Source profileQuality 90/100

alirezarezvani/claude-skills/engineering/security-guidance/skills/security-guidance/SKILL.md

security-guidance

PreToolUse security-anti-pattern hook for Claude Code. Catches 12 common security risks (command injection, XSS, SQL injection, unsafe deserialization, GitHub Actions workflow injection, eval/new Function code injection) BEFORE the Edit/Write/MultiEdit operation completes. Session-state caching prevents duplicate warnings on the same file+rule combo. Stdlib only — no dependencies. Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user

Source repository stars
24,975
Declared platforms
1
Static risk flags
0
Last source update
2026-08-25
Source checked
2026-08-26

Decision brief

What it does: where it fits

A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.

Best for

  • Use when you want a safety net during Claude Code sessions that touch security-sensitive code (auth, payments, user

Not for

  • Disabling the hook by default
  • Modifying the pattern list without security review

Compatibility matrix

Platform support, with evidence labels

PlatformStatusEvidenceWhat to check
CodexNot declaredNo explicit evidencePortability before use
Claude CodeDeclaredSource recordInstall path and trigger
CursorNot declaredNo explicit evidencePortability before use
Gemini CLINot declaredNo explicit evidencePortability before use
Open the compatibility checker

Installation

Inspect first. Install second.

The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

Source-detected install commandSource
npx skills add https://github.com/alirezarezvani/claude-skills --skill "engineering/security-guidance/skills/security-guidance"
Safe inspection promptEditorial

Inspect the Agent Skill "security-guidance" from https://github.com/alirezarezvani/claude-skills/blob/f2bac0a8f29b71846cc62d9d580249c2a3246030/engineering/security-guidance/skills/security-guidance/SKILL.md at commit f2bac0a8f29b71846cc62d9d580249c2a3246030. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

Workflow

What the source asks the agent to do

  1. 01

    Modifying the pattern list without security review

    Anyone can add a pattern. Removing one requires a security review — patterns exist because they map to real CVE classes.

    Anyone can add a pattern. Removing one requires a security review — patterns exist because they map to real CVE classes.
  2. 02

    What It Catches

    The file path being edited — flags GitHub Actions workflow files with risky ${{ }} patterns

    The file path being edited — flags GitHub Actions workflow files with risky ${{ }} patternsThe content being written — substring matches against 11 anti-patterns- The file path being edited — flags GitHub Actions workflow files with risky ${{ }} patterns - The content being written — substring matches against 11 anti-patterns
  3. 03

    How It Works

    1. Claude Code is about to run Edit, Write, or MultiEdit 2. PreToolUse hook fires → invokes securityreminderhook.py with the tool input as JSON on stdin 3. The hook extracts filepath + content + checks against the pattern table 4. If a pattern matches AND this warning hasn't bee…

    Claude Code is about to run Edit, Write, or MultiEditPreToolUse hook fires → invokes securityreminderhook.py with the tool input as JSON on stdinThe hook extracts filepath + content + checks against the pattern table
  4. 04

    Installation

    This plugin ships as a Claude Code plugin with hooks.json wiring:

    This plugin ships as a Claude Code plugin with hooks.json wiring:
  5. 05

    In Claude Code:

    /plugin marketplace add alirezarezvani/claude-skills /plugin install security-guidance@claude-code-skills bash ENABLESECURITYREMINDER=0 claude

    /plugin marketplace add alirezarezvani/claude-skills /plugin install security-guidance@claude-code-skills bash ENABLESECURITYREMINDER=0 claude

Permission review

Static risk signals and limitations

No configured static risk pattern was detected

This is not proof of safety. Runtime behavior, indirect dependencies, and hidden external systems are outside the static scan.

Evidence record

Why each signal appears

EvidenceSourceComputedTestedEditorial
SignalValueEvidence typeMeaning
Quality score90/100ComputedDocumentation, specificity, maintenance, and trust rules
Repository stars24,975SourceRepository attention, not individual Skill quality
Compatibility1 platformsSourceDeclared in the catalog source record
Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

Pinned source

Provenance and original SKILL.md

Repository
alirezarezvani/claude-skills
Skill path
engineering/security-guidance/skills/security-guidance/SKILL.md
Commit
f2bac0a8f29b71846cc62d9d580249c2a3246030
License
MIT
Collected
2026-08-26
Default branch
main
View the original SKILL.md

Security Guidance Hook

A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.

