security-guidance
πPluginanthropics/claude-code
Security reminder hook that warns about potential security issues when editing files, including command injection, XSS, and unsafe code patterns
Overview
An Anthropic official plugin that provides security reminders when editing files. Warns about potential security issues including command injection, XSS, and unsafe code patterns via a hook system.
Key Features
- Automatic security warnings when editing code files
- Detection of common vulnerability patterns (XSS, SQL injection, command injection)
- Hook-based integration that runs before file modifications
- OWASP-aligned security guidance
Who is this for?
Developers who want an extra layer of security awareness when Claude edits code. The hook automatically flags potential security issues before they're written to files.
Part of
anthropics-claude-code
π Related Resources
Installation
/plugin marketplace add anthropics/claude-code/plugin install security-guidance@claude-code-pluginsMore from this repository10
Interactive learning mode that requests meaningful code contributions at decision points (mimics the unshipped Learning output style)
Development kit for working with the Claude Agent SDK
Adds educational insights about implementation choices and codebase patterns (mimics the deprecated Explanatory output style)
Automated code review for pull requests using multiple specialized agents with confidence-based scoring to filter false positives
Easily create custom hooks to prevent unwanted behaviors by analyzing conversation patterns or from explicit instructions. Define rules via simple markdown files.
Interactive plugin for creating, designing, and implementing custom subagents in Claude Code with guided best practices
Comprehensive PR review agents specializing in comments, tests, error handling, type design, code quality, and code simplification
Bundled plugins for Claude Code including Agent SDK development tools, PR review toolkit, and commit workflows
Create distinctive, production-grade frontend interfaces with high design quality. Generates creative, polished code that avoids generic AI aesthetics.
Commands for git commit workflows including commit, push, and PR creation