security-guidance

PackSecurity

Security Guidance is a Claude plugin that reviews code written by AI agents. It flags risky patterns as edits happen, runs an LLM-powered diff review when a task stops, and uses an agentic commit reviewer to catch injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes. The security guidance Claude plugin gives developers a way to check agent-generated code before it lands.

Unavailable. Delivery for this kind is on the roadmap — not serving yet.

Have a setup where Claude plugins can be installed.

What your AI can do with it

  • Pattern-based warnings on code edits as they happen
  • LLM-powered diff review triggered on Stop
  • Agentic commit reviewer that inspects commits
  • Detects injection, XSS, SSRF, and hardcoded secrets
  • Covers 25+ vulnerability classes

Getting started

  1. Have a setup where Claude plugins can be installed.
  2. Add the Security Guidance plugin.
  3. Let the agent make code edits so pattern-based warnings appear.
  4. Review the LLM diff review output when a task stops.
  5. Check the agentic commit reviewer's findings before committing.

Signals

GitHub stars
37k
Forks
4k
Last commit
Sep 2026

Questions

What does the Security Guidance plugin do?
It reviews Claude-generated code with pattern-based warnings on edits, an LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes.
Which vulnerability classes does it detect?
It catches injection, XSS, SSRF, and hardcoded secrets, along with 25+ other vulnerability classes.
When does the review run?
Pattern-based warnings appear on edits as they happen, the LLM-powered diff review runs on Stop, and the agentic commit reviewer examines commits.
Advanced
Item type
plugin
Key
anthropics-claude-plugins-official-security-guidance
Source
github.com/anthropics/claude-plugins-official