace data flow and identify issues such as injection, XSS, SSRF, IDOR, authentication bypass and path traversal.

It is intended for Claude Code projects where security checks should run during development and before commits. It requires Claude Code 2.1.144 or newer, Python 3.8+ on the PATH, and a working API path such as a subscription, API key or third-party provider configuration. Behaviour can be adjusted with environment variables and project-specific security guidance files.

What's inside

  • 12 hooks for edit, turn-completion and commit-time security reviews

More from claude-plugins-official

Skills, not plugins

Prefer a single skill for development work? 471 skills in the same category, each installed on its own.

Development skills