Skip to content
Claude Code Mods

Plugin

security-guidance

Source verified. Source URL responded on 2026-09-20. Not a security review.Installable
  • Security
License
Apache-2.0

Three layers of security review for Claude-generated code: regex warnings on edits, an LLM diff review on Stop, and an agentic commit review.

The README describes pattern warnings on Edit and Write for about 25 known-dangerous patterns, an LLM review of the diff when Claude finishes a turn, and an SDK-driven reviewer on git commit that reads related files to trace data flow. Finding classes include injection, XSS, SSRF, hardcoded secrets, IDOR, auth bypass and unsafe deserialization.

Layers two and three send your diff to a model call (the README names Opus 4.7 as the default), so they use your API path and cost tokens. It needs Python 3.8 or newer on PATH, and each layer can be switched off with environment variables such as ENABLE_STOP_REVIEW and ENABLE_COMMIT_REVIEW.

This entry only records that the source exists. This directory has not scanned or audited the plugin.

What the badge means

Source verified means the source URL for this entry responded with HTTP 200 on . That is the whole claim. Nobody has read, scanned or run this code on your behalf, and the badge does not mean Anthropic or anyone else endorses it.

Sources change after the check date. Read the code and the publisher page before you install. How to check an extension

  • Mod

    Built inSource verified. Source URL responded on 2026-09-21. Not a security review.

    sec-default

    Keeps an organization's classic hooks, prompt content, managed settings and tool policy out of reach of user-installed plugins; adds no policy of its own.

    • Security
  • MCP server

    Source verified. Source URL responded on 2026-09-20. Not a security review.

    Filesystem MCP server

    Reference MCP server for file operations with directory allowlists set by arguments or MCP Roots.

    • Integration
    • Security