Command Palette
Search for a command to run...

Anthropic Launches Security-Guidance Plugin for Claude Code, Cites 30%-40% Drop in PR Security Comments

aiai-productsai-agents-codingtechcybersecurity 6 posts · 3 accounts

Anthropic has released a security-guidance plugin for Claude Code that helps developers identify and fix vulnerabilities while writing code. The tool is available to all Claude Code users through the plugin marketplace and runs via hooks to review code at three stages — file edits, model turns and commits — looking for risky patterns, examining full diffs and reading surrounding code to validate potential vulnerabilities.

The company said its internal rollout and benchmarks showed a 30% to 40% decrease in security-related comments on pull requests opened using the plugin, which it described as a lightweight first pass before full code review. Teams can also add organization-specific rules through a claude-security-guidance.md file placed in a repository or distributed via MDM, allowing the plugin to enforce internal policies alongside built-in checks.

From the sources (6 posts)

@scaling01

New Anthropic Repo: "Claude for Securing Source Code" A reference implementation for autonomous vulnerability discovery and human-reviewed remediation with Claude.

@claudedevs

We’ve shipped a security-guidance plugin for Claude Code that helps identify and fix vulnerabilities as you’re writing code. Available for all Claude Code users. Install from the plugin marketplace (/plugins).

@claudedevs

It runs via hooks and reviews code on three levels: - On file edits: looks for risky patterns like commonly misused dangerous libraries - After model turns: reviews the full diff for harder-to-spot issues - On commits: reads surrounding co

@claudedevs

We've been using the plugin extensively at Anthropic. Across our internal rollout and benchmarks, we’ve seen a 30-40% decrease in security-related comments on PRs opened using the plugin. The plugin serves as a lightweight first pass, cat

@claudedevs

You can add org-specific rules in a claude-security-guidance.md file. Drop it in your repo or distribute via MDM. The plugin enforces your policies alongside the built-in checks. Docs:

@cointelegraph

⚡️ NEW: Anthropic released a security-guidance plugin for Claude Code that helps developers identify and fix vulnerabilities while writing code.

Preview built on a synthetic news corpus (16 weeks, Apr–Jul 2026). Impact calls are model reads, not price data.

About Archive