The Claude AI Community Discord is open.Join us

Security Guidance

Security review for Claude-generated code. Pattern-based warnings on edits, LLM-powered diff review on Stop, and an agentic commit reviewer that catches injection, XSS, SSRF, hardcoded secrets, and 25+ other vulnerability classes.

Install

Run in your terminal

claude plugin install security-guidance@claude-plugins-official

Claude Code already includes the claude-plugins-official marketplace, so this installs directly. Start a new Claude Code session to use it.

Already in a Claude Code session?

Install

/plugin install security-guidance@claude-plugins-official

Published in Anthropic's claude-plugins-official marketplace (anthropics/claude-plugins-official).

Related plugins

Semgrep

Semgrep catches security vulnerabilities in real-time and guides Claude to write secure code from the start.

Plugin · by Semgrep · 20k marketplace installs

Claude Security

Deep vulnerability scanning of your own code, run entirely inside your Claude Code session at a chosen effort tier, with every finding challenged before it is reported and the verification tally computed in code. Turns surviving findings into targeted patches, each verified by a panel of agents, that you apply when you choose.

Plugin · by Anthropic · 8.6k marketplace installs

Sonatype Guide

Sonatype Guide MCP server for software supply chain intelligence and dependency security. Analyze dependencies for vulnerabilities, get secure version recommendations, and check component quality metrics.

Plugin · by Sonatype · 7.5k marketplace installs

Aikido Security

Aikido Security scanning for Claude Code — SAST, secrets, and IaC vulnerability detection powered by the Aikido MCP server.

Plugin · by Aikido Security · 7.3k marketplace installs

Sonarqube

Automatically enforce SonarQube code quality and security in the agent coding loop — 7,000+ rules, secrets scanning, agentic analysis, and quality gates across 40+ languages. PostToolUse hooks run analysis after every file edit. Pre-tool secrets scanning prevents 450+ patterns from reaching the LLM. Slash commands give on-demand access to quality gate status, coverage, duplication, and dependency risks. Includes SonarQube CLI, MCP Server, skills, hooks, and slash commands.

Plugin · by SonarSource · 6.4k marketplace installs

Auth0

Enterprise-grade auth, easy to implement. Add login, SSO, MFA, and access control to any app with framework-aware guidance.

Plugin · by Auth0 · 4.7k marketplace installs