Plugin
security-guidance
- Security
- Publisher
- Anthropic (opens in a new tab)
- License
- Apache-2.0
Three layers of security review for Claude-generated code: regex warnings on edits, an LLM diff review on Stop, and an agentic commit review.
The README describes pattern warnings on Edit and Write for about 25 known-dangerous patterns, an LLM review of the diff when Claude finishes a turn, and an SDK-driven reviewer on git commit that reads related files to trace data flow. Finding classes include injection, XSS, SSRF, hardcoded secrets, IDOR, auth bypass and unsafe deserialization.
Layers two and three send your diff to a model call (the README names Opus 4.7 as the default), so they use your API path and cost tokens. It needs Python 3.8 or newer on PATH, and each layer can be switched off with environment variables such as ENABLE_STOP_REVIEW and ENABLE_COMMIT_REVIEW.
This entry only records that the source exists. This directory has not scanned or audited the plugin.
What the badge means
Source verified means the source URL for this entry responded with HTTP 200 on . That is the whole claim. Nobody has read, scanned or run this code on your behalf, and the badge does not mean Anthropic or anyone else endorses it.
Sources change after the check date. Read the code and the publisher page before you install. How to check an extension