Best for
- Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user
alirezarezvani/claude-skills/engineering/security-guidance/skills/security-guidance/SKILL.md
PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user
Decision brief
A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Declared | Source record | Install path and trigger |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/alirezarezvani/claude-skills --skill "engineering/security-guidance/skills/security-guidance"Inspect the Agent Skill "security-guidance" from https://github.com/alirezarezvani/claude-skills/blob/f2bac0a8f29b71846cc62d9d580249c2a3246030/engineering/security-guidance/skills/security-guidance/SKILL.md at commit f2bac0a8f29b71846cc62d9d580249c2a3246030. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
Anyone can add a pattern. Removing one requires a security review — patterns exist because they map to real CVE classes.
The file path being edited — flags GitHub Actions workflow files with risky ${{ }} patterns
1. Claude Code is about to run Edit, Write, or MultiEdit 2. PreToolUse hook fires → invokes securityreminderhook.py with the tool input as JSON on stdin 3. The hook extracts filepath + content + checks against the pattern table 4. If a pattern matches AND this warning hasn't bee…
This plugin ships as a Claude Code plugin with hooks.json wiring:
/plugin marketplace add alirezarezvani/claude-skills /plugin install security-guidance@claude-code-skills bash ENABLESECURITYREMINDER=0 claude
Permission review
No configured static risk pattern was detected
This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.
Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 90/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 24,975 | Source | Repository attention, not individual Skill quality |
| Compatibility | 1 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.
This skill is a hook, not a slash command. Once installed, it runs automatically before every Edit, Write, or MultiEdit operation and warns + blocks if it detects a known dangerous pattern.
The hook scans both:
${{ }} patterns| Pattern | Category | Risk |
|---|---|---|
| GitHub Actions workflow expressions | Path-based | Workflow command injection via untrusted inputs |
child_process.exec, exec(, execSync( | Substring | Node.js command injection |
new Function | Substring | JS code injection |
eval( | Substring | JS code injection |
dangerouslySetInnerHTML | Substring | React XSS |
document.write | Substring | DOM XSS |
.innerHTML = | Substring | DOM XSS |
pickle | Substring | Python deserialization RCE |
os.system, from os import system | Substring | Python command injection |
shell=True (subprocess) | Substring | Python command injection |
f-string SQL or .format SQL | Substring | SQL injection |
yaml.load(, yaml.unsafe_load | Substring | YAML deserialization RCE |
Edit, Write, or MultiEditsecurity_reminder_hook.py with the tool input as JSON on stdin~/.claude/security_warnings_state_<session>.jsonThis plugin ships as a Claude Code plugin with hooks.json wiring:
# In Claude Code:
/plugin marketplace add alirezarezvani/claude-skills
/plugin install security-guidance@claude-code-skills
Once installed, no further configuration needed — the hook runs automatically.
Disable per-session via environment variable:
ENABLE_SECURITY_REMINDER=0 claude
# Hook is bypassed for this session
Use sparingly — the hook is most useful exactly when you're tempted to disable it (because you're under deadline pressure to ship something you know is sketchy).
If a specific file legitimately needs eval() or pickle (e.g., a sandboxed REPL, a deliberately unsafe parser for a fuzzer), document it in the file with a comment:
# SAFETY: pickle is the required serialization format for this internal tool.
# This file does NOT accept untrusted input. See SECURITY.md for boundary analysis.
import pickle
The hook will still warn on first edit per session. After acknowledging, subsequent edits in the same session are allowed (session-state caching).
Trade-off: AST-based detection would be more precise (no false positives on string literals containing "eval("). Substring-based is:
For 90%+ of cases, substring detection is sufficient. If you need stricter detection, layer in a proper SAST tool (semgrep, CodeQL) as a CI step.
The hook caches "warning shown" state in ~/.claude/security_warnings_state_<session_id>.json. These files:
<file_path>-<rule_name> keysYou can safely delete ~/.claude/security_warnings_state_*.json files at any time — the hook regenerates them on next run.
The hook writes to ~/.claude/security-warnings-log.txt for debugging hook misfires:
tail -f ~/.claude/security-warnings-log.txt
# Shows JSON decode errors, state-file save failures, etc.
(Upstream version wrote to /tmp/security-warnings-log.txt — we moved it to ~/.claude/ for persistence across reboots.)
This plugin is ported from David Dworken's MIT-licensed implementation in alirezarezvani/aeo-box.
Verbatim: the original 9 patterns (GitHub Actions, child_process.exec, new Function, eval, dangerouslySetInnerHTML, document.write, innerHTML, pickle, os.system) are preserved with their exact warning text.
Modifications:
subprocess shell=True, SQL injection via f-string or .format, yaml.unsafe_load/tmp/security-warnings-log.txt → ~/.claude/security-warnings-log.txtattribution block in .claude-plugin/authoring-notes.json (originally in plugin.json; relocated when issue #954 showed Claude Code rejects manifests carrying extension keys)Defeats the purpose. If ENABLE_SECURITY_REMINDER=0 becomes your default, you've trained yourself to ignore the safety net. Use it only for specific verified-safe operations.
Anyone can add a pattern. Removing one requires a security review — patterns exist because they map to real CVE classes.
The cache prevents nag-spam but is per-session. Don't rely on "I dismissed this once" as long-term policy — use the per-file documentation pattern instead (comment justifying the use).
engineering-team/skills/red-team — adversarial pen-testingengineering-team/skills/threat-detection — threat modeling + detection designengineering-team/skills/ai-security — AI-specific security (prompt injection, etc.)engineering/ship-gate — pre-production audit (8-category, ~89 checks)engineering/skill-security-auditor — security scan for skill packagesVersion: 2.7.3
Source: Ported from alirezarezvani/aeo-box .claude/plugins/security-guidance/ (originally by David Dworken at Anthropic, MIT)
License: MIT
Frequently asked questions
A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.
The source record exposes this install command: npx skills add https://github.com/alirezarezvani/claude-skills --skill "engineering/security-guidance/skills/security-guidance". Inspect the command and pinned source before running it.
The pinned source record declares support for: claude code.
Alternatives
vasilyu1983/AI-Agents-public
Designs application search systems. Use when choosing engines, indexing, relevance tuning, facets, autocomplete, or search analytics.
upex-galaxy/agentic-qa-boilerplate
Atlassian CLI (official `acli` binary, v1.3+ as of 2026) for Jira Cloud, Confluence Cloud, and org admin tasks from the terminal. Use whenever the user wants to create, view, edit, transition, assign, clone, archive, comment on, link, or bulk-operate on Jira work items; list or manage projects, boards, sprints, filters, dashboards, or custom-field definitions; create or update Confluence spaces, pages, or blog posts; activate/deactivate users at the org level; or authenticate to Atlassian from a
jojoprison/mnemo
Vault health audit — orphans, broken links, type-aware stale-review candidates, growth stats. Use whenever the user mentions vault maintenance, orphans, broken links, 'is my vault clean', 'проверь vault', 'сироты', 'битые ссылки', 'здоровье базы знаний', 'здоровье памяти', 'здоровье обсидиана', or asks for vault statistics — or proactively after creating 3+ notes in a session, after mass note creation, or when health checks haven't run in a while; the longer between checks, the more invisible or
vasilyu1983/AI-Agents-public
Builds analytics engineering layers for metrics, contracts, and BI-ready models. Use when shaping dbt or SQLMesh marts, metric governance, lineage, or data quality.