用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/mhenke/claude-code-unplugged --skill security-guidance命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
This skill should be used when the user asks to "create an agent", "add an agent", "write a subagent", "agent frontmatter", "when to use description", "agent examples", "agent tools", "agent colors", "autonomous agent", or needs guidance on agent structure, system prompts, triggering conditions, or agent development best practices for coding assistant plugins.
Automated PR and code reviewer guidelines
This skill should be used when the user asks to "create a slash command", "add a command", "write a custom command", "define command arguments", "use command frontmatter", "organize commands", "create command with file references", "interactive command", "use AskUserQuestion in command", or needs guidance on slash command structure, YAML frontmatter fields, dynamic arguments, bash execution in commands, user interaction patterns, or command development best practices for coding assistant.
基于 SOC 职业分类
正在显示 SKILL.md
| name | security-guidance |
| description | Security warnings, patterns scanner, and LLM diff security reviews |
Security review for Claude-generated code. Three layers:
Edit/Write for ~25 known-dangerous patterns (yaml.load, torch.load(weights_only=False), pickle.load on untrusted data, raw innerHTML, hardcoded secrets, etc.).git commit, an SDK-driven reviewer reads related files (Read/Grep/Glob) to trace data flow across the codebase, catching multi-file vulnerabilities pattern matching misses (IDOR, auth bypass, cross-file SSRF).Findings cover common web-vulnerability classes — injection, XSS, SSRF, hardcoded secrets, IDOR, auth bypass, unsafe deserialization, and path traversal among others.
/plugin install security-guidance@claude-plugins-official
Marketplace ships enabled by default in coding assistant — no setup beyond having the CLI itself.
PATH (python3, python, or py -3 — the plugin picks the first that works)All configuration is via environment variables. None are required for default behavior.
# 1P / gateway: a canonical model id
SECURITY_REVIEW_MODEL=claude-opus-4-7 # default
# Bedrock: use the inference-profile id
SECURITY_REVIEW_MODEL=us.anthropic.agent-opus-4-7
# Vertex: use the Vertex date-tag form
SECURITY_REVIEW_MODEL=claude-opus-4-7@20260218
SECURITY_REVIEW_MODEL controls the LLM diff review. SG_AGENTIC_MODEL (same syntax) controls the agentic commit reviewer; defaults to the same model.
| Variable | Default | What it does |
|---|---|---|
SECURITY_GUIDANCE_DISABLE=1 | unset | Kill switch — disables the entire plugin |
ENABLE_PATTERN_RULES=0 | on | Disable layer 1 (regex pattern warnings) |
ENABLE_CODE_SECURITY_REVIEW=0 | on | Disable all LLM reviews (Stop hook + commit/push) |
ENABLE_STOP_REVIEW=0 | on | Disable only the Stop-hook diff review, keeping commit/push reviews. Useful for multi-agent / shared-worktree setups where another agent can move HEAD between a worker's turns |
ENABLE_COMMIT_REVIEW=0 | on | Disable layer 3 (agentic commit review) |
SG_DUAL_OR=on # default off
Runs two parallel review calls and unions the findings. Catches a few percentage points more vulnerabilities in our testing, at roughly 2× the API cost per review. Most users don't need it.
Drop a security-guidance.md in any of:
~/.agent/security-guidance.md — user-wide rules<project>/.agent/security-guidance.md — project rules, intended to be committed<project>/.agent/security-guidance.local.md — local overrides, intended to be .gitignore'dAll three are loaded and concatenated into the LLM diff review's prompt in the order user → project → project-local. If the combined size exceeds the 8 KB prompt budget, the tail is truncated, so user-wide rules are kept and project-local rules are dropped first. The agentic commit reviewer (layer 3) does not currently read this file. Example:
# Acme security rules
- All SELECTs against the `customers` or `orders` tables MUST go through `db.replica`,
never `db.primary`. Primary is for writes only.
- Background jobs must not use the user-context auth token; they get
service-account creds from `jobs.get_service_account()`.
- Calls to `requests.get(url)` with a user-controlled `url` need
the SSRF-allowlist wrapper at `acme.net.safe_request`.
Built-in rules cover common web-vulnerability classes without it — security-guidance.md is for things specific to your codebase that the model can't infer.
The plugin sends data to a model endpoint to perform its reviews. Specifically, each Stop-hook diff review transmits the changed file paths, the diff hunks, and the relevant file contents in the diff; each agentic commit review additionally transmits any files the reviewer pulls in via Read/Grep/Glob while tracing data flow. Your security-guidance.md contents (user, project, and local) are appended to the prompt on every review, so don't put secrets in it.
Where that data goes depends on your coding assistant configuration:
api.anthropic.com and handled under Anthropic's Commercial Terms and Privacy Policy.ANTHROPIC_BASE_URL set): sent to your gateway URL instead. The gateway operator's terms apply.The plugin writes its own debug log to ~/.agent/security/log.txt (override with SECURITY_GUIDANCE_DEBUG_LOG). The log contains diffstate metadata and finding categories — no full file contents or model prompts — and rotates at 1 MB. Nothing is uploaded.
This is a best-effort assistive tool, not a guarantee. Treat findings as suggestions, not as a substitute for human code review, SAST/DAST, dependency scanning, or pen-testing. The reviewer can miss vulnerabilities, produce false positives, and may behave differently across codebases, languages, and model versions. No warranty is provided — use is subject to Anthropic's Commercial Terms.
Plugin doesn't seem to fire — check that ~/.agent/security-guidance.md (or hook activity) shows in debug logs. Run coding assistant with --debug-file /tmp/agent/debug.txt and grep for security_reminder_hook. The plugin also writes its own log to ~/.agent/security/log.txt.
Review never finds anything — verify your API path works. On 3P providers, check SECURITY_REVIEW_MODEL is set to a provider-specific id (not a bare claude-opus-4-7). On LLM gateways, check the gateway's logs for POST /v1/messages traffic from the plugin.
Too many false positives — drop SECURITY_REVIEW_MODEL to a cheaper model (claude-sonnet-4-6) and re-evaluate; if precision is the priority, stay on high-capability model.
Want to silence a specific finding — add a comment to the line explaining why it's safe; the LLM reviewer treats inline justifications as exclusions. For systemic exclusions, document them in your security-guidance.md.
Open an issue on the security-guidance plugin repo with:
assistant --version)~/.agent/security/log.txtBefore executing commands, creating files, or editing code, you should review your work for common security pitfalls. You can run the built-in python script helper using your bash tool to scan files for dangerous patterns:
python3 scripts/security_reminder_hook.py
The pattern rules scanner checks for:
innerHTML usage (XSS vulnerability)yaml.load, pickle.load without restrictions)torch.load(weights_only=False))Upon completing code writing or editing:
Before executing any commands, creating files, or editing code, you MUST output a structured XML <verification_gate> block evaluating the following checks:
secrets: Check for hardcoded API keys, secrets, credentials, or certificates. (PASS/FAIL)input_sanitization: Check for unsafe user input handling (e.g., innerHTML, eval, unvalidated parameters). (PASS/FAIL)paths: Check for path traversal vulnerabilities or directory escape attempts. (PASS/FAIL)Example output format:
<verification_gate>
<secrets>PASS</secrets>
<input_sanitization>PASS</input_sanitization>
<paths>PASS</paths>
</verification_gate>
Do not execute tools or code edits until you have output this verification gate.