This skill is a hook, not a slash command. Once installed, it runs automatically before every Edit, Write, or MultiEdit operation and warns + blocks if it detects a known dangerous pattern.

What It Catches

The hook scans both:

  • The file path being edited — flags GitHub Actions workflow files with risky ${{ }} patterns
  • The content being written — substring matches against 11 anti-patterns
PatternCategoryRisk
GitHub Actions workflow expressionsPath-basedWorkflow command injection via untrusted inputs
child_process.exec, exec(, execSync(SubstringNode.js command injection
new FunctionSubstringJS code injection
eval(SubstringJS code injection
dangerouslySetInnerHTMLSubstringReact XSS
document.writeSubstringDOM XSS
.innerHTML =SubstringDOM XSS
pickleSubstringPython deserialization RCE
os.system, from os import systemSubstringPython command injection
shell=True (subprocess)SubstringPython command injection
f-string SQL or .format SQLSubstringSQL injection
yaml.load(, yaml.unsafe_loadSubstringYAML deserialization RCE

How It Works

  1. Claude Code is about to run Edit, Write, or MultiEdit
  2. PreToolUse hook fires → invokes security_reminder_hook.py with the tool input as JSON on stdin
  3. The hook extracts file_path + content + checks against the pattern table
  4. If a pattern matches AND this warning hasn't been shown for this file+rule in this session:
    • Print the warning to stderr (Claude sees it)
    • Exit code 2 → blocks the tool call
    • Save the warning key to ~/.claude/security_warnings_state_<session>.json
  5. If a pattern matches BUT the warning was already shown this session:
    • Allow the tool call (exit code 0) — Claude already saw the warning once
  6. If no pattern matches:
    • Allow the tool call (exit code 0)

Installation

This plugin ships as a Claude Code plugin with hooks.json wiring:

# In Claude Code:
/plugin marketplace add alirezarezvani/claude-skills
/plugin install security-guidance@claude-code-skills

Once installed, no further configuration needed — the hook runs automatically.

Configuration

Disable per-session via environment variable:

ENABLE_SECURITY_REMINDER=0 claude
# Hook is bypassed for this session

Use sparingly — the hook is most useful exactly when you're tempted to disable it (because you're under deadline pressure to ship something you know is sketchy).

Per-File Override Pattern

If a specific file legitimately needs eval() or pickle (e.g., a sandboxed REPL, a deliberately unsafe parser for a fuzzer), document it in the file with a comment:

# SAFETY: pickle is the required serialization format for this internal tool.
# This file does NOT accept untrusted input. See SECURITY.md for boundary analysis.
import pickle

The hook will still warn on first edit per session. After acknowledging, subsequent edits in the same session are allowed (session-state caching).

Why The Patterns Are Substring-Based (Not AST-Based)

Trade-off: AST-based detection would be more precise (no false positives on string literals containing "eval("). Substring-based is:

  • Faster — runs in ms, doesn't parse the file
  • Cross-language — same hook works for JS/TS/Python/YAML/etc.
  • Conservative — false positives are easy to dismiss (one keystroke); false negatives are dangerous

For 90%+ of cases, substring detection is sufficient. If you need stricter detection, layer in a proper SAST tool (semgrep, CodeQL) as a CI step.

State Files

The hook caches "warning shown" state in ~/.claude/security_warnings_state_<session_id>.json. These files:

  • Are auto-cleaned after 30 days (10% chance per hook invocation)
  • Are session-scoped (each Claude session gets its own)
  • Contain a JSON list of <file_path>-<rule_name> keys

You can safely delete ~/.claude/security_warnings_state_*.json files at any time — the hook regenerates them on next run.

Debug Log

The hook writes to ~/.claude/security-warnings-log.txt for debugging hook misfires:

tail -f ~/.claude/security-warnings-log.txt
# Shows JSON decode errors, state-file save failures, etc.

