Security Guidance Plugin

A first-party Claude Code plugin that intercepts the agent’s own file writes. It registers a pre-tool hook on Write, Edit, and MultiEdit, matches the pending content against a catalog of dangerous constructs, and surfaces a warning with remediation guidance before the edit lands. Published on Anthropic’s plugin marketplace on 2026-05-26 and free.

Detection scope

Reported categories include command injection in GitHub Actions workflow files, child_process.exec() on interpolated input, eval() and new Function(), DOM injection through innerHTML and dangerouslySetInnerHTML, Python pickle deserialization, and os.system(). Trade coverage of the launch cites roughly 25 patterns.

The Design Choice That Defines It

The plugin warns and lets the edit proceed. Warnings are session-scoped, so each fires once. This is deliberate and it sets the control’s ceiling: it is a defect-reduction instrument operating at authoring time, not an enforcement point. An agent under indirect prompt injection is not deterred by a warning it authored past, and a developer running unattended never reads one.

Anthropic reports internal testing showing a 30–40% reduction in security-related pull-request comments, and the marketplace counter passed 157,000 installs in the first 24 hours per trade coverage (plugin listing). Both figures measure adoption and reviewer burden, not vulnerability escape rate.

No published efficacy data

Neither the false-negative rate nor the residual-defect rate is published. A 30–40% drop in reviewer comments is consistent with fewer defects reaching review and equally consistent with reviewers commenting less because a tool already spoke. Treat as a productivity result until an escape-rate measurement exists.

Companion Instruments

Anthropic ships several adjacent capabilities that act at different points in the same lifecycle, and they are easily confused:

InstrumentPoint in the lifecycleEnforcement
Security Guidance pluginPre-write, in-sessionWarning only
/security-review slash commandOn demand, over branch changesReport
claude-code-security-review GitHub ActionPull request, in CIGateable
Claude Code SecurityWhole-codebase discovery, research previewDashboard with human approval

Only the GitHub Action can hold a merge. An organization treating the plugin as its AI-code security control has placed the only non-gating instrument of the four at the gate.

Placement

Runtime plane of the AAI-S RA, and the cheapest available D4 artifact for the generative-coding shape — zero cost, first-party, hook-based. It does not on its own carry a D4 level, because the level criteria ask for controls that stop an action, and this one does not.