security-guidance Plugin
Security review for Claude-generated code. Pattern-based warnings on edits, LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes.
Install View latest version Open upstream repository
More actions and subscriptions
Compare latest version View observed updates for this package Subscribe with Atom View source record
Only the newest 50 observations in this subscription, not a full archive, upstream releases or installs. Updates-page links keep observation type and package filters; package-page links include all kinds for that package. Your local following list is not sent.
Install
This version is listed in the verified marketplace claude-plugins-official (repository anthropics/claude-plugins-official). Run these in Claude Code, in order:
- Add the marketplace
/plugin marketplace add anthropics/claude-plugins-official - Install the plugin
/plugin install security-guidance@claude-plugins-official
These commands install the marketplace's current upstream state, not the pinned commit snapshot on this page; the two can differ.
Contents of latest version 2.0.8 (commit ab024cd)
- package directory has its own license file; SPDX identifier not determined
Contents 5
Hook5
-
SessionStart
plugins/security-guidance/hooks/hooks.jsonPermalink -
UserPromptSubmit
plugins/security-guidance/hooks/hooks.jsonPermalink -
PostToolUse
plugins/security-guidance/hooks/hooks.jsonPermalink -
Stop
plugins/security-guidance/hooks/hooks.jsonPermalink -
SubagentStop
plugins/security-guidance/hooks/hooks.jsonPermalink
Nothing matches.
Dependencies, compatibility and skill declarations
Recorded dependencies 0
No dependency requirements were recorded from plugin.json or marketplace entries. Only manifest fields saved with the snapshot are shown here; dependency declarations in other files are outside the current collection scope.
Recorded compatibility
No compatibility requirement was recorded for this snapshot from plugin.json or a marketplace entry. Only manifest fields saved with the snapshot are shown here. Declarations in a skill's SKILL.md header are collected separately and, when present, shown on their own under “Skill file declarations”; they never overwrite or fill in this value.
All versions2
Each commit is an immutable snapshot, newest first. One version label can map to several commits.
| Version | Commit | Captured | Components | Actions |
|---|---|---|---|---|
| 2.0.8 Latest Same label, several commits | ab024cd |
5 | View Download Diff vs previous Compare… | |
| 2.0.8 Same label, several commits | 3ea32df |
5 | View Download Compare… |