(Upstream version wrote to /tmp/security-warnings-log.txt — we moved it to ~/.claude/ for persistence across reboots.)

Source + Attribution

This plugin is ported from David Dworken's MIT-licensed implementation in alirezarezvani/aeo-box.

Verbatim: the original 9 patterns (GitHub Actions, child_process.exec, new Function, eval, dangerouslySetInnerHTML, document.write, innerHTML, pickle, os.system) are preserved with their exact warning text.

Modifications:

  • Added 3 patterns: subprocess shell=True, SQL injection via f-string or .format, yaml.unsafe_load
  • Debug log moved from /tmp/security-warnings-log.txt~/.claude/security-warnings-log.txt
  • Restructured as a claude-skills plugin with attribution block in .claude-plugin/authoring-notes.json (originally in plugin.json; relocated when issue #954 showed Claude Code rejects manifests carrying extension keys)

Anti-Patterns

Disabling the hook by default

Defeats the purpose. If ENABLE_SECURITY_REMINDER=0 becomes your default, you've trained yourself to ignore the safety net. Use it only for specific verified-safe operations.

Modifying the pattern list without security review

Anyone can add a pattern. Removing one requires a security review — patterns exist because they map to real CVE classes.

Treating session-state as immutable security policy

The cache prevents nag-spam but is per-session. Don't rely on "I dismissed this once" as long-term policy — use the per-file documentation pattern instead (comment justifying the use).

Related Skills

  • engineering-team/skills/red-team — adversarial pen-testing
  • engineering-team/skills/threat-detection — threat modeling + detection design
  • engineering-team/skills/ai-security — AI-specific security (prompt injection, etc.)
  • engineering/ship-gate — pre-production audit (8-category, ~89 checks)
  • engineering/skill-security-auditor — security scan for skill packages

Trigger Phrases

  • "add security hook"
  • "block unsafe code before write"
  • "detect command injection"
  • "prevent SQL injection patterns"
  • "warn on eval / pickle / os.system"
  • "GitHub Actions security hook"

Version: 2.7.3 Source: Ported from alirezarezvani/aeo-box .claude/plugins/security-guidance/ (originally by David Dworken at Anthropic, MIT) License: MIT

Frequently asked questions

What to verify before installation and use

What does the security-guidance source document cover?

A PreToolUse hook that blocks 12 common security anti-patterns before Claude Code writes them.

How do I install security-guidance?

The source record exposes this install command: npx skills add https://github.com/alirezarezvani/claude-skills --skill "engineering/security-guidance/skills/security-guidance". Inspect the command and pinned source before running it.

Which Agent platforms does the source record declare?

The pinned source record declares support for: claude code.

Alternatives

Compare before choosing

Computed 9581

vasilyu1983/AI-Agents-public

software-search

Designs application search systems. Use when choosing engines, indexing, relevance tuning, facets, autocomplete, or search analytics.

Computed 9520

upex-galaxy/agentic-qa-boilerplate

acli

Atlassian CLI (official `acli` binary, v1.3+ as of 2026) for Jira Cloud, Confluence Cloud, and org admin tasks from the terminal. Use whenever the user wants to create, view, edit, transition, assign, clone, archive, comment on, link, or bulk-operate on Jira work items; list or manage projects, boards, sprints, filters, dashboards, or custom-field definitions; create or update Confluence spaces, pages, or blog posts; activate/deactivate users at the org level; or authenticate to Atlassian from a

Computed 956

jojoprison/mnemo

health

Vault health audit — orphans, broken links, type-aware stale-review candidates, growth stats. Use whenever the user mentions vault maintenance, orphans, broken links, 'is my vault clean', 'проверь vault', 'сироты', 'битые ссылки', 'здоровье базы знаний', 'здоровье памяти', 'здоровье обсидиана', or asks for vault statistics — or proactively after creating 3+ notes in a session, after mass note creation, or when health checks haven't run in a while; the longer between checks, the more invisible or

Computed 9181

vasilyu1983/AI-Agents-public

data-analytics-engineering

Builds analytics engineering layers for metrics, contracts, and BI-ready models. Use when shaping dbt or SQLMesh marts, metric governance, lineage, or data quality.